Good day everyone,
I hope you are all well and having excellent day, welcome to CryptoGod-1’s blog on all things crypto. With sanctions imposed on Tornado Cash and Sinbad shut down, it seems that YoMix has become to favourite Bitcoin Mixer for the North Korean Lazarus Group.
YoMix
The leading blockchain analytics firm, Chainalysis, noted in a report released on Thursday the 15th of February that YoMix has become the main alternative Bitcoin Mixer for the North Korean Lazarus Group following the sanctions imposed on Tornado Cash, and with the closure of Sinbad. The recent discoveries by the blockchain analysis firm noted that a wallet linked to the North Korean hacking operations had recently received funds from YoMix. This same wallet to to get its funds from Sinbad.
The North Korean hackers associated with the notorious Lazarus Group have changed tact from novel money laundering techniques and are focusing on making use of cross-chain bridges to obfuscate the origins of their illicitly obtained cryptocurrency funds. The group is famous for its involvement in numerous hacks against crypto companies and protocols such as Harmony, Coincheck, and Atomic Wallet. It has historically relied on services such as Tornado Cash and Sinbad to mix its coins, but now it is making use of the new mixing service known as YoMix.
The notable surge in funds going through YoMix in 2023 was noted by Chainlysis, and the inflows have increased fivefold. Approximately one-third of these funds originated from wallets associated with crypto hacks which indicates a significant reliance on the mixer by illicit actors who seek to obfuscate the origins of their funds.
The surge in usage has also highlighted the adaptable process of these threats and how these actors evolve in the face of increasing security measures along with the closure of previously popular money laundering avenues. These alternative laundering services are a godsend for the sophisticated cybercriminal group in the midst of heightened regulatory crackdowns.
There was also a shift towards less centralized money laundering practices at the deposit address level. This came even as laundering activities became slightly more concentrated at the service level. This trend has suggested that crypto criminals may be diversifying their laundering activities across multiple nested services or deposit addresses in an attempt to further evade detection by law enforcement and exchange compliance teams.
The Lazarus Group of hackers have also made use of cross-chain bridges to move their funds seamlessly across different blockchain networks. These bridging protocols have become increasingly popular as $743.8 million worth of crypto from crime-related addresses were transferred through bridges in 2023. This was double the amount sent during 2022. North Korea-affiliated hackers were particularly active with bridges for money laundering purposes and remains a prevalent option among cybercriminals. In total the number of funds laundered through various platforms and services in 2023 was $22.2 billion compared with $31.5 billion in 2022.
There was a decline in the popularity of mixing services among cybercriminals as these services saw a drop from $1 billion in 2022 down to $504.3 million worth of crypto in 2023. It was noted by Chainalysis that:
“Much of this is likely due to law enforcement and regulatory efforts, such as the sanctioning and shutdown of mixer Sinbad in November 2023.”
Many centralised exchanges continue to be the primary destination for illicit funds and it was reported that 71.7% of all illicit funds moved to just five different centralised exchanges in 2023. This concentration of illicit funds remains significant and 109 exchange deposit addresses received over $10 million each and a total of $3.4 billion laundered in 2023. Crypto criminals are diversifying their money laundering activities across multiple addresses and services to evade detection and mitigate the risk of asset freezing.
It was also noted that there are differences in the level of concentration among different types of cybercrime. Those who tend to make their funds from ransomware and child sexual exploitation materials tend to concentrate their funds in a small number of deposit addresses, while online scammers and darknet vendors spread their illicit funds across various addresses to evade detection.
Have a great day.
Peace. CryptoGod-1.
Referral Links and Follow Me: