Cookies Policy
We use strictly necessary cookies whilst you are here. These are to enable the website to work and cannot be disabled. To read more about what this means, please see our Privacy Policy.

How Huione Guarantee and Huione Pay Facilitate Cybercrime and Advanced Persistent Threats

July 21, 2024
In Southeast Asia, two entities have come under scrutiny for their involvement in a broad array of illicit activities: Huione Guarantee and Huione Pay.

by Kade Morton (CEO)

Introduction

As light has been shed on cryptocurrency mixers like Tornado Cash, cybercriminals right through to advanced persistent threats (APTs) looking to launder stolen funds have been forced to turn elsewhere. In Southeast Asia, two entities have come under scrutiny for their involvement in a broad array of illicit activities: Huione Guarantee and Huione Pay. These platforms, both subsidiaries of the Cambodian conglomerate Huione Group, have become significant players in the region’s illicit financial ecosystem.

Huione Guarantee

Huione Guarantee, established in 2021, has rapidly evolved into a significant player in the illicit digital economy of Southeast Asia. Ostensibly intended as a legitimate marketplace, it is a hub for cybercriminal operations. The platform, which comprises of various messaging app channels, offers a variety of illicit services, including money laundering, deepfake technology and stolen data. The platform helps to facilitate “pig butchering” scams, where fraudsters develop relationships with victims to persuade them into fraudulent investments.

The platform is also linked to human trafficking and worker abuse, with scam compounds operating like prisons, where trafficked workers are restrained and subjected to torture. Merchants on the platform advertise equipment like electric shock shackles and batons used to control these workers.

Over three years, researchers have tracked $11 billion in transactions on Huione Guarantee, primarily conducted using Tether (USDT), a stablecoin pegged to the U.S. dollar. The total figure is likely larger, due to the turnover of vendors obscuring at least a portion of transactions.

Huione Pay

Huione Pay, another subsidiary of the Cambodian conglomerate Huione Group, operates as a merchant on Huione Guarantee’s platform. Huione Pay offers currency exchange, payments, and remittance services. Despite its legitimate facade, Huione Pay has been implicated in significant illicit activities, particularly involving the laundering of stolen cryptocurrency.

From June 2023 to February 2024, Huione Pay received over $150,000 worth of cryptocurrency from a digital wallet associated with APT45. Attributed to North Korea’s 3rd Bureau, Foreign Intelligence / Lab 110 of the Reconnaissance Bureau of the General Staff Department (RGB), APT45 is also known as Lazarus Group, Hidden Cobra, Guardians of Peace, NICKEL ACADEMY, Black Artemis, COVELLITE, CTG-2460, Dark Seoul, High Anonymous, Labyrinth Chollima, New Romanic Cyber Army Team, NNPT Group, Who Am I?, Whois Team, TA404, APT-C-26, ZINC and Diamond Sleet.

The United Nations Office on Drugs and Crime (UNODC) has observed similar collaborations between North Korean hackers and other criminal enterprises in Southeast Asia, leveraging casinos and unregulated cryptocurrency exchanges to launder money.

The Huione Pay wallet had been used to deposit funds stolen from three crypto companies, Atomic Wallet, CoinsPaid and Alphapo. The FBI attributed the hacks to APT45.

Huione Pay is also deeply intertwined with Cambodia’s political elite. One of its directors, Hun To, is a cousin of the current Cambodian Prime Minister, Hun Manet. Hun To has reportedly been suspected of heroin trafficking and money laundering by Australian Police. He has also been linked to Chinese organised crime and at least one scam compound.

Challenges

The lack of operational security around the advertisement of these services, and around transactions related to these services is remarkable at first glance, but less so on further investigation.

The National Bank of Cambodia (NBC) has stated that payments firms like Huione Pay are prohibited from dealing with cryptocurrencies due to risks related to volatility, cybercrime, and anonymity, which can facilitate money laundering and terrorism financing. Despite these regulations, Huione Pay continues to receive cryptocurrency transactions. No public action from NBC has been forthcoming against Huione Guarantee or Huione Pay.

It was also reported in 2012 by the Sydney Morning Herald that Australian police planned to arrest and question Hun To on an upcoming trip to Australia, but the operation was foiled when Hun To was denied a visa to enter Australia. Australian embassy officials in Phnom Penh cited the need to avoid a diplomatic incident.

This seeming invulnerability is now being leveraged by groups like APT45 to continue funding the North Korean regime.

Moving Forward

By offering services such as money laundering, deepfake technology, and equipment for restraining trafficked workers, Huione Guarantee has become a vital resource for cybercriminals looking to exploit the digital economy’s vulnerabilities. Similarly, Huione Pay’s involvement in laundering cryptocurrency stolen by North Korea’s APT45 exemplifies the intersection of geopolitical interests and organised crime.

