North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales

Threat actors with ties to the Democratic People’s Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent investigations identifying suspected workers employed in sales and marketing and the medical profession.

The ongoing insider threat is part of what has been described as the IT worker scheme, where North Korea leverages its network of skilled IT workers, both within and outside the country, to fraudulently land jobs in Fortune 500 companies and private sector firms across the world and remotely earn income to further Pyongyang’s unlawful nuclear weapons and ballistic missile programs.

This entails relying on stolen or forged identity documents, VPNs, and proxy services to mask their true identity and location. The yearslong campaign is also tracked under the monikers Famous Chollima, Jasper Sleet, Nickel Tapestry, PurpleDelta (formerly TAG-121), UNC5267, and Wagemole.

“DPRK workers present a unique detection challenge for defenders: rather than compromising accounts or breaking in via gaps in the organizations’ environments, they’re tricking companies into remotely hiring them, and oftentimes actually doing the legitimate work they were hired to do,” Huntress said in an analysis.

In one case in February 2026, three employees of an Australian healthcare company were flagged as North Korean workers impersonating Chinese individuals after they were found repeatedly connecting through Astrill VPN and IPRoyal Proxy, fraudulently created identity documents, similarities between two of the employees’ passports, and glaring word anomalies in electronic bills submitted as proof of residence during the onboarding process.

“Despite the likelihood of passports and resident identity cards being fraudulent, there’s still the possibility that these documents contained legitimate information or pictures from others who have had their identity information stolen or borrowed,” Huntress added.

A second case this month at an unnamed financial services firm uncovered the presence of PiKVM on their device. The use of KVM switches like PiKVM or TinyPilot has been previously attributed to the North Korean IT worker scheme, allowing the remote threat actors to connect to devices hosted on laptop farms.

The “employee” is also said to have accessed a third-party file-sharing service SendGB to download a modified version of a legitimate GitHub profile, likely for use as their own profile picture on an internal communications tool.

Days after the installation of PiKVM, the same device also had a Guermok USB capture card attached to it so as to enable “video streaming through it to be sent as a webcam input in web conferencing applications such as Zoom.” Although the use of Guermok by itself isn’t suspicious, the fact that PiKVM installation and Guermok USB attachment happened one after the other raises red flags.

In a third case investigated by Huntress in August 2026, a sales and marketing hire onboarded 13 days earlier appeared to have stolen or borrowed an existing identity to land the job, substituting the legitimate individual’s face with the suspected DPRK worker after the former’s details, including name, date of birth, and location, along with their mugshot were posted online by law enforcement post their arrest.

“Mitigating the risk of fraudulent workers begins at the interview stage and continues with performing rigorous background checks of new hires prior to onboarding,” Huntress said. “When in doubt, performing standard background checks, searching the individuals online, and verifying any employment history will help to weed out DPRK workers early in the interview process.”

These are far from isolated cases. Recorded Future’s Insikt Group said it observed one cluster linked to PurpleDelta applied to jobs at over 1,100 companies, mostly in software and technology, staffing and consulting, and healthcare and biotechnology sectors, between late 2024 and early 2025.

The threat actors, comprising multiple operators likely based in China, are suspected to have maintained 22 fabricated personas, some synthetically generated using artificial intelligence (AI) and using identity documents sourced from an illicit ID-generation service called TrustID Card (“trustidcard[.]com”).

Describing PurpleDelta as maintaining a “high operational tempo,” the threat intelligence company said the threat actors have applied to at least 60 positions per day across 10 job platforms, used multi-account management browsers and separate Google Chrome profiles to manage distinct personas, and maintained extensive tracking spreadsheets to coordinate applications across identities.

“During job interviews, they used screen recording software alongside AI transcription and chatbot tools to generate real-time answers, often repeating ChatGPT responses verbatim,” Recorded Future added. “Once employed, operators recorded internal meetings at victim organizations and used Google Translate to draft pre-written excuses to justify using personal devices and bank accounts for work.”

In addition, PurpleDelta operators have been found to rely on identity-brokering services, account-renting via AnyDesk, and multi-accounting tools, as well as coordinate via Telegram and Slack to complete work, and communicate with facilitators who procure and maintain company-issued hardware on the operators’ behalf.

