OAK — OnChain Attack Knowledge

Threat actor · OAK-G04

OAK-G04 — DPRK IT-Worker Placement Scheme

Aliases
"DPRK IT workers," "North Korean IT worker fraud scheme," "remote-IT-worker placement scheme," sometimes referred to in industry forensic reporting as the "insider-as-revenue-channel" complement to Lazarus / TraderTraitor (OAK-G01) cyber operations. Named operator-network entities in the public record include the Chinyong Information Technology Cooperation Company (a.k.a. Jinyong IT Cooperation Company; sanctioned May 23, 2023) and U.S.-based laptop-farm facilitators (Christina Marie Chapman, Erick Ntekereze Prince, Emanuel Ashtor, and others named in DOJ indictments).
First observed in crypto
approximately 2018, per industry forensic reporting that DPRK IT workers were obtaining engineering roles at crypto and Web3 firms under false identities by at least that year. Public attribution and enforcement action accelerate from 2022 forward.
Attribution status
confirmed at the scheme-and-named-facilitator level — joint U.S. State / Treasury / FBI advisory dated May 16, 2022 ([fbidprkitworker2022]); OFAC SDN designations of Chinyong IT Cooperation Company and Kim Sang Man on May 23, 2023 ([treasurydprkitworker2023]); multiple DOJ indictments and convictions, including the Christina Marie Chapman "laptop farm" prosecution (guilty plea February 2024; sentenced 102 months / July 2025) ([dojchapmanindictment2024]) and the Jin Sung-Il / Pak Jin-Song et al. five-defendant indictment (Southern District of Florida, January 2025); March 2026 OFAC round designating six individuals and two entities for IT-worker fraud ([ofac2026dprkitworker]). Attribution that specific crypto-firm exploits are downstream of an OAK-G04 placement (Munchables March 2024; Solareum and other industry-reported cases) is inferred-strong from forensic providers (Chainalysis, TRM Labs, ZachXBT) where the on-chain signature, hire-then-exploit timeline, and identity-overlap evidence are jointly documented.
Active
yes (as of v0.1) — Chainalysis estimates the IT-worker stream generated approximately $800M for the DPRK in 2024 and the channel is continuing to expand into 2025–2026 per [chainalysis2024dprk] and follow-on Chainalysis reporting; OFAC is sustaining a tempo of designations against the network, and DOJ indictments and laptop-farm prosecutions are ongoing.

Description

OAK-G04 is the DPRK IT-worker placement scheme: a state-directed revenue-generation channel under which DPRK-affiliated workers obtain remote engineering and IT roles at Western firms — disproportionately at crypto, Web3, and DeFi companies — under fabricated, stolen, or synthetic identities, and then either remit salary to the regime, exfiltrate funds via insider access, or both. The scheme is operationally and conceptually distinct from OAK-G01 (Lazarus / DPRK direct cyber attacks) along three axes: (1) vector: G04 is a placement-and-employment-fraud scheme operating through hiring pipelines, not an intrusion campaign; (2) attribution surface: G04 attribution is sanctions-and-employment-fraud-led (advisories, OFAC designations of the worker-deployment entities, DOJ indictments of laptop-farm facilitators) rather than wallet-cluster-and-malware-fingerprint-led; (3) role in the kill chain: G04 is a sustained insider-access / revenue-skim channel; G01 is point-in-time extraction. The two Groups intersect: a worker placed via G04 may be the off-chain entry vector for a G01 extraction event, and several public cases support that pattern.

