North Korea Builds Complex Crypto Laundering Pipeline Through China and Money Mules, RUSI Report Finds
RUSI’s analysis shows that the first stage of the pipeline involves immediate layering, where stolen coins are moved across multiple blockchain networks and mixed in a variety of wallets. The funds are then handed to a network of third‑party facilitators that have ties to organized crime groups in China. These groups act as intermediaries, routing the assets through additional wallets and using mixing services to further obscure the trail. In the final stage, the money is transferred to money mules who convert the cryptocurrency into fiat through P2P transactions or OTC desks that operate in jurisdictions with weak regulatory oversight. The report notes that the use of mules and OTC channels is a common tactic employed by state‑backed cybercriminals to avoid detection by law‑enforcement agencies.
The pipeline fits into a broader pattern of North Korean cyber activity. The regime has been linked to the Lazarus Group, a state‑sponsored hacking collective that has carried out high‑profile thefts, including a $41 million attack on the online casino Stake.com. According to other reports, North Korea has used stolen cryptocurrency to fund its weapons programs and to generate revenue that is otherwise blocked by sanctions. The use of a complex laundering network allows the regime to convert digital assets into usable cash while keeping the trail of the funds obscured.
The implications of this pipeline are significant for the global financial system. Because the funds pass through multiple blockchains and are mixed in a variety of wallets, tracing the origin of the assets becomes a difficult task for investigators. The involvement of Chinese crime syndicates and money mules adds another layer of complexity, as these actors operate across borders and often use informal channels that are not subject to the same regulatory scrutiny as licensed exchanges. The report highlights that the use of OTC desks and P2P transfers can bypass the anti‑money‑laundering (AML) controls that are typically enforced by regulated financial institutions.
Regulators and law‑enforcement agencies are taking steps to counter the threat. In recent months, the U.S. Treasury Department has sanctioned individuals and companies that are believed to be involved in laundering North Korean proceeds. The report indicates that the United Kingdom and other jurisdictions are also working to strengthen their AML frameworks and to increase cooperation with international partners. However, the report stresses that the evolving nature of the pipeline and the use of new technologies make it challenging to keep pace with the criminal actors.
In summary, RUSI’s report documents a sophisticated laundering pipeline that North Korean cybercriminals use to convert stolen cryptocurrency into fiat currency. The system relies on a network of Chinese crime syndicates, money mules, P2P transfers, illicit marketplaces, and OTC desks to obscure the origin of the funds. The pipeline is part of a broader strategy that enables the regime to fund its programs while evading sanctions. While regulators are increasing oversight and taking enforcement actions, the complex and evolving nature of the pipeline means that the threat remains active and difficult to fully neutralise.