Case Library / Deepfake & Synthetic Media / DPRK RevGen Massachusetts Scheme: Wang Brothers' Laptop Farms and Shell Companies for North Korean IT Workers

DPRK RevGen Massachusetts Scheme: Wang Brothers' Laptop Farms and Shell Companies for North Korean IT Workers

Two New Jersey men ran US "laptop farms" and shell companies that let North Korean IT workers pose as American remote employees at 100+ US firms, generating over $5 million for the DPRK regime and enabling theft of ITAR-controlled defense data before both were sentenced to federal prison in April 2026.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

Kejia "Tony" Wang and Zhenxing "Danny" Wang, two US nationals based in New Jersey, ran a multi-year scheme (roughly 2021 to October 2024) that placed North Korean IT workers into remote jobs at more than 100 US companies by disguising them as ordinary US-based remote employees. The workers used stolen identities of over 80 real Americans to get hired, and the Wangs created shell companies (Hopana Tech LLC, Tony WKJ LLC, Independent Lab LLC) plus "laptop farms" at their own residences to host victim-company laptops and route remote access to the overseas workers via KVM hardware. The scheme generated more than $5 million for the DPRK government and caused victim companies at least $3 million in remediation costs; one victim, a California AI/defense contractor, had ITAR-controlled technical data stolen by an overseas co-conspirator in early 2024. DOJ unsealed charges in June 2025, both men pleaded guilty (September 2025 and January 2026), and both were sentenced to federal prison in April 2026.

How the Attack Worked

From roughly 2021 to October 2024, North Korean IT workers and overseas co-conspirators (in China, the UAE, and Taiwan) used stolen and fabricated identities, compromising more than 80 real US persons, with fake driver's licenses and Social Security cards, to apply for and win remote IT jobs at over 100 US companies, including many Fortune 500 firms. Kejia "Tony" Wang served as the US-based manager, traveling to Shenyang and Dandong, China in 2023 to coordinate with overseas actors, including a North Korean former classmate, and supervising at least five US facilitators. Zhenxing "Danny" Wang was one of those facilitators. Once a fake candidate was hired, the victim company shipped a work laptop to a facilitator's US residence; the facilitators ran "laptop farms" of hundreds of hosted machines and connected each laptop to KVM (keyboard-video-mouse) switches or remote-desktop software, letting the real overseas worker operate it as if physically present in the US. The Wangs set up shell companies with matching websites and bank accounts, including Hopana Tech LLC, Tony WKJ LLC, and Independent Lab LLC, that had no real employees or operations but existed solely to receive victim-company wage payments and launder them onward to overseas co-conspirators. Separately, between January 19 and April 2, 2024, an overseas co-conspirator used this remote-access setup to break into the network of a California-based AI/defense contractor ("Company C" in court filings) and exfiltrate technical data marked as controlled under the International Traffic in Arms Regulations (ITAR).

The Lure & the Tell

The lure was a convincing "remote US-based IT professional" package: a stolen but real American identity (name, SSN, ID documents), a plausible resume, and a corporate laptop that authenticated and behaved as if it were sitting in a US facilitator's home, exactly what employers expect from a legitimate remote hire, especially post-pandemic when in-person verification norms had relaxed. The tell that eventually unraveled it was investigative and forensic rather than something the victim companies caught in real time: FBI/DCIS searches recovered more than 70 physical laptops and KVM devices from facilitator residences, seized 29 financial accounts and dozens of fraudulent domains tied to the shell companies, and traced wage payments from the Hopana Tech/Tony WKJ/Independent Lab accounts overseas. Publicly, the broader DPRK IT-worker campaign (documented by Microsoft, Unit 42, and other security researchers and incident-response firms) has been caught via secondary tells: device/network telemetry showing KVM or RMM software installed immediately after laptop provisioning, logins from Chinese/Russian IPs or Astrill VPN, workers who avoid camera use or fail unscripted personal questions, and shipping addresses that don't match the claimed identity.

Outcome

Charges were unsealed June 27-30, 2025 in the District of Massachusetts: Zhenxing Wang was arrested and indicted on a five-count indictment alongside eight overseas co-defendants (Chinese nationals Jing Bin Huang, Baoyu Zhou, Tong Yuze, Yongzhe Xu, Ziyou Yuan, and Zhenbang Zhou, and Taiwanese nationals Mengting Liu and Enchia Liu, all still at large as of April 2026); Kejia Wang was charged separately by criminal information and had already agreed to plead guilty. Kejia Wang pleaded guilty in September 2025 to conspiracy to commit wire fraud, money laundering, and identity theft; Zhenxing Wang pleaded guilty in January 2026 to conspiracy to commit wire fraud and money laundering. On April 15, 2026, US District Judge Nathaniel M. Gorton sentenced Kejia Wang to 108 months and Zhenxing Wang to 92 months in prison, each with 3 years of supervised release, $600,000 in forfeiture ($400,000 already recovered), and $29,236.03 in restitution from Kejia Wang. The action was part of a coordinated nationwide DOJ/FBI/DCIS/HSI effort that also searched 29 suspected laptop farms across 16 states, seized 29 financial accounts, 21 fraudulent websites, and roughly 200 computers, and separately charged a North Korean scheme that stole ~$900,000 in virtual currency from an Atlanta blockchain firm.

Why It Matters

This case is one of the most fully-documented US prosecutions showing how the DPRK's remote-IT-worker revenue scheme actually operates end to end: stolen identity plus a domestic laptop farm plus shell-company banking is enough to make a foreign, sanctioned operative look, to an employer's HR and IT systems, indistinguishable from a legitimate US remote hire. It matters for the deepfake/synthetic-identity education angle because it sits inside a documented wave of DPRK operations (per Microsoft, Unit 42, and CNN research on the same 2021-2024 timeframe) that increasingly layers AI-generated resumes, face-swapped ID photos, and even real-time deepfake video/voice on top of this same laptop-farm infrastructure, meaning organizations should assume identity verification, video interviews, and background checks can all be defeated simultaneously, and that the strongest signal is often behavioral/technical telemetry after hire (KVM/RMM installs, foreign IPs, VPN use) rather than anything visible during hiring itself. It also demonstrates concrete national-security fallout beyond fraud: theft of ITAR-controlled defense technology by workers who were never who they claimed to be.

Defenses

DOJ/FBI guidance issued alongside the case (and echoed by Microsoft's Jasper Sleet research and Unit 42's False Face report on the same DPRK campaign) recommends: requiring cameras on for every interview round and flagging candidates who report chronic video/audio "technical issues"; using unexpected, personally-anchored questions (e.g., local/historical references) that scripted or AI-assisted personas struggle with; verifying identity documents against live biometric/liveness checks rather than static uploads; scrutinizing resumes/background-check submissions for name, address, and date inconsistencies across platforms; calling references by phone or video rather than relying on email; flagging laptop shipping addresses that don't match the verified identity address or that change post-offer; monitoring for corporate-issued laptops authenticating from foreign IPs, KVM/RMM software installed immediately after provisioning, or use of VPN services (e.g., Astrill) associated with DPRK IT-worker infrastructure; and treating remote-only IT hiring pipelines as a distinct fraud-risk surface requiring HR-security collaboration, not just a staffing convenience.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Front-company and banking infrastructure setup: per the charging documents, an overseas handler ("Individual C," described as managing a North Korea-based IT company) directed Kejia Wang to register US shell companies (Hopana Tech, Tony WKJ) and corresponding bank and money-transfer-service accounts before any specific victim company was targeted, giving the scheme a bank-account-holding, seemingly legitimate US business front to hide behind.
Countering Stage 1: Shell-company and account formation is difficult to interdict before a specific victim is even chosen; the nearest realistic control is know-your-business (KYB) and beneficial-ownership screening at the banks and money-transfer services approving these accounts, which is also where this case was ultimately unwound (29 financial accounts seized).
2
Identity sourcing and validation: co-conspirators registered accounts with commercial online background-check services and ran public-records searches against more than 700 US persons to find and verify names, addresses, dates of birth, and Social Security numbers suitable for building convincing fake employee personas, per the indictment.
Countering Stage 2: Background-check and public-records providers can add anomaly detection for accounts running high-volume, sequential identity lookups (here, more than 700 searches from one account) rather than assuming every paying customer is a legitimate employer or verifier.
3
Document forgery: using the validated identity data, the conspirators created forged US driver's licenses, Social Security cards, and passports bearing an overseas IT worker's photo paired with a real American's personal information, consistent with the DOJ's May 2022 interagency advisory cited in the charging documents on how DPRK IT workers typically build cover identities.
Countering Stage 3: Employers should verify identity documents through live biometric or liveness-based checks rather than accepting static uploaded photos of IDs, since forged documents are built to pass a visual, one-time glance rather than a real-time challenge.
4
Persona and resume engineering: overseas workers built resumes and online profiles matched to specific remote IT job postings (including at cleared defense contractors), a step the indictment describes explicitly and that is consistent with the broader campaign's documented use of AI polish to make resumes read as native, error-free English.
Countering Stage 4: Recruiters and hiring managers can cross-check resume and profile details (claimed employers, dates, locations) for internal consistency and consistency across platforms, and independently verify references by phone or video rather than relying only on emailed contacts.
5
Application, interview, and I-9 fraud: the fake persona applied for and won a remote IT role, then completed a signed I-9 employment-eligibility form falsely swearing US citizenship or residency, per multiple victim-company narratives in the indictment; the broader campaign is separately documented experimenting with camera-on video interviews defeated via real-time deepfake overlays or voice-changing software, though the Wang case charging documents do not allege that specific technique.