The scheme's modern-public profile begins with the joint U.S. Department of State / Treasury / FBI advisory of May 16, 2022 ([fbidprkitworker2022]), which described in operational detail how DPRK IT workers obtain remote freelance and full-time positions, the red-flag indicators (multi-IP logins from disparate countries, payment-routing through Chinese bank accounts, requests for cryptocurrency settlement, identity inconsistencies across platforms), and the regime's revenue-extraction model. OFAC's May 23, 2023 designation of Chinyong IT Cooperation Company and its Vladivostok-based representative Kim Sang Man ([treasurydprkitworker2023]) was the first sanctions action specifically targeting the worker-deployment infrastructure rather than only the proceeds. The Christina Marie Chapman prosecution ([dojchapmanindictment2024]) — a U.S.-based "laptop farm" operator who hosted company-issued workstations to make remote DPRK workers appear domestic — is the canonical worked example of the U.S.-side facilitator role in the scheme; the case generated more than $17M in illicit revenue across more than 300 U.S. companies. The Jin Sung-Il / Pak Jin-Song five-defendant indictment (Southern District of Florida, January 2025) named two North Korean nationals and three facilitators for activity from approximately April 2018 through August 2024 against at least 64 U.S. companies. A March 2026 OFAC designation round added six individuals and two entities specifically for IT-worker fraud ([ofac2026dprkitworker]).

The crypto-specific significance of G04 is twofold. First, per [chainalysis2024dprk] and follow-on Chainalysis reporting, the IT-worker channel produced an estimated $800M for the DPRK in 2024 alone — a materially-sized revenue stream that has grown as direct-attack defenses have improved against G01 operations. Second, G04 placements have produced documented insider-access exploits at crypto firms: the Munchables case (March 26, 2024; ~$62.5M ETH on Blast, with funds ultimately returned) is the cleanest worked example of a DPRK-developer hire-then-exploit chain, with the project having hired four developers believed to be the same person under different GitHub identities (NelsonMurua913, Werewolves0493, BrightDragon0719, Super1114). Industry reporting ([coindesk2024dprkinfiltration]) names additional crypto projects that have unknowingly hired DPRK IT workers, including Injective, ZeroLend, Fantom, Sushi, Yearn Finance, and Cosmos Hub, and characterises more than 40 DeFi platforms as having inadvertently employed DPRK-affiliated developers. The defender-relevant point is that G04 makes the hiring pipeline itself a primary attack surface for crypto firms, in addition to the more-familiar G01 social-engineering and supply-chain vectors.

Targeting profile

OAK-G04 does not "target" victims in the upstream-extraction sense; the scheme's operational counterparties and impacted parties are:

  • Crypto exchanges, Web3 startups, and DeFi protocols — the disproportionately-affected industry segment, both because of compensation levels and because remote-first hiring norms reduce identity-verification friction.
  • Non-crypto Western tech firms — the scheme also operates broadly against Fortune 500 companies and U.S. defense suppliers; the Chapman case alone touched more than 300 U.S. companies, and the FBI advisory frames the scheme as a cross-industry threat.
  • Freelance and remote-work platforms — Upwork, Fiverr, GitHub-based contracting, and similar venues are explicitly named in the May 2022 advisory as scheme abuse vectors.
  • Identity-document subjects (U.S. residents whose identities are stolen / borrowed) — secondary victims; the Chapman case documented $17M reported to the IRS / SSA in the names of real U.S. individuals.
  • Downstream crypto users — when a G04 placement produces an insider-extraction event (Munchables-class), the protocol's users are the ultimate financial victims even though the firm is the proximate target.

Observed Techniques

OAK v0.1 does not yet have a dedicated insider-placement Tactic (this is a TAXONOMY-GAPS candidate; see Discussion). Existing on-chain Techniques observed in OAK-G04-attributable activity include:

