
The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) has imposed sanctions on six people and two organizations involved in a North Korean IT worker program aimed at deceiving American businesses to generate revenue for its weapons programs.
“The North Korean government targets U.S. companies through deceptive tactics by overseas IT operatives who misuse sensitive data and extort businesses for large sums,” said Treasury Secretary Scott Bessent.
The deceptive scheme, also known as Coral Sleet/Jasper Sleet, PurpleDelta, and Wagemole, uses fake documents, stolen identities, and invented personas to help IT workers hide their true identities and secure employment at legitimate companies in the U.S. and other countries. A large portion of their earnings are then sent back to North Korea to support its missile programs, violating international sanctions.
In some instances, these efforts are supported by deploying malware to steal confidential information, and demanding ransoms to prevent the release of stolen data.
The individuals and entities sanctioned by OFAC are listed below –
This development follows LevelBlue’s report on the IT worker scheme’s use of Astrill VPN to conduct operations from countries like China, leveraging the service’s ability to bypass China’s internet censorship. They tunnel traffic through U.S. exit nodes, posing as legitimate U.S. employees.
“These actors often operate from China instead of North Korea due to its reliable internet infrastructure and ability to use VPNs to hide their true location,” security researcher Tue Luu said. “Lazarus Group’s subgroups, like Contagious Interview, rely on this capability to access the global internet, manage command-and-control infrastructure, and mask their real location.”
The cybersecurity company also reported an unsuccessful North Korean attempt to infiltrate an organization by responding to a job advertisement. The IT worker, hired on August 15, 2025, as a remote Salesforce data employee, was terminated 10 days later due to consistent logins from China.
A key aspect of Jasper Sleet’s approach is using AI for identity creation, social engineering, and long-term operational persistence at a low cost, highlighting how AI-powered services reduce technical barriers and enhance threat actors’ abilities.
“Jasper Sleet uses AI throughout the attack to get hired, stay employed, and misuse access at scale,” Microsoft said. “Threat actors are using AI to quickly gather information to develop convincing digital personas suited to specific job markets and roles.”
Another important component is using an AI application called Faceswap to insert North Korean IT workers’ faces into stolen documents and create professional headshots for resumes. This aims to enhance campaign precision and increase credibility by creating believable digital identities.
Additionally, remote IT workers have reportedly used agentic AI tools to create fake company websites and rapidly generate, refine, and reimplement malware, sometimes by jailbreaking large language models (LLMs).
“Threat actors like North Korean remote IT workers depend on long-term, trusted access,” Microsoft said. “Therefore, defenders should treat fraudulent employment and access misuse as an insider-risk scenario, focusing on detecting unauthorized credential usage, unusual access patterns, and consistent, low-level activity.”
A detailed report by Flare and IBM X-Force revealed that these IT workers use timesheets to track job applications and progress, IP Messenger (IPMsg) for internal communication, and Google Translate to translate job descriptions, create applications, and interpret responses from tools like ChatGPT.
The IT worker scheme has a tiered structure involving recruiters, facilitators, IT workers, and collaborators, each with a different role –
“With the help of recruited Western collaborators, mainly from LinkedIn and GitHub, who knowingly or unknowingly provide their identities, NKITW can penetrate organizations more effectively and for longer periods,” the companies said in a report shared with The Hacker News.
“North Korea’s IT worker operations are widespread and deeply integrated within the DPRK party-state, serving as a crucial part of its revenue generation and sanctions evasion efforts.”
#evade #funding #korean #news #north #remote #sanctions #schemes. #via #wmds: #work #workers’ — News
© Bulletproof Servers. All rights reserved.