Countering Stage 5: Require cameras on for every interview round, ask unscripted and personally anchored questions that a scripted or synthetic persona struggles with, and match the interviewee's live appearance against the submitted ID photo rather than treating the two as separately verified.
6
Laptop-farm onboarding: once hired, the fake employee instructed the victim company to ship its standard-issue corporate laptop to a US facilitator's residential address rather than the (nonexistent) worker's own home.
Countering Stage 6: Flag and independently verify any laptop shipping address that does not match the candidate's stated home address, or that changes shortly after an offer is accepted, before equipment ships.
7
Remote-access handoff: the facilitator (Zhenxing Wang or another of the at-least-five US facilitators Kejia Wang supervised) logged into the laptop and installed remote-desktop software, or connected it to an internet-connected KVM switch, so the actual overseas worker could operate the machine as if physically present in the US.
Countering Stage 7: Deploy endpoint monitoring or application allowlisting on corporate-issued laptops that alerts on installation of remote-desktop software or connection to unrecognized peripheral/KVM hardware immediately after provisioning, plus geolocation checks flagging authentication from unexpected countries or from VPN services associated with DPRK IT-worker infrastructure.
8
Payroll capture and laundering: wages the victim company believed it was paying a US employee were direct-deposited into bank or money-transfer accounts controlled by the shell companies, then transferred onward to overseas co-conspirators in China, the UAE, and Taiwan, with US facilitators skimming a fee off the top.
Countering Stage 8: Banks and payment platforms can apply money-laundering typologies tuned to this pattern (a newly formed, no-employee LLC receiving multiple corporate payroll direct deposits and rapidly forwarding the funds overseas), and employer finance/HR teams can cross-check that payroll destination accounts belong to the named employee rather than a third-party business entity.
9
Privileged-access exploitation and objective completion: with standing, authenticated access to the employer's network maintained over weeks or months, an overseas co-conspirator used the Company C foothold to access and exfiltrate technical files marked as ITAR-controlled, completing both the steady revenue-generation objective and, in that instance, an espionage/export-control-violation objective on top of it.
Countering Stage 9: Apply least-privilege access and data-loss-prevention controls to sensitive or export-controlled (ITAR) data stores regardless of an employee's tenure or apparent standing, so that a single compromised or fraudulently obtained account cannot freely access and exfiltrate controlled technical data; this is the strongest available backstop once every earlier hiring-stage control has already failed.
Quick Facts
Victim
100+ U.S. companies, including multiple Fortune 500 firms; named/described victims include an unnamed California-based AI/defense contractor ("Company C") whose ITAR-controlled data was stolen, and a Massachusetts-based semiconductor distributor; more than 80 U.S. persons whose identities were stolen and used to secure the fraudulent jobs.
Location
Facilitators based in Edison and New Brunswick, New Jersey; victim companies located across 27 US states and DC per the unsealed indictment (Massachusetts, California, New York, New Jersey, Florida, New Mexico, Georgia, Maryland, Alabama, North Carolina, Illinois, Ohio, South Carolina, Michigan, Texas, Indiana, Arkansas, Missouri, Tennessee, Minnesota, Rhode Island, Wisconsin, Oregon, Pennsylvania, Washington, Utah, Colorado, plus DC); overseas coordination tied to Shenyang and Dandong, China, and North Korea; case prosecuted in the District of Massachusetts.
Date
Conduct: ~2021 to October 2024. Charges unsealed: June 27-30, 2025 (Zhenxing Wang indictment; Kejia Wang criminal information). Guilty pleas: Kejia Wang September 2025, Zhenxing Wang January 2026. Sentenced: April 15, 2026.
Impact
DOJ: scheme generated more than $5 million in illicit revenue for the DPRK regime. Victim companies incurred at least $3 million in legal fees, network-remediation costs, and other damages. Kejia Wang, Zhenxing Wang, and four other US facilitators collectively received nearly $700,000 for their roles. Court ordered $600,000 in forfeiture (of which $400,000 had been recovered by sentencing) plus $29,236.03 in restitution from Kejia Wang. All figures per DOJ press releases; not independently audited outside the criminal case.
Status
Confirmed
Case Type
Real-World Incident
Sector
Cross-Sector / Multiple Industries, Defense & Aerospace, Manufacturing & Industrial, Professional & Business Services, Technology & Software
Threat Actor
Nation-State / APT
Related

Related Cases

Binance CCO Patrick Hillmann's Alleged Deepfake 'Hologram' Listing Scam Claim (2022)

Binance CCO Patrick Hillmann claimed scammers built an AI deepfake "hologram" of him from his TV interview footage and used…

Incident 2022Read →

Deepfake Martin Lewis/Elon Musk Investment Scam Costs Brighton Man £76,000 via Fake Revolut Account "Carl"

A Brighton-area kitchen fitter lost roughly £76,000, including four loans he was pressured into taking out, after a Facebook ad…

Incident 2023Read →

LastPass Employee Foils AI Voice Deepfake of CEO Karim Toubba (2024)

An attacker impersonated LastPass CEO Karim Toubba with an AI voice clone over WhatsApp, but the targeted employee spotted the…

Incident 2024Read →