DPRK IT Workers’ Fake Jobs Fund WMDs: OFAC Sanctions Network.
Mar 18, 2026 // 21:36 - Niko Dunn


The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) has imposed sanctions on six people and two organizations for their participation in North Korea’s (DPRK) IT worker program, which aims to cheat U.S. companies and generate funds for its weapons programs.

“The North Korean government targets U.S. businesses with deceptive tactics used by its IT workers abroad, who misuse sensitive data and demand money from companies,” stated Treasury Secretary Scott Bessent.

This deceptive scheme, also known as Coral Sleet/Jasper Sleet, PurpleDelta, and Wagemole, uses fake documents, stolen identities, and invented personas to help IT workers hide their true identities and get jobs at legitimate U.S. and other international companies. A large part of their earnings is then sent back to North Korea to support its missile programs, violating international sanctions.

Sometimes, these efforts are supported by using malware to steal confidential information and demanding ransom to prevent the release of stolen data.

The individuals and entities targeted by the latest OFAC sanctions are listed below:

  • Amnokgang Technology Development Company, an IT firm that manages teams of overseas IT workers and engages in illegal procurement activities to obtain and sell military and commercial technology through its international networks.
  • Nguyen Quang Viet, the CEO of Quangvietdnbg International Services Company Limited, a Vietnamese company that provides currency conversion services for North Koreans. It’s estimated that the company converted about $2.5 million into cryptocurrency between mid-2023 and mid-2025.
  • Do Phi Khanh, an associate of Kim Se Un, who was sanctioned by the U.S. in July 2025. Do allegedly acted as Kim’s representative, allowing Kim to use his identity to open bank accounts and launder money from IT workers.
  • Hoang Van Nguyen, who also assists Kim in opening bank accounts and facilitating cryptocurrency transactions.
  • Yun Song Guk, a North Korean national who led a group of IT workers doing freelance work from Boten, Laos, since at least 2023. Yun coordinated multiple financial transactions totaling over $70,000 with Hoang Minh Quang related to IT services and collaborated with York Louis Celestino Herrera to create freelance IT service contracts.

This development follows LevelBlue’s report on the IT worker scheme’s use of Astrill VPN to conduct operations in countries like China, taking advantage of the service’s ability to bypass China’s internet restrictions. The strategy involves routing internet traffic through U.S. servers, making them appear as legitimate U.S.-based employees.

“These malicious actors often operate from China instead of North Korea because of better internet infrastructure and the ability to use VPNs to hide their real location,” security researcher Tue Luu explained. “Lazarus Group subgroups, including Contagious Interview, rely on this capability to access the unrestricted global internet, manage their infrastructure, and conceal their actual location.”

The cybersecurity firm also reported a failed attempt by North Korea to infiltrate an organization by responding to a job posting. The IT worker, hired on August 15, 2025, as a remote employee to work on Salesforce data, was fired 10 days later due to suspicious logins from China.

A key aspect of Jasper Sleet’s method is using artificial intelligence to create fake identities, perform social engineering, and maintain long-term operations at a low cost. This highlights how AI-powered services can reduce technical challenges and enhance the capabilities of malicious actors.

“Jasper Sleet uses AI throughout the attack process to get employed, stay employed, and misuse access on a large scale,” Microsoft said. “Malicious actors are using AI to speed up the reconnaissance process, which informs the creation of compelling digital personas customized for specific job markets and roles.”

Another important element is the use of the AI application Faceswap to insert the faces of North Korean IT workers into stolen identity documents and create professional headshots for resumes. This aims to improve the precision of their campaigns and increase credibility by developing believable digital identities.

Additionally, it’s believed that these remote IT workers have used AI tools to create fake company websites and to quickly generate, improve, and re-implement malware components, sometimes by bypassing the restrictions of large language models (LLMs).

“Malicious actors, such as North Korean remote IT workers, rely on long-term, trusted access,” Microsoft stated. “Therefore, defenders should treat fraudulent employment and access misuse as an insider-risk situation, focusing on detecting misuse of legitimate credentials, unusual access patterns, and sustained, low-intensity activity.”

A detailed report by Flare and IBM X-Force, analyzing the methods employed by these IT workers, revealed that they use timesheets to track job applications and work progress, IP Messenger (IPMsg) for internal communication, and Google Translate to translate job descriptions, create applications, and even interpret responses from tools like ChatGPT.

The IT worker scheme is structured with multiple levels of operation, including recruiters, facilitators, IT workers, and collaborators, each playing a specific role:

  • Recruiters, who screen potential IT workers and record initial interviews to send to facilitators.
  • Facilitators and IT workers, who create personas, secure freelance or full-time employment, and onboard new hires.
  • Collaborators, who provide their personal identity and information to help IT workers complete the hiring process and receive company laptops.

“With the assistance of recruited Western collaborators, mainly from LinkedIn and GitHub, who willingly or unwillingly provide their identities for use in the IT worker fraud scheme, North Korean IT workers can penetrate organizations more deeply and reliably for a longer time,” the companies said in a report shared with The Hacker News.

“North Korea’s IT worker operations are extensive and deeply embedded within the North Korean government. They are crucial for generating revenue and bypassing sanctions.”

#dprk  #fake  #fund  #jobs  #network  #news  #ofac  #sanctions  #wmds:  #workers’   —   News