Cybercrime DB

Nation-State Hacker Indictments by the US DOJ

DOJ indictments expose how state hackers actually operate, not just what they target.

Reporter · · 10 min read
Cover illustration for “Nation-State Hacker Indictments by the US DOJ”
hacker arrests and indictments · August 31, 2026 · 10 min read · 2,339 words

The DOJ has been indicting nation-state hackers for a decade now, and if you actually sit down and read those indictments instead of skimming the press release, you get something most threat reports don't give you: sworn, evidence-tested detail on how China, Russia, Iran, and North Korea run their hacking operations. It's a public, citable, oddly generous body of threat intelligence, and most security teams treat it like homework, missing the gift it actually is.

The DOJ has said outright what it's trying to do here: end the impunity that used to define cyberspace, using the one tool that lets a country reach across borders without firing a shot. That doctrine started in 2014, when the department charged five members of the Chinese military with hacking, the first time the U.S. ever brought criminal charges against a state actor for this kind of thing. The legal mechanic is almost mundane once you see it: take domestic criminal law and apply it transnationally, and suddenly you've got a way to define what counts as acceptable state behavior online, and what doesn't. CSIS analysts have argued that this approach, indictments paired with sanctions, has done more to make state hackers recalculate risk than any Cyber Command operation or military response. The indictment is the opening move, and everything else, travel bans, OFAC sanctions, frozen assets, follows from it.

So does any of it work? That's the tension this whole record sits on, and it's worth working through with an open case file rather than a predetermined conclusion.

What a decade of indictments looks like as a dataset

By October 2020, the DOJ had filed 13 indictments against foreign state hackers, four of them against Russian actors. That's a small number in absolute terms, but it tells you where the early attention went. Then 2018 happened: charges against criminal actors tied to China, Russia, Iran, and North Korea, spread across multiple indictments in a single year, and the pace was clearly speeding up.

Four adversaries show up again and again across this entire body of work: the PRC, Russia, Iran, and North Korea. Each one has its own operational fingerprint and its own reason for being online in the first place, economic advantage, geopolitical leverage, information warfare, hard cash. But the indictments aren't spread evenly across them, and that unevenness is itself information. More charges against one country can reflect higher attribution confidence or more political appetite to name names, independent of actual activity volume.

And here's the catch with treating this as a dataset: it's incomplete by design. Not every operation gets indicted, and some never will, for reasons ranging from evidentiary weakness to diplomatic caution. Read the corpus as a partial map, with known gaps built in.

How the PRC structures deniability, and what the i-Soon indictment exposed about it

The March 2025 indictment tied to i-Soon and APT27 is one of the more useful documents to come out of this whole program, because it shows the actual plumbing of Chinese state deniability. The Ministry of Public Security and the Ministry of State Security don't always hack things themselves. They contract it out, to private firms and freelance operators, so that if anyone gets caught, the government is a comfortable step removed.

Those charged in that case included i-Soon employees, two MPS officers, and two individuals, Yin Kecheng and Zhou Shuai, already known as members of the Silk Typhoon cluster. Lay that indictment flat and you can trace the entire chain, from a commercial contractor doing the technical work up to the government office that's buying the output. The business model described in the charging documents is almost casually mercenary: exploit vulnerable systems, steal data, sell it to the PRC government or to whoever else wants it. Part criminal enterprise, part intelligence operation, running on the same infrastructure.

The named targets read like a greatest-hits list of espionage priorities: U.S. critics, Asian governments, and, most damaging of all, the U.S. Treasury, breached in late 2024 through a compromised government contractor. CrowdStrike's 2025 Global Threat Report clocked a 150% jump in PRC-linked threat activity across all sectors between 2023 and 2024, and the indictment activity lines up with that spike closely enough to explain a good chunk of it.

For anyone doing detection work, the lesson isn't subtle: that contractor layer exists specifically to break the attribution chain. Infrastructure that looks like a run-of-the-mill commercial operation, i-Soon-style tooling, i-Soon-style hosting, should be treated as potentially MSS or MPS-directed no matter how commercial the paperwork looks on the surface.

Volt Typhoon and Salt Typhoon as two distinct pre-positioning strategies inside the same infrastructure target set

Volt Typhoon and Salt Typhoon get lumped together constantly because they both live inside U.S. critical infrastructure and both come out of China. Treating them as the same threat will misconfigure your detection priorities consequentially.

