Lazarus Group OTC Broker Network

đź”´ High Risk

The Lazarus Group OTC broker network represents a critical vulnerability in the global fight against state-sponsored cybercrime and sanctions evasion, exposing how North Korea systematically exploits China’s underground financial infrastructure to monetize billions in stolen cryptocurrency. Despite Beijing’s nominal ban on crypto trading, Chinese OTC brokers—operating through shell companies, false identities, and off-platform P2P channels—serve as the primary off-ramp for DPRK hacking proceeds, converting assets like USDT and ETH into fiat via bank transfers while deliberately avoiding regulated exchanges with AML controls. On-chain evidence ties specific traders, such as Yicong Wang, to over $17 million consolidated from 25+ Lazarus hacks, while OFAC sanctions on figures like Wu Huihui confirm that these networks are not rogue actors but integral components of a state-directed laundering pipeline that funds North Korea’s weapons programs. The persistence of this system—despite frozen assets, platform bans, and repeated U.S. enforcement actions—demonstrates both the sophistication of DPRK’s financial warfare strategy and the complicity of China’s shadow banking sector in enabling one of the most consequential money-laundering operations of the digital age.

The Lazarus Group OTC Broker Network case demonstrates how North Korea, through its state‑sponsored hacking unit, steals billions in cryptocurrency and then relies on China‑based underground OTC brokers to convert those proceeds into usable fiat. Chinese traders and shell firms act as the financial backbone of this scheme, using false identities, P2P channels, and informal banking relationships to avoid regulated exchanges and AML controls. On‑chain evidence ties specific OTC operators to dozens of Lazarus hacks, with millions consolidated in broker‑controlled wallets before cash‑out via bank transfers and stablecoin settlements. U.S. sanctions, DOJ forfeiture actions, and industry reports collectively confirm that this is not an isolated abuse but a structured, recurring pipeline that materially supports DPRK’s sanctioned weapons programs. The case thus establishes a clear, documented link between North Korean state cybercrime and Chinese underground finance, proving that both countries are central to one of the world’s most consequential crypto‑money‑laundering operations.

Countries Involved

This case centrally involves North Korea (DPRK) as the state sponsor of the Lazarus Group hacking operations and China as the primary geographic hub for the over‑the‑counter (OTC) broker network that converts stolen cryptocurrency into fiat. North Korean cyber units, linked to the Reconnaissance General Bureau, execute large‑scale thefts from exchanges and DeFi protocols, then route proceeds through China‑based OTC traders and shell firms that operate outside regulated exchanges. Chinese jurisdictions and adjacent zones (including Hong Kong and, in some reports, Cambodian/Malaysian corridors used by Chinese brokers) function as the operational base where illicit crypto is aggregated, layered, and cashed out via bank transfers, P2P trades, and gift‑card schemes. The cross‑border nature of the scheme—DPRK theft plus Chinese underground banking—creates a transnational laundering pipeline that exploits gaps between cryptocurrency enforcement in China and sanctions enforcement against North Korea. Together, these two countries form a core axis in the global crypto‑laundering ecosystem, with DPRK providing the illicit revenue source and China‑linked brokers providing the financial infrastructure to monetize it.

 

Public reporting on this OTC network intensified in 2023–2024, when U.S. authorities and on‑chain investigators began explicitly tying Chinese OTC traders to Lazarus‑linked hacks. OFAC’s 2023 sanctions on China‑based facilitators (including Wu Huihui and Cheng Hung Man) marked a major enforcement milestone, formally alleging that these individuals converted stolen crypto for DPRK actors via OTC channels. In October 2024, blockchain investigator ZachXBT published detailed findings identifying Chinese trader Yicong Wang (aliases “Seawang,” “Greatdtrader,” “BestRhea977”) as a key node laundering tens of millions of dollars from Lazarus hacks since 2022. Subsequent reports in 2025–2026, including TRM Labs’ “Shadow Bankers” analysis and Arkham’s 2026 Lazarus footprint report, further documented how Chinese underground OTC desks serve as a persistent “bottleneck” for DPRK and other criminal proceeds. These layered disclosures—from regulatory actions to investigative journalism and blockchain analytics—collectively established the Lazarus OTC broker network as a documented, ongoing money‑laundering mechanism benefiting North Korea via China‑based infrastructure.

