North Korean authorities arrested two people in Wonsan after investigators linked them to a smishing and voice-phishing scheme that targeted donju, the country’s wealthy market entrepreneurs. The suspects allegedly sent fraudulent text messages posing as the central bank or inspection authorities, luring victims to malicious links that installed malware and exposed Jonsong e-wallet passwords in real time. Officials said the operation enabled direct theft from mobile wallets and, in some cases, follow-on extortion using victims’ family information.
The Ministry of Social Security reportedly formed a special task force to trace the stolen funds, identify possible accomplices, and determine whether similar cases had spread beyond Wonsan. Victims in Wonsan, Sinuiju, and Chongjin were said to have suffered heavy losses, contributing to cash shortages and wholesale price increases in local jangmadang markets. Reporting indicated the two suspects were trained IT specialists educated at Pyongyang’s Central University and later assigned to a government institution, underscoring concern that state-trained technical talent is being used for domestic cyber-enabled financial crime.

Get the infrastructure and lures behind it.
2 events from the most recent confirmed update back to the earliest known activity.
After learning of the cyber-enabled financial crimes, North Korea’s Ministry of Social Security established a special investigation task force that ultimately arrested two individuals in Wonsan. The report explicitly says the arrests occurred in mid-July 2026, and investigators began tracing stolen funds and checking for accomplices and similar cases elsewhere.
A pair of suspects allegedly ran a smishing campaign impersonating North Korean authorities, using malware-laced text messages to capture Jonsong e-wallet passwords and steal funds from wealthy market entrepreneurs. The operation also enabled follow-on voice-phishing extortion using victims’ family information and reportedly affected victims in Wonsan, Sinuiju, and Chongjin.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.