CISA's advisory AA24-038A laid out Volt Typhoon's defining trait: persistent access inside American energy, water, communications, and transportation networks, some of it sitting there for at least five years, using living-off-the-land techniques to hide inside native operating system processes instead of dropping obvious malware. FBI Director Wray put it plainly in January 2024 testimony, describing Chinese hackers as "positioning on American infrastructure in preparation to wreak havoc." That's staging for a fight nobody's had yet, a different order of intent than routine intelligence gathering.

Salt Typhoon is a different animal with a different job. Its target was the lawful wiretap systems used by U.S. intelligence and law enforcement, and it reportedly got hold of a near-complete list of phone numbers the DOJ had under wiretap. That's collection, aimed at intelligence access, distinct from Volt Typhoon's disruption footprint, even with an overlapping telecom and government-adjacent target set.

The tradecraft connects them; the goals diverge. Both rely on blending into legitimate system processes rather than deploying anything novel or signature-detectable, which pushes the whole detection burden away from matching known malware and toward behavioral analytics, watching for what normal processes shouldn't be doing. In January 2025, the U.S. sanctioned a PRC-based individual and a cybersecurity company for enabling the Salt Typhoon intrusions, a fast turnaround from indictment logic to sanctions action, and a decent preview of how quickly that pipeline can move when the will is there.

North Korea's financial operations as a fully documented case study in mission-driven cybercrime

Diagram: North Korea's Crypto Theft: Scale and Acceleration. Visualizes: Visualise the escalating scale of DPRK-linked cryptocurrency theft using the concrete figures in the article.

North Korea advertises the motive through its operational record. The motive is money, documented plainly in the indictments, and the indictments read as heist documentation rather than espionage cases.

The February 2025 Bybit theft, $1.5 billion in Ethereum, attributed to North Korea's Lazarus Group, stands as the largest cryptocurrency theft ever recorded and the clearest single statement of what Pyongyang is actually after online. Scale it out further: DPRK-linked actors stole $2.02 billion in 2025 alone, a 51% jump year over year, bringing the all-time cumulative haul to $6.75 billion, and accounting for 76% of all crypto hack value through April 2026. Chainalysis put a finer point on it with 2024 numbers: $1.3 billion stolen across 47 separate incidents. That volume carries equal weight to the dollar total. This is a systematic assembly line.

Lazarus sits inside North Korea's Reconnaissance General Bureau, and the indictments name specific people within that structure, which gives defenders an actual chain of command to map against observed behavior instead of guessing at an org chart. There's a second track running alongside the theft, too: fraudulent IT worker schemes, where North Korean operatives take remote tech jobs under false identities. OFAC designated six individuals and two entities for running schemes that generated close to $800 million in 2024, and an interagency advisory noted individual operatives can pull in as much as $300,000 a year, with Pyongyang skimming off up to 90% of it for the state.

Recovery is possible, just limited. The DOJ seized more than $15 million in stolen cryptocurrency from four platforms in 2023, proof that asset recovery is a real, operational capability for anyone advising clients on crypto exposure. The Tornado Cash case carries significant weight: OFAC designated the mixing service in 2022, and co-founder Roman Storm was convicted in 2025. That's one of Lazarus's go-to laundering tools, gone, and sometimes the most effective move is pulling the plug on the infrastructure they all depend on, targeting the system over the individual.

Iran and Russia: two different uses of the hack-and-leak model and what the charging documents reveal about targeting logic

Iran and Russia both run hack-and-leak operations, but the charging documents show two different targeting philosophies underneath the same playbook.

The September 2024 indictment against three IRGC employees, Masoud Jalili, Seyyed Ali Aghamiri, and Yaser Balaghi, charged them with breaking into the accounts of U.S. officials, journalists, NGO staff, and campaign workers, then trying to funnel the stolen material to the opposing campaign and to the press. The stated objective in the documents is dual-purpose: hurt one specific campaign, and chip away at public confidence in the electoral process generally. Read that motive as a filter, and you can predict what similar Iranian operations will target next. This behavior also has a long history behind it; a 2016 DOJ indictment against Iranian actors for DDoS attacks on the U.S. financial sector puts a multi-decade paper trail behind Iran's cyber program, useful for anyone building a longitudinal threat model grounded in the full historical record.

