SAN FRANCISCO — To modern corporate IT departments and cyber threat intelligence units, detecting a remote employee working from an unauthorized foreign country typically relies on a standard playbook: tracking geographic IP anomalies, flagging commercial VPN ranges, and blocking known data center proxy addresses.
However, when state-sponsored threat actors operate behind a domestic proxy facilitator, standard network security controls can be completely bypassed.
Federal court filings unsealed by the U.S. Department of Justice highlight a multi-year cyber-fraud investigation centered around Zhenxing "Danny" Wang and his corporate entity, Hopana Tech LLC. Investigators allege Wang utilized Hopana Tech to construct and manage a $5 million domestic laptop farm network, establishing a critical technical bridge that allowed North Korean IT operatives to effortlessly bypass corporate static IP filters and infiltrate major U.S. enterprises.
The Operational Ledger | The Hopana Tech LLC Infrastructure
By converting ordinary American residential internet connections into dedicated proxy hubs, Hopana Tech provided the technological mask needed to hide foreign operatives from corporate security audits.
Hopana Tech Network Case Profile
| Key Operator | Zhenxing "Danny" Wang |
| Corporate Entity | Hopana Tech LLC |
| Network Value | Estimated $5 million generated in illicit technology contract revenue |
| Primary Threat Actor | Overseas North Korean IT workers (DPRK Ministry of State Security affiliates) |
| Defrauded Sectors | Fortune 500 tech companies, financial institutions, and healthcare networks |
| Core Technical Tactic | Converting residential broadband routers into static IP proxy nodes |
The Mechanics | How DPRK Operatives Bypass Corporate VPN Static IP Filters
Major enterprise security teams routinely mandate that remote software engineers connect directly to internal networks via corporate-issued VPNs, or log in strictly from verified, static U.S. IP addresses. Standard commercial VPN services fail to bypass these security protocols because their IP addresses belong to recognizable data center ranges, which are instantly flagged by automated security tools like Okta or CrowdStrike.
To defeat these filters, Wang and Hopana Tech deployed a specialized, multi-stage residential proxy architecture.
The Residential Proxy Bypass Funnel
Procurement of Residential IP Blocks
Hopana Tech established partnerships or leased infrastructure from residential proxy providers. Unlike data center IPs, residential IPs are assigned directly by consumer Internet Service Providers like Comcast, AT&T, or Spectrum. To corporate security monitoring tools, traffic originating from a residential IP appears indistinguishable from a standard home internet connection.
Physical Laptop Farms and KVM Hardware
To bypass hardware-level device management tools that track physical device locations, Hopana Tech hosted physical corporate laptops inside domestic laptop farms.
Hopana Tech | Technical Infrastructure Breakdown
| Laptop Reception | When victimized U.S. firms shipped laptops to newly hired "American" workers, the devices were delivered directly to Hopana-managed domestic addresses. |
| Hardware Integration | The hardware was plugged into local power, connected to residential Wi-Fi/Ethernet networks, and integrated with KVM (Keyboard, Video, Mouse) hardware over IP adapters. |
| Masked Remote Sessions | Sitting in locations across East Asia, North Korean operatives initiated encrypted tunnels to Hopana Tech's residential proxy nodes. The operative controlled the U.S.-based laptop via remote-desktop protocols. |
| Clean IP Footprint | When the corporate laptop transmitted authentication tokens to the employer's internal VPN or SSO portals, the incoming traffic registered as a clean, static residential IP address originating from inside the United States. |
Because the connection matched the expected geographic footprint of a domestic remote worker, automated anomaly detectors failed to trigger alerts, allowing the foreign operatives to maintain full-time employment, collect six-figure tech salaries, and access sensitive corporate source code without raising suspicion.
Unraveling the Multi-Million Dollar Pipeline
The $5 million scheme generated massive financial windfalls that were converted into cryptocurrency and offshore wire transfers, funneled directly to state-sponsored accounts funding Pyongyang's weapons programs.
Federal law enforcement agencies, working alongside private sector threat intelligence firms, unraveled the network by cross-referencing hardware telemetry data, residential ISP traffic spikes, and financial transaction logs linked to Hopana Tech LLC.
The dismantling of Wang's operation serves as an urgent wake-up call for the technology sector. As threat actors refine their ability to route traffic through domestic residential hubs, federal agencies emphasize that enterprise security teams must look beyond basic IP tracking, implementing strict biometric identity verification, hardware-level supply chain tracking, and out-of-band video checks during remote onboarding to defend against domestic proxy facilitation.
This case is the third chapter in the North Korea IT infiltration story. The Wall Street Journal investigation revealed the $800 million global scale of the operation. The Christina Marie Chapman sentencing showed how federal authorities are prosecuting domestic facilitators. The Hopana Tech case exposes the technical infrastructure layer, specifically how residential proxy hubs enable the VPN bypass that makes the entire remote infiltration pipeline possible. For more on how AI is reshaping the security landscape, see our coverage of the House Democrats' push for AI safety legislation.