 

BTC, ETH, USDT (Ethereum & Tron), USDC, various DeFi tokens

The core criminal conduct here is sophisticated, state‑sponsored money laundering intertwined with cyber‑theft and sanctions evasion. Lazarus Group, acting on behalf of the North Korean regime, commits wire fraud, computer intrusion, and large‑scale cryptocurrency theft from exchanges, bridges, and DeFi protocols. The proceeds are then laundered through a network of China‑based OTC brokers who convert stolen crypto into fiat using bank transfers, P2P trades, and sometimes prepaid instruments, deliberately avoiding regulated exchanges with robust AML/KYC controls. This constitutes classic money laundering: placement (moving stolen crypto into OTC channels), layering (chain‑hopping, mixing, and using multiple wallets), and integration (converting to fiat and spending via legitimate‑looking trade or real‑estate purchases). In parallel, the scheme violates U.S. and UN sanctions by providing material support to DPRK entities tied to weapons programs, making it both a financial crime and a national‑security threat. The involvement of Chinese underground bankers further implicates organized‑crime laundering infrastructure that serves multiple global criminal networks, amplifying the scale and complexity of the offense.

 

Key entities include the DPRK‑linked Lazarus Group (often associated with the Reconnaissance General Bureau) as the primary thief and beneficiary of the laundered funds. China‑based OTC traders and informal “shadow banks” operate as the main laundering conduit, with individuals like Yicong Wang (aliases “Seawang,” “Greatdtrader,” “BestRhea977”) identified as consolidating millions from dozens of Lazarus‑linked hacks. Earlier OFAC actions targeted figures such as Wu Huihui and Cheng Hung Man, who coordinated large‑scale conversions of stolen crypto into fiat on behalf of DPRK actors. Shell companies structured as import/export or trading firms are used to justify fund flows and layer transactions, while some payment processors and P2P platforms in Southeast Asia have been implicated as secondary channels. Blockchain analytics firms (Chainalysis, TRM Labs, Arkham) and on‑chain investigators (ZachXBT) have played a critical role in mapping these networks, but the operational core remains the DPRK hacking apparatus and its China‑based financial enablers.

 

Yes. Politically exposed persons (PEPs) and state‑linked entities are central to this scheme because Lazarus Group is widely assessed by U.S. and allied governments as a North Korean state‑sponsored hacking organization tied to the Reconnaissance General Bureau. Sanctions designations explicitly link laundering proceeds to DPRK weapons‑of‑mass‑destruction and ballistic‑missile programs, implicating senior regime interests and state institutions as ultimate beneficiaries. Individuals sanctioned by OFAC, such as China‑based OTC facilitators, are described as providing material support to DPRK‑controlled cyber operations, effectively acting as financial proxies for a sanctioned state. While many OTC brokers are private actors, their systematic role in converting stolen funds for a state‑backed entity transforms them into de facto PEP‑adjacent facilitators under sanctions frameworks. This PEP dimension elevates the case from ordinary crypto crime to a sanctioned state‑sponsored financial pipeline that undermines international non‑proliferation and anti‑money‑laundering regimes.

 

The network employs a multi‑stage laundering playbook tailored to exploit weaknesses in both blockchain monitoring and traditional banking oversight. After theft, Lazarus moves funds through mixers, cross‑chain bridges, and decentralized exchanges to obscure origins and break on‑chain links to the original hack. Stolen assets are then consolidated into a small set of “collector” wallets controlled by China‑based OTC traders, who act as the primary off‑ramp. These brokers convert crypto—especially stablecoins like USDT—into fiat via bank transfers, P2P settlements, and sometimes prepaid instruments (e.g., gift cards), often using false identities and shell trading companies to justify transactions. Funds are further layered through multiple accounts and jurisdictions, including Hong Kong and Southeast Asian corridors, before being integrated into the legitimate economy through real‑estate purchases, trade payments, or personal consumption. The entire pipeline is designed to avoid regulated exchanges with strong AML/KYC, relying instead on informal, triad‑linked OTC desks that specialize in high‑volume, low‑scrutiny conversions for DPRK and other criminal clients.

 

While exact totals are difficult to pin down due to the covert nature of OTC flows, available evidence indicates that tens to hundreds of millions of dollars have been laundered through this specific DPRK–China OTC channel. On‑chain analyst ZachXBT identified one wallet cluster (“0x501”) associated with Chinese trader Yicong Wang that consolidated over $17 million linked to more than 25 Lazarus‑attributed hacks. Broader reporting estimates that Lazarus has stolen over $3 billion in crypto in recent years, with a significant share routed through Chinese underground OTC brokers for cash‑out. TRM Labs’ 2025 analysis describes Chinese OTC networks as the primary “bottleneck” for DPRK and other major criminal proceeds, implying that a large fraction of DPRK’s crypto revenue—potentially hundreds of millions annually—passes through these channels. Even conservative readings of the available data support the conclusion that the Lazarus OTC broker network has facilitated laundering on a scale that materially supports North Korea’s sanctioned programs.