Delving into the workings of Huione Guarantee and Huione Pay provides a clearer picture of the cybercrime and APT landscape. This understanding is the first step in developing robust strategies to combat digital illicit activities, protecting the integrity of the global financial system, and safeguarding individuals and organisations from the growing threat of cybercrime and cyberespionage.

References

https://www.elliptic.co/blog/cyber-scam-marketplace

https://therecord.media/tether-freezes-29-million-crypto-connected-to-scam-marketplace

https://www.reuters.com/technology/cybersecurity/north-korean-hackers-sent-stolen-crypto-wallet-used-by-asian-payment-firm-2024-07-15/

https://www.reuters.com/world/asia-pacific/north-korean-hackers-criminals-share-money-laundering-networks-southeast-asia-un-2024-01-15/

https://www.unodc.org/roseap/uploads/documents/Publications/2024/Casino_Underground_Banking_Report_2024.pdf

https://www.mandiant.com/resources/insights/apt-groups#north-korea

https://www.cisa.gov/news-events/alerts/2017/06/13/hidden-cobra-north-koreas-ddos-botnet-infrastructure

https://www.secureworks.com/about/press/media-alert-secureworks-discovers-north-korean-cyber-threat-group-lazarus-spearphishing

https://www.secureworks.com/research/threat-profiles

https://www.proofpoint.com/us/blog/threat-insight/above-fold-and-your-inbox-tracing-state-aligned-activity-targeting-journalists

https://mp-weixin-qq-com.translate.goog/s/W4hkBRJnwN1G32QCpaNNoA?_x_tr_sl=auto&_x_tr_tl=en&_x_tr_hl=en&_x_tr_pto=wapp&utm_source=substack&utm_medium=email

https://learn.microsoft.com/en-us/defender-xdr/microsoft-threat-actor-naming?view=o365-worldwide

https://www.smh.com.au/national/drugs-our-man-in-cambodia-20120325-1vsiz.html

https://www.youtube.com/watch?v=fiy03A7YfW4

https://www.aljazeera.com/features/longform/2022/8/11/meet-cambodia-cyber-slaves

https://cloud.google.com/blog/topics/threat-intelligence/apt45-north-korea-digital-military-machine

Benefits

Why 
select 
Arachne?

Do you want to maximise your security within your budget? Arachne Digital is the logical choice.

Our platform searches the internet for information on threat actors, gathers reports, and categorises the findings by region, industry, and threat actor. Our process automatically maps TTPs to MITRE ATT&CK®, slashing research time and saving you money.

Threat Mitigation Experts

Connect with a way to see and neutralise potential attacks before they impact your organisation. Arachne Digital empowers organisations to anticipate and avoid cyber threats by delivering actionable intelligence.

Optimised Security Posture

By integrating the precise threat intelligence provided by our reports, you can evolve, prioritise and implement effective and continually updated security controls relevant to your organisation.

Streamlined Compliance

Comprehensive, insightful threat intelligence reports support audit preparations. Demonstrate a proactive approach to cybersecurity and achieve and maintain compliance more easily.

Testimonials 
& 
Partnerships

“Arachne Digital’s team works closely with us in integrating our tool, Speculo, with their data. Speculo is designed to help organisations get a full picture of their cyber risk with reliable analytics and a streamlined risk assessment process. The integration of Arachne Digital’s threat intelligence into Speculo provides evidence-based insights into cyber risks, making the tool more relevant to our customers. Arachne facilitated multiple face-to-face meetings and video calls, provided technical resources, comprehensive documentation, and example reports. This collaboration ensured that we could seamlessly integrate and utilize their data, significantly enriching the value we deliver to our clients.

Arachne Digital’s commitment to excellence and their proactive approach in supporting our needs have made them an indispensable partner. We highly recommend their services to any organisation looking to strengthen their threat intelligence capabilities.”

Partnership

We 
are 
partnered 
with 
DISARM 
Foundation.

Arachne Digital is proud to partner with the DISARM Foundation as the inaugural member of their Partner Programme, launched at the beginning of 2024.

This partnership is crucial in supporting the DISARM Foundation’s mission to maintain and enhance the DISARM Framework, ensuring it remains a free and continuously updated resource in the fight against disinformation.

Through our collaboration, Arachne Digital provides valuable feedback, promotes the integration of the framework into our operations, and encourages wider adoption within the defender community. This partnership highlights our commitment to combating evolving threats and fostering a secure digital environment.


Empower. 
Defend. 
Prevail.

Newsletter
Stay in the loop with our latest updates, exclusive offers, and content by subscribing to our newsletter.

© 2024 Arachne Digital, ALL RIGHTS RESERVED
Built by