Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
North Korea🇰🇵 KP1 malware family

Jasper Sleet

Also known asJasper SleetStorm-0287

Jasper Sleet is a North Korean threat cluster tracked by Microsoft, formerly known as Storm-0287, associated with the DPRK remote IT worker scheme. Reported aliases include Storm-0287, PurpleDelta, Wagemole, Nickel Tapestry, and UNC5267. Microsoft has tracked this activity since at least early 2020. The operation centers on North Korean operatives posing as remote IT workers using stolen, rented, or fabricated identities to obtain employment at legitimate companies, historically with emphasis on U.S. organizations and technology-related roles, but with reported expansion globally. The scheme is described as a revenue-generation operation for the DPRK regime and weapons programs, while also enabling espionage, theft of sensitive information, and in some cases extortion. Reporting states these workers have infiltrated companies across multiple industries and may steal intellectual property, source code, trade secrets, credentials, and other sensitive records. Tradecraft described in the content includes creation of fraudulent digital personas using fake names, email addresses, social media profiles, GitHub and LinkedIn accounts, forged or altered identity documents, and professional-looking headshots. Microsoft observed Jasper Sleet using generative AI to research job postings on platforms such as Upwork, extract required skills, generate culturally appropriate names and email formats, tailor resumes and cover letters, and build reusable personas aligned to targeted roles. Microsoft also observed use of the Faceswap application to insert workers’ faces into stolen identity documents and generate polished resume photos, and use of voice-changing software during remote interviews to disguise accents. After gaining employment, Jasper Sleet reportedly uses AI-enabled communications to maintain cover, draft professional responses, answer technical questions in unfamiliar environments, generate code snippets, reduce language barriers, and sustain long-term fraudulent employment. The content also states that AI is used across the attack lifecycle to get hired, stay hired, and misuse access at scale. Microsoft further reported that North Korean actors including Jasper Sleet use AI to accelerate post-compromise tasks such as analyzing victim environments, identifying lateral movement paths, escalating privileges, locating credentials and sensitive data, and minimizing detection risk. Operational infrastructure and concealment methods mentioned in the content include VPNs, VPSs, proxy services, remote management tools, facilitator-operated laptop farms, and assistance from facilitators who validate identities, forward company hardware, and support freelance platform accounts. Tools and services specifically cited include Astrill VPN, JumpConnect, TinyPilot, Rust Desk, TeamViewer, AnyViewer, and AnyDesk. Microsoft reported disrupting this activity by suspending 3,000 Outlook/Hotmail accounts linked to the operation and implementing detections in Microsoft Entra ID Protection and Microsoft Defender XDR. The content also notes overlap with broader DPRK activity and references related clusters such as Coral Sleet, Sapphire Sleet, Moonstone Sleet, and general remote IT worker activity tracked by Microsoft under Storm-0287.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Software & Services

Where they're from

Attributed origin per open-source reporting.

  • KP
MITRE ATT&CK

Tradecraft

22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

12 of 15 tactics25 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
2 techniques
T1589×5
Gather Victim Identity Information
T1598×2
Phishing for Information
TA0042
Resource Development
2 techniques
T1585×5
Establish Accounts
T1586×2
Compromise Accounts
T1586.002
Email Accounts
TA0001
Initial Access
4 techniques
T1078×7
Valid Accounts
T1133×2
External Remote Services
T1199
Trusted Relationship
T1566×3
Phishing
T1566.002
Spearphishing Link
TA0002
Execution
1 technique
T1059
Command and Scripting Interpreter
TA0003
Persistence
3 techniques
T1078×7
Valid Accounts
T1133×2
External Remote Services
T1136
Create Account
TA0004
Privilege Escalation
1 technique
T1078×7
Valid Accounts
TA0005
Stealth
2 techniques
T1036×7
Masquerading
T1078×7
Valid Accounts
TA0008
Lateral Movement
2 techniques
T1021
Remote Services
T1550
Use Alternate Authentication Material
TA0009
Collection
1 technique
T1005
Data from Local System
TA0011
Command and Control
2 techniques
T1090
Proxy
T1219
Remote Access Tools
TA0010
Exfiltration
1 technique
T1537
Transfer Data to Cloud Account
TA0040
Impact
2 techniques
T1486
Data Encrypted for Impact
T1657
Financial Theft
ACTIVITY FEED

Recent activity

13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

itproNews
Mar 24, 2026
Observability will be key to agentic AI safety, says Microsoft Security exec | IT Pro

Uses AI to enhance tradecraft, including sustained large-scale misuse of legitimate access, identity fabrication through social engineering, and long-term persistence at low cost.

Read more
the hacker newsNews
Mar 18, 2026
OFAC Sanctions DPRK IT Worker Network Funding WMD Programs Through Fake Remote Jobs

North Korean IT worker operation using fake identities and fraudulent employment to infiltrate companies, generate revenue for the DPRK, steal sensitive data, and in some cases conduct extortion. The group also uses AI to fabricate identities, support social engineering, and maintain long-term access.

Read more
itproNews
Mar 9, 2026
Is your new hire an AI clone? Microsoft says North Korean hackers are using AI to impersonate job seekers and steal company secrets | IT Pro

Conducting North Korean fake-employee infiltration operations against western companies, using generative AI, voice-changing software, face-swapping, forged identity documents, and AI-assisted job applications to obtain and maintain remote employment inside organizations.

Read more
bleeping computerNews
Mar 7, 2026
Microsoft: Hackers abusing AI at every stage of cyberattacks

Uses generative AI to support North Korea-linked remote IT worker schemes by creating realistic fake identities (names, resumes, communications), tailoring personas to job postings, and maintaining access after being hired at Western companies.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping22

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal1

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.