North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales

North Korean workers are expanding remote-job fraud beyond IT into healthcare and sales, using false identities, proxies, and laptop farms.

The Hacker News The Hacker News
威胁情报APT活动人工智能安全终端安全开源安全

Threat actors with ties to the Democratic People's Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent investigations identifying suspected workers employed in sales and marketing and the medical profession.

The ongoing insider threat is part of what has been described as the IT worker scheme, where North Korea leverages its network of skilled IT workers, both within and outside the country, to fraudulently land jobs in Fortune 500 companies and private sector firms across the world and remotely earn income to further Pyongyang's unlawful nuclear weapons and ballistic missile programs.

This entails relying on stolen or forged identity documents, VPNs, and proxy services to mask their true identity and location. The yearslong campaign is also tracked under the monikers Famous Chollima, Jasper Sleet, Nickel Tapestry, PurpleDelta (formerly TAG-121), UNC5267, and Wagemole.

"DPRK workers present a unique detection challenge for defenders: rather than compromising accounts or breaking in via gaps in the organizations' environments, they're tricking companies into remotely hiring them, and oftentimes actually doing the legitimate work they were hired to do," Huntress said in an analysis.

In one case in February 2026, three employees of an Australian healthcare company were flagged as North Korean workers impersonating Chinese individuals after they were found repeatedly connecting through Astrill VPN and IPRoyal Proxy, fraudulently created identity documents, similarities between two of the employees' passports, and glaring word anomalies in electronic bills submitted as proof of residence during the onboarding process.

"Despite the likelihood of passports and resident identity cards being fraudulent, there's still the possibility that these documents contained legitimate information or pictures from others who have had their identity information stolen or borrowed," Huntress added.

A second case this month at an unnamed financial services firm uncovered the presence of PiKVM on their device. The use of KVM switches like PiKVM or TinyPilot has been previously attributed to the North Korean IT worker scheme, allowing the remote threat actors to connect to devices hosted on laptop farms.

The "employee" is also said to have accessed a third-party file-sharing service SendGB to download a modified version of a legitimate GitHub profile, likely for use as their own profile picture on an internal communications tool.

Days after the installation of PiKVM, the same device also had a Guermok USB capture card attached to it so as to enable "video streaming through it to be sent as a webcam input in web conferencing applications such as Zoom." Although the use of Guermok by itself isn't suspicious, the fact that PiKVM installation and Guermok USB attachment happened one after the other raises red flags.

In a third case investigated by Huntress in August 2026, a sales and marketing hire onboarded 13 days earlier appeared to have stolen or borrowed an existing identity to land the job, substituting the legitimate individual's face with the suspected DPRK worker after the former's details, including name, date of birth, and location, along with their mugshot were posted online by law enforcement post their arrest.

"Mitigating the risk of fraudulent workers begins at the interview stage and continues with performing rigorous background checks of new hires prior to onboarding," Huntress said. "When in doubt, performing standard background checks, searching the individuals online, and verifying any employment history will help to weed out DPRK workers early in the interview process."

These are far from isolated cases. Recorded Future's Insikt Group said it observed one cluster linked to PurpleDelta applied to jobs at over 1,100 companies, mostly in software and technology, staffing and consulting, and healthcare and biotechnology sectors, between late 2024 and early 2025.

The threat actors, comprising multiple operators likely based in China, are suspected to have maintained 22 fabricated personas, some synthetically generated using artificial intelligence (AI) and using identity documents sourced from an illicit ID-generation service called TrustID Card ("trustidcard[.]com").

Describing PurpleDelta as maintaining a "high operational tempo," the threat intelligence company said the threat actors have applied to at least 60 positions per day across 10 job platforms, used multi-account management browsers and separate Google Chrome profiles to manage distinct personas, and maintained extensive tracking spreadsheets to coordinate applications across identities.

"During job interviews, they used screen recording software alongside AI transcription and chatbot tools to generate real-time answers, often repeating ChatGPT responses verbatim," Recorded Future added. "Once employed, operators recorded internal meetings at victim organizations and used Google Translate to draft pre-written excuses to justify using personal devices and bank accounts for work."

In addition, PurpleDelta operators have been found to rely on identity-brokering services, account-renting via AnyDesk, and multi-accounting tools, as well as coordinate via Telegram and Slack to complete work, and communicate with facilitators who procure and maintain company-issued hardware on the operators' behalf.

"PurpleDelta activity is almost certainly ongoing and will very likely continue to expand in scale and sophistication as North Korean IT workers adapt to increased awareness and detection efforts," Recorded Future explained.

"The increasing integration of AI tools into PurpleDelta's tradecraft presents a compounding risk. The use of custom ChatGPT assistants, real-time AI transcription during interviews, and AI-generated profile photos lowers the barrier to plausible deception and enables operators to perform credibly in technical roles they may not fully understand."

The findings coincide with a number of related developments -

"Operating under synthetic identities, these individuals present themselves as highly experienced developers from all over the world to secure lucrative, long-term remote roles," Group-IB said. "This is not a classic malware intrusion chain; it is a labor-enabled access model built around social engineering, synthetic identity operations, and platform abuse."

"Beyond the immediate risk of data theft, organizations that unknowingly hire these workers face severe legal and compliance risks, as employing or paying DPRK IT workers could constitute a direct breach of U.N., U.S., and U.K. financial sanctions."

The persistent nature and the scale of the threat have prompted nearly a dozen governments to issue a joint alert late last month, urging all countries, companies, and other entities to intensify efforts to understand the scope of the DPRK worker schemes and implement appropriate countermeasures.

"Companies operating online platforms should continue to strengthen their countermeasures, such as enhancing identity verification procedures (strict review of identification documents, requirement of in-person interviews, etc.) and detecting suspicious accounts (introduction of systems that notify anomalous information entries, etc.)," cybersecurity and intelligence agencies from the U.S., Japan, South Korea, Australia, Canada, France, Germany, Italy, the Netherlands, New Zealand, and the U.K.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.