Interagency delegations from the United States, Japan, and the Republic of Korea gathered in Washington, D.C. on June 25 and 26 to coordinate responses to North Korea’s cryptocurrency thefts, laundering activities, information technology worker schemes, and malicious cyber activity at the Trilateral Diplomatic Working Group on DPRK Cyber Threats.
All three delegations reiterated their commitment to achieving the complete denuclearization of North Korea and denying revenue that could support sanctioned activities such as the unlawful development of weapons of mass destruction and ballistic missiles.
Representatives from the United States, South Korea, and Japan said they were concerned about cryptocurrency heists attributed to North Korean actors. They noted reports including a $290 million theft from KelpDAO and a $285 million theft from Drift Protocol. Participants said they would increase efforts to expose North Korean cryptocurrency thefts and raise awareness about these threats in Europe, Southeast Asia, and Africa. The representatives also said there is an increasing risk posed by North Korean IT workers utilizing artificial intelligence capabilities. They committed to supporting industry efforts aimed at enhancing detection and mitigation of schemes designed to defraud U.S. and international companies.
The participants reiterated what they described as the importance of continued law enforcement cooperation in order to strengthen enforcement of international sanctions against North Korea, with the goal of preventing malicious cyber activity and illicit revenue generation.
The delegations also highlighted leveraging private sector expertise as important for addressing these challenges. They expressed gratitude toward Coinbase, Mandiant Threat Intelligence (part of Google Cloud Security), Polymarket, and Upwork for participating in the inaugural private-sector session of this working group.