WageMole is a North Korea-linked state-sponsored threat activity cluster centered on fraudulent remote-employment schemes in which operatives use stolen, synthetic, or fabricated identities to obtain jobs at foreign companies. The activity is also tracked under overlapping labels including UNC5267, Jasper Sleet, DPRK IT worker operations, and North Korean IT worker schemes. It is part of a broader DPRK sanctions-evasion and revenue-generation ecosystem, while also creating insider-access opportunities that can support espionage, data theft, and follow-on cyber operations. WageMole operators pose as software developers and other skilled professionals, build forged résumés and developer profiles, and use fake references, front companies, and well-maintained technical personas to pass hiring workflows. Reported fronts associated with the activity include DredSoftLabs, MetaMint Studio, MegaMint Studio, and JSoft Labs. The operation has used freelance and recruiting platforms, forged identity documents, synthetic personas, and increasingly real-time deepfake technology during interviews. Facilitators help with account creation, identity verification, payments, bank access, mobile numbers, and laptop farms that allow workers to appear locally present in the victim’s country while remotely accessing employer-issued systems. The cluster primarily targets Western organizations, especially technology-focused employers, but reporting also shows expansion into government, defense-related organizations, financial services, health care, and non-technical professional work such as architecture and engineering. Small and mid-sized businesses have been repeatedly cited as targets, and software developers, Web3 firms, blockchain projects, and companies hiring remote technical talent are particularly exposed. WageMole is closely linked to the DPRK-linked DeceptiveDevelopment and Contagious Interview ecosystem. In that relationship, recruiter-themed malware operations compromise developers and steal identity material that can later support fraudulent job placement. Associated lure chains have used trojanized coding challenges, malicious repositories, and interview-themed social engineering to deliver malware families such as BeaverTail, InvisibleFerret, and OtterCookie. While those malware-delivery operations are often tracked separately, multiple reports assess that stolen victim information and identities are handed off into WageMole-style employment fraud workflows. Once embedded inside victim organizations, WageMole operators can create significant insider risk. Documented behavior includes abuse of corporate access, suspicious file transfers, unauthorized software execution, use of remote-management tooling, concealment of true location through VPNs and proxies, and theft or threatened release of sensitive data and source code. Recent reporting also indicates an increase in extortion by dismissed workers who threaten to leak proprietary information. The dominant purpose of the activity remains illicit revenue generation for the DPRK regime, including sanctions evasion and support to state priorities, but the access obtained can also enable espionage and broader post-compromise operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this threat actor.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.