 

Blockchain investigations show a consistent pattern: stolen funds from Lazarus hacks are first moved through mixers and DeFi protocols to obscure their origin, then funneled into a small set of high‑value wallets controlled by China‑based OTC traders. For example, ZachXBT traced USDT and ETH from multiple hacks (Alex Labs, Irys, Bondly, Maverick) into addresses linked to Yicong Wang, where millions were aggregated before conversion to fiat via bank transfers or P2P settlements. Tether froze $374,000 USDT in one of Wang’s wallets after linking it to blacklisted addresses, illustrating how stablecoins are used as a key intermediate instrument before final off‑ramping. OFAC’s 2023 sanctions filing describes similar flows for Wu Huihui and Cheng Hung Man, who received large transfers from DPRK‑controlled accounts and moved them through shell companies and bank accounts to complete the cash‑out. Across these cases, the transaction graph reveals repeated use of the same OTC nodes, indicating a durable, specialized infrastructure that systematically monetizes DPRK thefts through China‑based financial channels.

 

U.S. authorities have responded with a combination of sanctions, civil forfeiture, and public warnings targeting both DPRK hackers and their China‑based enablers. In 2023, OFAC sanctioned three individuals—including Wu Huihui and Cheng Hung Man—for materially supporting Lazarus Group by converting stolen crypto into fiat via OTC networks operating in China and North Korea. In 2020, the DOJ filed a civil forfeiture complaint against 280 crypto addresses linked to Lazarus‑related exchange hacks, describing how OTC brokers nested at exchanges were used to cash out millions. More recently, Tether froze hundreds of thousands of USDT in wallets tied to Chinese OTC traders after blockchain investigators linked them to Lazarus hacks. The FBI and Treasury have issued repeated advisories warning that DPRK actors use social engineering and sophisticated laundering chains, including Chinese OTC brokers, to move and monetize stolen funds. These actions collectively affirm that the Lazarus OTC network is a recognized, high‑priority target for U.S. and allied enforcement due to its role in sanctions evasion and large‑scale money laundering.

 

Lazarus Group OTC Broker Network
Case Title / Operation Name:
Lazarus Group OTC Broker Network
Country(s) Involved:
Cambodia, China, Korea, North (North Korea), Russia, United States
Platform / Exchange Used:
Informal OTC desks (China/SE Asia), P2P networks, Tether (USDT), decentralized exchanges, Binance, KuCoin (indirectly via OTC nests), Huione Pay (Cambodia)
Cryptocurrency Involved:

BTC, ETH, USDT (Ethereum & Tron), USDC, various DeFi tokens

Volume Laundered (USD est.):
$17M+ via single trader cluster (Yicong Wang); $100M+ via sanctioned OTC facilitators (Wu Huihui/Cheng Hung Man); $3B+ total Lazarus crypto theft (2017–2025)
Wallet Addresses / TxIDs :
“0x501” cluster (Yicong Wang); 280 addresses in 2020 DOJ forfeiture; Tether-blacklisted USDT wallets; OFAC-sanctioned DPRK addresses (e.g., 2023/2025 designations)
Method of Laundering:

Chain-hopping via DEXs/bridges; mixing (Tornado Cash, Sinbad); consolidation into OTC broker wallets; stablecoin conversion (USDT/USDC); fiat cash-out via bank transfers, P2P trades, and prepaid gift cards; use of shell import/export firms for trade-based layering

Source of Funds:

State-sponsored cyber-theft (exchange hacks, DeFi exploits, bridge hacks); Reconnaissance General Bureau (RGB)-linked operations; proceeds funneled to DPRK weapons programs

Associated Shell Companies:

Import/export trading firms (China/HK); shadow banking networks; unregistered OTC desks operating under trade licenses; DPRK IT worker front companies

PEPs or Individuals Involved:

Lazarus Group (DPRK state hackers); Yicong Wang (aliases: Seawang, Greatdtrader, BestRhea977); Wu Huihui & Cheng Hung Man (OFAC-sanctioned OTC facilitators); Sim Hyon Sop (DPRK banker, KKBC); Tian Yinyin & Li Jiadong (OFAC-sanctioned Chinese launderers)

Law Enforcement / Regulatory Action:
OFAC sanctions (2020, 2023, 2025); DOJ civil forfeiture (2020, 2025); Tether asset freezes ($374K+ USDT); FBI advisories on DPRK cyber theft; UN Panel of Experts reports on sanctions evasion
Year of Occurrence:
2018–2025 (ongoing pattern; major public reports 2023–2026)
Ongoing Case:
Ongoing
đź”´ High Risk