Russia's approach, laid out in a December 2024 indictment against three Russian nationals and two St. Petersburg companies, Medialand LLC and ML.Cloud LLC, on charges of computer fraud, wire fraud, and money laundering, comes with a $10 million Rewards for Justice bounty attached. That bounty is a signal in itself: high attribution confidence, and a stated intent to keep escalating.

Then there's the case that undercuts the whole idea of indictments as deterrence. GRU officer Anatoliy Sergeyevich Kovalev was indicted for the 2016 election interference operation, and he was charged again in 2020. Same person, same agency, four years apart, still operating. If an indictment were actually stopping people, that name wouldn't appear twice.

Why indictments have not stopped any of these actors, and what they have actually changed

None of these four countries has stopped hacking because of an indictment. The record backs it up conclusively.

Despite the first-ever PRC indictment coming in 2014, Chinese state hackers have since been indicted for economic espionage more than once. Kovalev's double indictment tells the same story from the Russian side: charged, unbothered, charged again. On a strict definition of deterrence as behaviour stopped, these are the two clearest counterexamples in the whole record.

CSIS's framing holds up better than a simple deterrence argument, though. Indictments and sanctions earn their value by imposing real costs on individuals and choking off pieces of the financial infrastructure those operations run on, independent of whether any single operation is stopped outright. Consider what happened after the Evil Corp OFAC designation: ransomware victims suddenly faced sanctions violations for paying up, which changed victim behavior while Evil Corp's operations continued uninterrupted. The Tornado Cash case shows the same logic from a different angle, hit the laundering infrastructure and you degrade a specific capability, independent of whether the individual operator is ever caught. Asset seizures reinforce the same point: stolen proceeds remain recoverable even after landing on a blockchain.

The honest read for anyone doing this work professionally: indictments function best as a public record of confirmed tactics and a signal of how confident the U.S. government is in its attribution. Their value as intelligence outlasts whatever deterrent effect they were supposed to have.

Reading indictments as practitioner-grade threat intelligence

Here's what an indictment gives you that a typical vendor threat report doesn't: named individuals, organizational structure, specific tools, specific victim sectors, specific timeframes, and often indicators of compromise, all of it sworn to and tested against an evidentiary standard before it ever became public. That confidence tier sits well above an unattributed blog post calling something "a sophisticated threat actor."

The contractor layer the i-Soon indictment exposed is a structural insight of the first order. It tells defenders that infrastructure with a commercial face can still be state-directed, and that attribution work has to look past the actor sitting closest to the keyboard. Volt Typhoon's documented five-year dwell time gives you an actual baseline for how long living-off-the-land intrusions go unnoticed, which should feed directly into how a detection program gets designed, not filed away as a slide deck statistic. And the DPRK indictments, taken together, force three separate practitioner domains into a single threat model: crypto exchange security, IT hiring and identity verification, and sanctions compliance. Most teams keep those three in separate departments; North Korea treats them as a single integrated operation.

Look at the sector list across this entire body of indictments and it reads like a full risk audit: academia, aerospace, biomedical, the defence industrial base, healthcare, manufacturing, maritime, telecoms, government, and financial services. That is every major sector. If your organisation sits in any one of those, there is an indictment with your sector's name on it and your adversary's methods laid out in plain English. The practical discipline is simple enough to describe: read the "manner and means" and "overt acts" sections as tactic documentation, read the named defendants and their affiliations as organizational intelligence, and treat the gap between last known activity and the unsealing date as a rough floor for how long these actors can sit undetected.

Research groups that track this corpus over time, building cumulative analysis across filings, are the ones actually turning it into usable intelligence; Cyberou is one outlet doing that work, grounding its analysis in live threat activity and reading past the press release. That's really the discipline this whole body of documents rewards. Security vendors whose tools address the tactics these indictments describe have an unusually solid, publicly verifiable evidence base to build honest, specific content around, trading the vague "sophisticated nation-state actor" language for grounded, citable claims. The court record already did the hard part, and somebody just has to actually read it.

Sources

  1. darkreading.com
  2. justice.gov
  3. en.wikipedia.org
  4. fdd.org
  5. techtarget.com
  6. csis.org

More in hacker arrests and indictments