  • OAK-T8.001 (Common-Funder Cluster Reuse) — the attribution-side Technique used by Chainalysis, TRM Labs, and independent investigators (notably ZachXBT) to link salary-remittance addresses across G04-placed workers and to associate exploit-proceeds addresses with prior salary-receipt activity. The persistence of remittance-cluster identity across employer rotations is a defining G04 fingerprint.
  • OAK-T7.002 (CEX Deposit-Address Layering) — the canonical off-ramp for both salary remittance and small-scale insider exfiltration (the Munchables exploiter cashed out ~$6,220 to a MEXC deposit address before the operation was unwound).
  • OAK-T9.004 (Access-Control Misconfiguration) — applicable when the insider-extraction step exploits privileged developer / deployer keys held legitimately by the G04-placed worker (the Munchables case is in this class: the developer used proxy-contract upgrade authority to assign themselves a 1M-ETH internal balance).
  • OAK-T11.001 (Third-Party Signing/Custody Vendor Compromise) — adjacent Technique when the G04 placement is at a vendor (custody, multisig tooling, signing infrastructure) whose access fans out to multiple downstream firms; the public record contains industry-forensic claims that G04-placed workers have been hired at vendors in the G01 supply-chain target set, and OAK should track this overlap as the G01 × G04 chain matures.
  • Pre-incident vectors not yet in OAK v0.1 scope (TAXONOMY-GAPS candidates):
  • Identity fabrication and synthetic-identity hiring fraud — the off-chain entry vector that defines G04. A future OAK Tactic for "off-chain operator-placement-as-entry-vector" should subsume this and the G01 social-engineering / fake-job-offer pattern under a single insider / personnel attack-surface category.
  • Laptop-farm facilitator infrastructure — the U.S.-domestic enabling layer (Chapman, Ntekereze, Ashtor) is governance-and-policy-layer behaviour outside the on-chain Tactic taxonomy at v0.1 but is essential context for any defender model of G04.

Observed Examples

  • examples/2024-03-munchables.md — Munchables (March 26, 2024) — ~$62.5M. DPRK developer(s) hired into the project's smart-contract team across four overlapping GitHub identities; insider used proxy-contract upgrade authority to mint a 1M-ETH internal balance on Blast and drained ~17,414 ETH. Industry forensic reporting ([chainalysis2024dprk], [coindesk2024dprkinfiltration]) attributes the activity to a DPRK-IT-worker-placement chain rather than a G01 direct-attack chain. Funds were ultimately returned (the perpetrator was identified rapidly and faced laundering-pipeline friction). Canonical G04 insider-extraction worked example. Attribution at inferred-strong.
  • Chinyong IT Cooperation Company / Kim Sang Man designation (May 23, 2023). OFAC SDN designation of the named DPRK worker-deployment entity and its Vladivostok-based salary-remittance representative ([treasurydprkitworker2023]). The first sanctions action specifically targeting the worker-deployment infrastructure layer of G04. Attribution at confirmed.
  • U.S. v. Christina Marie Chapman (D.D.C., guilty plea Feb 11, 2024; sentenced 102 months July 24, 2025). Arizona laptop-farm operator; >$17M in illicit revenue; >300 U.S. companies affected; 49 laptops shipped to a Chinese border city near North Korea ([dojchapmanindictment2024]). The canonical U.S.-domestic-facilitator case. Attribution at confirmed.
  • U.S. v. Jin Sung-Il, Pak Jin-Song, et al. (S.D. Fla., indictment unsealed January 2025). Five-defendant indictment naming two North Korean nationals and three facilitators (one Mexican national, two U.S. nationals) for an April 2018 – August 2024 scheme touching at least 64 U.S. companies; $866,255 from ten of those companies, laundered through a Chinese bank account. Attribution at confirmed.
  • March 2026 OFAC designation round. Six individuals and two entities designated for IT-worker fraud generating "nearly $800 million in 2024" per Chainalysis ([ofac2026dprkitworker]). Sustains the post-2022 enforcement tempo. Attribution at confirmed.
  • Industry-reported additional placements. Per [coindesk2024dprkinfiltration] and TRM Labs reporting, named crypto projects that have unknowingly employed DPRK IT workers include Injective, ZeroLend, Fantom, Sushi, Yearn Finance, Cosmos Hub, and the Solareum team (the latter hired a North Korean developer less than four months before being hacked, per DOJ statements cited in Chainalysis reporting). More than 40 DeFi platforms are characterised as inadvertently employing DPRK-affiliated developers at some point. Attribution at inferred-strong per project; the cohort-level claim is documented across multiple forensic providers.

