The high-profile worker scams run by threat actors linked to North Korea’s government that has haunted the IT industry for several years continue to bleed over into other industries.
Recent reports by Huntress and Recorded Future’s Insikt Group threat intelligence unit say that the campaigns – known best collectively as Famous Chomilla – have been detected targeting such sectors as healthcare, sales and marketing, staffing, and consulting, biotechnology, and in at least one instance, a U.S. government agency.
The reports come less than a year after a similar notice by Okta threat researchers, who wrote that not only were the operations spilling over from IT and cryptocurrency, but also were spreading beyond the United States – long the primary target – to other countries, including Great Britain, Germany, Canada, India, and Australia.
The international trend has been in the spotlight this year, with the U.S. State Department and FBI issuing a warning in July about the scams in conjunction with counterparts in other countries, including Japan, South Korea, Australia, New Zealand, and Canada. European countries – Germany, France, Italy, the UK, and the Netherlands – also signed on.
The continued expansion into other industries and countries is a worrying trend in a complex cybercriminal operation that reportedly brings as much as $800 million a year into North Korea, which uses the scams to evade international sanctions and help fund its vast weapons programs.
How They Work
Along with funneling their wages to the North Korean government, the fraudulent workers also access and exfiltrate company data, deploy malware, and at times – if discovered – extort their employers. The emergence of generative AI also has aided their operations, with potential hires able to use deepfakes and other tools during job interviews and to create false identities.
“DPRK [Democratic People’s Republic of Korea] workers present a unique detection challenge for defenders: rather than compromising accounts or breaking in via gaps in the organizations’ environments, they’re tricking companies into remotely hiring them, and oftentimes actually doing the legitimate work they were hired to do,” Huntress researchers wrote. “Furthermore, DPRK workers often use stolen identity documents, VPNs, and proxy services to mask their true identity and location, meaning other methods must be used to help verify if an employee is who they say they are.”
North Korean IT workers will create online accounts that falsify their identities and nationalities, either by making them up or stealing them from other people. They forge ID documents, use images from third parties, including proxies in other countries.
According to the FBI, they increasingly are using these proxies in job interviews, including in-person interviews. The scammers will do IT work in such areas as web page or software development. They often work in China and other countries, with people in the United State and other countries hosting “laptop farms” to give the impression they’re working in those countries.
Many Workers, Many Victims
They’re also prolific. Insikt Group researchers wrote that between late 2024 and early 2025, they followed on cluster of PurpleDelta – their designation for North Korean IT workers – that applied to jobs at more than 1,100 companies, with operators running at least 22 fake personas across multiple clusters and likely to be employed by at least 10 organizations.
They were “supported by AI-generated profile photos, custom-configured ChatGPT assistants, and identity documents sourced from an illicit ID-generation service,” they wrote. “In some cases, the operators have applied to at least 60 positions per day across multiple job platforms, used multi-account management browsers and separate Google Chrome profiles to manage distinct personas simultaneously, and maintained detailed tracking spreadsheets to coordinate applications across identities.”
The researchers found that once employed, PurpleDelta scammers recorded internal meetings at their companies, used screen recording software during work sessions, and used Google Translate to write justifications for using personal devices and bank accounts.
“Video evidence indicates that PurpleDelta operators use identity-brokering services, account-renting via AnyDesk, and multi-accounting tools, and coordinate via Telegram and Slack, with support from facilitators who procure and maintain company-issued hardware on the operators’ behalf,” they wrote.
Fake IDs and Stolen Photos
Huntress researchers said that this year, they’ve been involved in investigations of five people who were likely DPRK workers. In three instances, they reviewed fraudulent ID documents, and in another, identified a photo that was stolen from a legitimate GitHub account and the face altered.
In one case last month, executives with an Australian company brought Huntress onboard to investigate three people they suspected were North Koreans passing themselves off as Chinese. The researchers found three suspicious accounts that used several IP addressed linked to Astrill VPN nodes, that the workers were using IPRoyal Proxy, a legitimate service provider that sell access to IP addresses for routing internet traffic, and WorkTitans B.V., a bulletproof hosting operation.
The extensive use of VPN and the proxy infrastructure by all three accounts indicated that the people were trying to hide their locations. In addition, Huntress also found overlaps in documents – such as electricity bills and resident ID cards – used by two of the workers.
Indicators of a Scam
In another case in August, the researchers “identified multiple suspicious, low-prevalence physical devices connected to the host, which matched indicators that had been previously tied to DPRK workers.” That included a PiKVM, an open source KVM-over-IP device based on Raspberry Pi that enables users to remotely control a connected computer via a web browser at the hardware level, giving them remote access before the operating system boots and without having to install remote access software.
They also detailed a tampered photo of another person and the use of a Guermok USB capture card that was registered as a webcam on the worker’s system and allowed for video streaming through it to be sent as a webcam input in web conferencing apps like Zoom.
A third case involved a worker who either stole or borrowed someone else’s identity to get hired. Evidence included a mugshot that was different than the obtained identity document, and that the signature on two ID documents seemed to be a digital overlay rather than handwritten.