
The IT worker scheme sits at the intersection of three enforcement gaps: (1) crypto-to-fiat conversion points where shell companies can still move money despite Korea Ryonbong being sanctioned, (2) the lack of secondary sanctions on intermediaries that DTEX has identified but Treasury has not yet designated, and (3) the fact that North Korea's revenue-sharing model is deliberately distributed to avoid single-point-of-failure vulnerabilities. If Treasury does not move quickly to designate the named intermediaries, the scheme will simply route funds through new shells—the underlying IT worker revenue ($2.84M per quarter) is stable and will find new paths.
The revenue stream is no longer compartmentalized—it's now a direct funding mechanism for Russia's active ammunition and weapons consumption in Ukraine.
Korea Ryonbong General Corp is a named sanctioned entity, meaning US and allied financial systems are already supposed to block these flows, yet the transactions occurred through December-February with the wallet remaining active as of the report date. Secondary sanctions enforcement against intermediaries and front companies now becomes the binding constraint: Treasury must identify and designate the specific shell entities facilitating these transfers, or the IT worker revenue will continue funding Russian logistics at a scale ($2.84M over three months) that matters when ammunition shortages are driving operational tempo.
Has Treasury designated the intermediary shell companies DTEX identified, or are they still operational? The report names Sobaeksu, Saenal, and Songkwang as conduits—are these on the OFAC SDN list as of July 22?
Strategic intelligence, synthesized daily — with a public track record. Every call graded against what actually happened.