Citations

  • [fbidprkitworker2022] — joint U.S. State / Treasury / FBI advisory, May 16, 2022; primary public-record characterisation of the scheme.
  • [treasurydprkitworker2023] — Treasury press release JY1498 (May 23, 2023) designating Chinyong IT Cooperation Company and Kim Sang Man.
  • [dojchapmanindictment2024] — DOJ press releases on the Christina Marie Chapman case (indictment, guilty plea, and sentencing).
  • [ofac2026dprkitworker] — March 12, 2026 OFAC designation round against six individuals and two entities for IT-worker fraud.
  • [chainalysis2024dprk] — DPRK-attributed scale, including $800M IT-worker-channel estimate for 2024 (companion citation; cited from G01 as well).
  • [coindesk2024dprkinfiltration] — industry feature documenting the DPRK-IT-worker infiltration of crypto firms, with named projects and the Munchables-class chain.

Discussion

On the attribution-strength split. The scheme as a category and the named worker-deployment / facilitator entities are confirmed — multiple OFAC designations, multiple DOJ indictments and convictions, and a joint State / Treasury / FBI advisory. Per-firm claims that this hire was a DPRK IT worker who later caused this exploit are typically inferred-strong unless the specific case appears in a court filing or Treasury press release naming the placement and the firm. OAK contributors writing G04-attributed examples should preserve this split per-incident, as with G03.

On why OAK-G04 is placement-and-employment-fraud rather than cyber-attack. Structuring G04 as a separate Group from G01 reflects the public-record reality that the DPRK runs distinct revenue-generation pipelines under different operational ownership, with different attribution surfaces and different defender controls. Conflating G04 into G01 would (a) obscure the hiring-pipeline attack surface that is the defining G04 control point, (b) misrepresent the scheme's primary attribution evidence (sanctions-and-employment-fraud rather than malware-and-wallet-cluster), and (c) waste the framework's ability to recommend distinct defender controls for the two pipelines. The Lazarus / TraderTraitor branding within G01 already covers DPRK direct cyber attacks; G04 is the parallel category for placement-fraud.

On the relationship to OAK-G01. G01 and G04 are complementary pipelines under shared state direction, not competing or identical operations. The two intersect in cases where a G04 placement provides the off-chain entry vector for a G01 extraction event — a chain that is operationally efficient for the regime but is operationally separable for defender controls. Hiring-pipeline controls (multi-source identity verification, video-attestation interviews, in-person work-authorization checks, GitHub-history-and-IP-address forensics) defend against G04. Engineering-pipeline controls (signer-key segregation, multisig-vendor diligence, supply-chain-build attestation, social-engineering training) defend against G01. A defender investing in only one set leaves the other pipeline open. OAK's separation of the two Groups is intended to make this control split explicit.

On the relationship to OAK-G03. G04 and G03 share the infrastructure-with-distinct-jurisdictional-substrate pattern — Chinyong / Kim Sang Man (Russia-based DPRK-operated worker deployment) and Garantex / Grinex (Russia-resident laundering infrastructure) both rely on Russia-territory operational substrate, but the operator profile and role in the kill chain are different. G04 produces revenue and insider access; G03 launders proceeds. Joint coverage at the Russia-jurisdictional layer is reasonable for state-level policy work, but at the per-firm defender-control level the two Groups remain distinct.

On TAXONOMY-GAPS. OAK v0.1's Tactic catalog does not have a clean home for insider-placement-as-entry-vector or for off-chain hiring-pipeline compromise. Both G01 (LinkedIn fake-job-offer payload delivery; supply-chain workstation compromise) and G04 (placement-fraud-with-insider-access) sit in this gap and are tracked in their respective Group pages with explicit "pre-incident vectors not yet in OAK" notes. A v0.x OAK update may introduce a dedicated Tactic for "operator-placement and personnel-pipeline compromise" that subsumes both patterns and gives Group pages a non-narrative anchor for these vectors.

On v0.x evolution. G04's 2026+ trajectory will depend on (a) whether AI-assisted identity fabrication tooling further compresses the diligence advantage of legitimate hiring pipelines (already noted in CNN and TRM Labs reporting), (b) whether enforcement against U.S.-domestic facilitators (Chapman-class cases) continues at sufficient tempo to make laptop-farm operation a deterrent-relevant offense, and (c) whether the cohort of crypto firms that have unknowingly hired DPRK workers expands further as more historical placements are unwound through forensic linkages. OAK should update this entry as the public record evolves; the attribution-strength conventions documented here apply to all such updates.