North Korean IT Workers Evade Sanctions, Funding WMDs via Remote Work Schemes.
Mar 20, 2026 // 14:03 - Niko Dunn


The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) has imposed sanctions on six people and two organizations involved in a North Korean IT worker program aimed at deceiving American businesses to generate revenue for its weapons programs.

“The North Korean government targets U.S. companies through deceptive tactics by overseas IT operatives who misuse sensitive data and extort businesses for large sums,” said Treasury Secretary Scott Bessent.

The deceptive scheme, also known as Coral Sleet/Jasper Sleet, PurpleDelta, and Wagemole, uses fake documents, stolen identities, and invented personas to help IT workers hide their true identities and secure employment at legitimate companies in the U.S. and other countries. A large portion of their earnings are then sent back to North Korea to support its missile programs, violating international sanctions.

In some instances, these efforts are supported by deploying malware to steal confidential information, and demanding ransoms to prevent the release of stolen data.

The individuals and entities sanctioned by OFAC are listed below –

  • Amnokgang Technology Development Company, an IT firm that manages overseas IT worker teams and illegally acquires and sells military and commercial technology through its international network.
  • Nguyen Quang Viet, the CEO of Vietnamese company Quangvietdnbg International Services Company Limited, which provides currency conversion services for North Koreans. It is estimated that the company converted approximately $2.5 million into cryptocurrency between mid-2023 and mid-2025.
  • Do Phi Khanh, an associate of Kim Se Un, who was sanctioned by the U.S. in July 2025. Do allegedly acted as Kim’s representative, allowing Kim to use his identity to open bank accounts and launder money from IT workers.
  • Hoang Van Nguyen, who also helps Kim open bank accounts and facilitates cryptocurrency transactions for Kim.
  • Yun Song Guk, a North Korean national who has managed a group of IT workers performing freelance IT work from Boten, Laos, since at least 2023. Yun has coordinated numerous financial transactions totaling over $70,000 with Hoang Minh Quang related to IT services, and has collaborated with York Louis Celestino Herrera to develop freelance IT service contracts.

This development follows LevelBlue’s report on the IT worker scheme’s use of Astrill VPN to conduct operations from countries like China, leveraging the service’s ability to bypass China’s internet censorship. They tunnel traffic through U.S. exit nodes, posing as legitimate U.S. employees.

“These actors often operate from China instead of North Korea due to its reliable internet infrastructure and ability to use VPNs to hide their true location,” security researcher Tue Luu said. “Lazarus Group’s subgroups, like Contagious Interview, rely on this capability to access the global internet, manage command-and-control infrastructure, and mask their real location.”

The cybersecurity company also reported an unsuccessful North Korean attempt to infiltrate an organization by responding to a job advertisement. The IT worker, hired on August 15, 2025, as a remote Salesforce data employee, was terminated 10 days later due to consistent logins from China.

A key aspect of Jasper Sleet’s approach is using AI for identity creation, social engineering, and long-term operational persistence at a low cost, highlighting how AI-powered services reduce technical barriers and enhance threat actors’ abilities.

“Jasper Sleet uses AI throughout the attack to get hired, stay employed, and misuse access at scale,” Microsoft said. “Threat actors are using AI to quickly gather information to develop convincing digital personas suited to specific job markets and roles.”

Another important component is using an AI application called Faceswap to insert North Korean IT workers’ faces into stolen documents and create professional headshots for resumes. This aims to enhance campaign precision and increase credibility by creating believable digital identities.

Additionally, remote IT workers have reportedly used agentic AI tools to create fake company websites and rapidly generate, refine, and reimplement malware, sometimes by jailbreaking large language models (LLMs).

“Threat actors like North Korean remote IT workers depend on long-term, trusted access,” Microsoft said. “Therefore, defenders should treat fraudulent employment and access misuse as an insider-risk scenario, focusing on detecting unauthorized credential usage, unusual access patterns, and consistent, low-level activity.”

A detailed report by Flare and IBM X-Force revealed that these IT workers use timesheets to track job applications and progress, IP Messenger (IPMsg) for internal communication, and Google Translate to translate job descriptions, create applications, and interpret responses from tools like ChatGPT.

The IT worker scheme has a tiered structure involving recruiters, facilitators, IT workers, and collaborators, each with a different role –

  • Recruiters, who screen potential IT workers and record initial interviews to send to facilitators.
  • Facilitators and IT workers, who create personas, secure freelance or full-time employment, and onboard new hires.
  • Collaborators, who provide their personal identity and information to help IT workers complete the hiring process and receive company devices.

“With the help of recruited Western collaborators, mainly from LinkedIn and GitHub, who knowingly or unknowingly provide their identities, NKITW can penetrate organizations more effectively and for longer periods,” the companies said in a report shared with The Hacker News.

“North Korea’s IT worker operations are widespread and deeply integrated within the DPRK party-state, serving as a crucial part of its revenue generation and sanctions evasion efforts.”

#evade  #funding  #korean  #news  #north  #remote  #sanctions  #schemes.  #via  #wmds:  #work  #workers’   —   News