Coral Sleet is a North Korean state-linked threat actor associated with the DPRK’s fraudulent remote IT worker ecosystem and broader cyber intrusion activity. The group is also tracked as Storm-1877 and has been referred to by other teams as PurpleDelta and Wagemole. Its operations support revenue generation for the North Korean regime and also create opportunities for follow-on espionage, insider abuse, data theft, and extortion. Coral Sleet is one of the crews behind long-running fake IT worker schemes in which operatives use fabricated or stolen identities, tailored resumes, forged professional personas, and deceptive interview practices to obtain remote employment at foreign companies. The actor has used AI extensively to accelerate persona creation, tailor applications to specific job markets and roles, generate multilingual social-engineering content, and sustain believable communications after hiring. Reported tradecraft includes use of voice-masking during interviews, AI-assisted identity fabrication, and maintenance of long-term fraudulent access inside victim organizations. Beyond employment fraud, Coral Sleet has used AI-assisted development platforms to rapidly create and manage high-trust web infrastructure at scale for campaign staging, testing, and command-and-control operations. The group has also used AI coding tools to generate, refine, and reimplement malware components, demonstrating rapid iterative capability growth. Reporting further attributes to Coral Sleet experimentation with jailbroken AI models and agentic AI workflows to automate parts of the attack chain, including fake website creation, infrastructure provisioning, payload testing, and deployment. Coral Sleet’s observed capabilities span initial access, reconnaissance, persistence, defense evasion, credential and sensitive-data theft, privilege escalation, lateral movement, post-compromise analysis, malware development, and exfiltration. Since late 2024, DPRK fake IT worker activity associated with this ecosystem has reportedly escalated in some cases to theft of sensitive data and source code followed by ransom demands. Coral Sleet is part of a broader cluster of North Korean operators that includes Jasper Sleet and Sapphire Sleet, all of which have been observed using AI as a force multiplier across the attack lifecycle.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
North Korean state-sponsored operatives posing as remote IT workers to obtain employment at foreign companies, funnel salaries to the DPRK regime, and more recently steal sensitive data and source code for extortion.
Uses AI to enhance tradecraft, including sustained large-scale misuse of legitimate access, identity fabrication through social engineering, and long-term persistence at low cost.
Identified as one of the North Korean groups using AI to enhance fake-worker schemes aimed at infiltrating western companies through remote hiring processes.
North Korea-linked activity cluster observed using development platforms (and, per the broader article theme, agentic/automated AI assistance) to rapidly stand up, manage, and scale attack infrastructure, improving campaign staging, testing, and C2 operations; also referenced as being involved in the 'fake IT worker' scam.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.