Living intelligence brief · Updated September 2026
DPRK IT Worker Threat Intelligence
North Korean remote IT worker activity is tracked under several vendor names and overlaps with a wider DPRK cyber ecosystem. This page organizes the employment-focused activity, recurring TTPs, government guidance and operational intelligence defenders can use.
Intelligence snapshot
Employment and contractor income supports DPRK state interests and can violate sanctions.
The operator may enter through approved hiring, credentials and company-issued hardware.
Stolen identities, facilitators, laptop farms, VPNs, proxies and RMM tools recur across reporting.
Government reporting documents sensitive-data theft, code theft, persistence and extortion.
How researchers track the activity
These names overlap around DPRK remote employment activity, but vendor taxonomies are not guaranteed to map one-to-one.
| Research organization | Tracking name | What it covers |
|---|---|---|
| Google / Mandiant | UNC5267 | IT worker operations using stolen identities to obtain remote employment or contractor access. |
| Microsoft Threat Intelligence | Jasper Sleet | Activity associated with North Korea’s remote IT worker program. Microsoft also tracks related employment-focused clusters. |
| Palo Alto Networks Unit 42 | Wagemole | North Korean operatives seeking unauthorized remote employment for financial gain and potential espionage. |
Sources: Mandiant, Microsoft Threat Intelligence, and Unit 42.
Recurring TTPs
The employment operation is better understood as a chain of activity than as a single indicator.
Stolen identities, altered documents, false resumes, developer profiles and AI-assisted persona building.
Direct applications, freelance platforms, staffing firms and contractor routes.
Facilitators, laptop farms, VPNs, VPSs, proxies and RMM software.
Approved accounts, corporate devices and normal job activity.
Salary generation, sensitive-data access, code theft and, in some cases, extortion.
Key government guidance
Eleven-government alert
A coordinated multinational warning on DPRK IT worker activity, including false identities, facilitators, laptop farms, remote access and AI-assisted impersonation.
Read imper.ai analysis →FBI / IC3: threats to U.S. businesses
Detailed guidance on facilitators, U.S.-based infrastructure, equipment shipping, payment accounts, interviewing and contracted IT workers.
Read FBI / IC3 guidance →FBI / IC3: data extortion
Warns that some workers have exfiltrated proprietary information and code, harvested credentials and extorted employers after discovery.
Read the FBI alert →Known individuals are only one visible layer of the operation
The FBI’s DPRK IT Workers wanted page publicly identifies 14 individuals allegedly involved in a conspiracy to generate and launder revenue for the North Korean regime. The bureau says federal arrest warrants were issued in December 2024.
The poster is valuable threat-intelligence context because it demonstrates direct U.S. law-enforcement action against the scheme. It should not be used as a visual watchlist for hiring teams. Organizations still need to detect unknown or reused identities, facilitators, remote operators and infrastructure that will not appear on a wanted poster.
Do not conflate every DPRK job campaign
North Korean IT worker operations involve people seeking legitimate employment under concealed identities. Other DPRK campaigns may instead pose as recruiters or employers to infect job seekers with malware. The actors, infrastructure and objectives can overlap, but the attack models are different and should be investigated separately.
Goal: enter the enterprise as a trusted worker or contractor.
Goal: compromise job seekers or developers through recruitment lures.
What threat-intelligence teams should operationalize
Known VPNs, proxies, laptop-farm IPs, VPSs and remote-access tooling.
Reused personas, phones, email accounts, resumes, payment details and addresses.
Interview, onboarding, shipping, device enrollment and recovery anomalies.
Feed internal investigations back into hunting, watchlists and recruiter / Help Desk guidance.
Threat intelligence FAQ
Are UNC5267, Jasper Sleet and Wagemole the same group?
They are vendor tracking labels for overlapping North Korean remote IT worker activity, but each vendor’s taxonomy and clustering methodology is different. They should not automatically be treated as exact synonyms.
What is the primary objective of DPRK IT workers?
Government and private-sector reporting consistently identifies revenue generation as a central objective. The access can also create opportunities for espionage, sensitive-data theft, persistence and extortion.
What infrastructure is commonly associated with the schemes?
Reporting repeatedly documents VPNs, VPSs, proxy services, RMM software, remote desktop tools, U.S.-based facilitators and laptop farms.
How should threat intelligence connect to internal security teams?
Translate external reporting into hiring checks, watchlists, network detections, Help Desk escalation criteria and incident-response playbooks, then feed internal findings back into threat hunting.
Turn threat intelligence into workforce controls
imper.ai helps surface device, network and operating-environment signals during hiring and other high-risk workforce interactions.
