Living intelligence brief · Updated September 2026

DPRK IT Worker Threat Intelligence

North Korean remote IT worker activity is tracked under several vendor names and overlaps with a wider DPRK cyber ecosystem. This page organizes the employment-focused activity, recurring TTPs, government guidance and operational intelligence defenders can use.

Intelligence snapshot

Primary objectiveRevenue generation

Employment and contractor income supports DPRK state interests and can violate sanctions.

Access modelLegitimate workforce access

The operator may enter through approved hiring, credentials and company-issued hardware.

Common concealmentFalse identity + remote infrastructure

Stolen identities, facilitators, laptop farms, VPNs, proxies and RMM tools recur across reporting.

Enterprise riskInsider access, theft and extortion

Government reporting documents sensitive-data theft, code theft, persistence and extortion.

How researchers track the activity

These names overlap around DPRK remote employment activity, but vendor taxonomies are not guaranteed to map one-to-one.

Research organizationTracking nameWhat it covers
Google / MandiantUNC5267IT worker operations using stolen identities to obtain remote employment or contractor access.
Microsoft Threat IntelligenceJasper SleetActivity associated with North Korea’s remote IT worker program. Microsoft also tracks related employment-focused clusters.
Palo Alto Networks Unit 42WagemoleNorth Korean operatives seeking unauthorized remote employment for financial gain and potential espionage.

Sources: Mandiant, Microsoft Threat Intelligence, and Unit 42.

Recurring TTPs

The employment operation is better understood as a chain of activity than as a single indicator.

PersonaAcquire or fabricate identity

Stolen identities, altered documents, false resumes, developer profiles and AI-assisted persona building.

EmploymentSecure remote role

Direct applications, freelance platforms, staffing firms and contractor routes.

InfrastructureAppear domestic

Facilitators, laptop farms, VPNs, VPSs, proxies and RMM software.

AccessOperate as a trusted user

Approved accounts, corporate devices and normal job activity.

Monetization / riskRevenue, theft or extortion

Salary generation, sensitive-data access, code theft and, in some cases, extortion.

Key government guidance

Eleven-government alert

A coordinated multinational warning on DPRK IT worker activity, including false identities, facilitators, laptop farms, remote access and AI-assisted impersonation.

Read imper.ai analysis →

FBI / IC3: threats to U.S. businesses

Detailed guidance on facilitators, U.S.-based infrastructure, equipment shipping, payment accounts, interviewing and contracted IT workers.

Read FBI / IC3 guidance →

FBI / IC3: data extortion

Warns that some workers have exfiltrated proprietary information and code, harvested credentials and extorted employers after discovery.

Read the FBI alert →
FBI enforcement evidence

Known individuals are only one visible layer of the operation

The FBI’s DPRK IT Workers wanted page publicly identifies 14 individuals allegedly involved in a conspiracy to generate and launder revenue for the North Korean regime. The bureau says federal arrest warrants were issued in December 2024.

The poster is valuable threat-intelligence context because it demonstrates direct U.S. law-enforcement action against the scheme. It should not be used as a visual watchlist for hiring teams. Organizations still need to detect unknown or reused identities, facilitators, remote operators and infrastructure that will not appear on a wanted poster.

14individuals named by the FBI
Dec. 2024federal arrest warrants issued
Up to $5MRewards for Justice offer described by FBI
Source: Federal Bureau of Investigation. Poster shown unaltered and linked to the original FBI source.
Official FBI DPRK IT Workers wanted poster

Do not conflate every DPRK job campaign

North Korean IT worker operations involve people seeking legitimate employment under concealed identities. Other DPRK campaigns may instead pose as recruiters or employers to infect job seekers with malware. The actors, infrastructure and objectives can overlap, but the attack models are different and should be investigated separately.

IT worker operationAttacker seeks employment

Goal: enter the enterprise as a trusted worker or contractor.

Malicious recruitmentAttacker poses as employer

Goal: compromise job seekers or developers through recruitment lures.

What threat-intelligence teams should operationalize

Infrastructure

Known VPNs, proxies, laptop-farm IPs, VPSs and remote-access tooling.

Identity patterns

Reused personas, phones, email accounts, resumes, payment details and addresses.

Workforce events

Interview, onboarding, shipping, device enrollment and recovery anomalies.

Feedback loop

Feed internal investigations back into hunting, watchlists and recruiter / Help Desk guidance.

Threat intelligence FAQ

Are UNC5267, Jasper Sleet and Wagemole the same group?

They are vendor tracking labels for overlapping North Korean remote IT worker activity, but each vendor’s taxonomy and clustering methodology is different. They should not automatically be treated as exact synonyms.

What is the primary objective of DPRK IT workers?

Government and private-sector reporting consistently identifies revenue generation as a central objective. The access can also create opportunities for espionage, sensitive-data theft, persistence and extortion.

What infrastructure is commonly associated with the schemes?

Reporting repeatedly documents VPNs, VPSs, proxy services, RMM software, remote desktop tools, U.S.-based facilitators and laptop farms.

How should threat intelligence connect to internal security teams?

Translate external reporting into hiring checks, watchlists, network detections, Help Desk escalation criteria and incident-response playbooks, then feed internal findings back into threat hunting.

Turn threat intelligence into workforce controls

imper.ai helps surface device, network and operating-environment signals during hiring and other high-risk workforce interactions.