“PurpleDelta activity is almost certainly ongoing and will very likely continue to expand in scale and sophistication as North Korean IT workers adapt to increased awareness and detection efforts,” Recorded Future explained.

“The increasing integration of AI tools into PurpleDelta’s tradecraft presents a compounding risk. The use of custom ChatGPT assistants, real-time AI transcription during interviews, and AI-generated profile photos lowers the barrier to plausible deception and enables operators to perform credibly in technical roles they may not fully understand.”

The findings coincide with a number of related developments –

  • The U.S. Federal Bureau of Investigation (FBI) is investigating how a North Korean IT worker successfully gained employment at an unnamed federal government agency. It’s believed that the remote IT employee was doing contract work rather than being hired directly.
  • The operators are funnelingWestern salaries through a web of front companies and intermediaries, including entities like Sobaeksu, Saenal, and Songkwang that have been sanctioned in the U.S. for sanctions evasion. According to DTEX, the scheme is also being used to support the regime’s objectives, such as weapons manufacturing and supporting Russia’s war effort. In all, the scheme is estimated to have made $1.97 million in payments between December 2025 and February 2026 flowing through the sanctioned Ryongbong General Corporation.
  • Earlier this May, two U.S. nationals, Matthew Isaac Knoot and Erick Ntekereze Prince, were sentenced to 18 months in prison each for running a laptop farm for North Korean remote IT workers. The two separate schemes impacted almost 70 U.S. companies and generated a combined $1.2 million in illicit revenue.
  • A month before that, 42-year-old Kejia Wang and 39-year-old Zhenxing Wang were sentenced to 108 and 92 months in prison, respectively, for operating a similar laptop farm at their homes in New Jersey and helping IT workers obtain remote jobs at more than 100 American companies, generating roughly $5 million and causing losses of more than $3 million to the victim companies. Four other men, Oleksandr Didenko, 29, Audricus Phagnasay, 25, Jason Salazar, 30, and Alexander Paul Travis, 35, were sentenced in February and March.
  • A series of reports from Nisos have revealed how DPRK operatives are using employment fraud to target cryptocurrency firms with an aim to conduct asset theft. One of the IT workers was also caught applying for a lead AI architect role at the human risk management company, inadvertently exposing their use of PiKVM to maintain control of their device located in a laptop farm containing 20 machines.
  • In April, Microsoft disclosed it observed Jasper Sleet actors accessing Workday Recruiting Web Service endpoints that are exposed through external career sites likely to obtain details about open roles and recruitment workflows. During the recruiting phase, the adversary is known to communicate with the target organization’s hiring team using emails, and legitimate platforms like Microsoft Teams, Zoom, or Cisco Webex for interviews. Upon being hired, the threat actors create new Workday profiles and update payroll information, typically tied to a facilitator.

“Operating under synthetic identities, these individuals present themselves as highly experienced developers from all over the world to secure lucrative, long-term remote roles,” Group-IB said. “This is not a classic malware intrusion chain; it is a labor-enabled access model built around social engineering, synthetic identity operations, and platform abuse.”

“Beyond the immediate risk of data theft, organizations that unknowingly hire these workers face severe legal and compliance risks, as employing or paying DPRK IT workers could constitute a direct breach of U.N., U.S., and U.K. financial sanctions.”

The persistent nature and the scale of the threat have prompted nearly a dozen governments to issue a joint alert late last month, urging all countries, companies, and other entities to intensify efforts to understand the scope of the DPRK worker schemes and implement appropriate countermeasures.

“Companies operating online platforms should continue to strengthen their countermeasures, such as enhancing identity verification procedures (strict review of identification documents, requirement of in-person interviews, etc.) and detecting suspicious accounts (introduction of systems that notify anomalous information entries, etc.),” cybersecurity and intelligence agencies from the U.S., Japan, South Korea, Australia, Canada, France, Germany, Italy, the Netherlands, New Zealand, and the U.K.

📰 Original Source:TheHackerNews
✍️ Author: info@thehackernews.com (The Hacker News)

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *