Jasper Sleet — APT Profile
Jasper Sleet is a North Korean state-sponsored threat actor tracked by Microsoft Threat Intelligence, representing North Korea's fraudulent remote IT worker program active since at least 2020. Operating under fabricated identities with AI-assisted resume generation, face-swapping tools such as Faceswap, and real-time voice-changing software, the group infiltrates Western technology, manufacturing, healthcare, financial services, and energy organizations by securing legitimate remote employment. Once hired, operators deploy PiKVM hardware devices as out-of-band access channels to bypass EDR controls and exfiltrate sensitive data covertly. Microsoft has suspended over 3,000 Outlook and Hotmail accounts linked to Jasper Sleet activity and coordinated takedowns with the US Department of Justice, which seized 29 financial accounts and disrupted laptop farms across 16 US states.Also tracked as
Storm-0287
IntelFusions coverage (1)
- North Korean IT Workers and the AI-Enabled Attack Chain: Inside Microsoft's Threat Intelligence Report 2026-03-06 · AI Security
Tools & malware
- AnyDesk remote_access
- AnyViewer remote_access
- Astrill VPN anonymization
- Azure Virtual Desktop (AVD) anonymization
- Faceswap ai_tool
- JumpConnect remote_access
- Large Language Models (LLMs) ai_tool
- PiKVM hardware_implant
- RustDesk remote_access
- TeamViewer remote_access
- TinyPilot hardware_implant
- Voice-changing software anonymization
Vendor research
- Jasper Sleet: North Korean remote IT workers' evolving tactics to infiltrate organizations Microsoft Threat Intelligence
- Microsoft Defender Experts Disrupt Jasper Sleet's Insider Access Campaign Microsoft Defender Experts
- AI as tradecraft: How threat actors operationalize AI Microsoft Threat Intelligence