Breaking
SecurityDeveloping Story

North Korea's Job Fraud Widens Beyond IT

DPRK workers now target sales, marketing, and healthcare roles, using AI and VPNs to evade detection.

··1 hour ago·6 min read
person holding round blue frame
Photo by Sasun Bughdaryan on Unsplash

North Korean threat actors have expanded their fraudulent employment operations beyond the IT sector, with recent investigations identifying suspected workers in sales, marketing, and even the medical profession. This evolution of the so-called IT worker scheme signals a broadening of a threat that has long targeted Fortune 500 companies and private firms, now reaching into new industries.

Inside the IT Worker Scheme

The scheme leverages North Korea's network of skilled IT workers, both within and outside the country, to fraudulently land jobs in Fortune 500 companies and private sector firms across the world. These workers remotely earn income to further Pyongyang's unlawful nuclear weapons and ballistic missile programs, according to the source article.

Operators rely on stolen or forged identity documents, VPNs, and proxy services to mask their true identity and location. The campaign is tracked under several monikers, including Famous Chollima, Jasper Sleet, Nickel Tapestry, PurpleDelta (formerly TAG-121), UNC5267, and Wagemole.

Healthcare Sector Breach

In February 2026, three employees of an Australian healthcare company were flagged as North Korean workers impersonating Chinese individuals. The red flags included repeated connections through Astrill VPN and IPRoyal Proxy, fraudulently created identity documents, similarities between two of the employees' passports, and glaring word anomalies in electronic bills submitted as proof of residence during onboarding.

Huntress, the security firm that investigated these cases, noted in an analysis that “DPRK workers present a unique detection challenge for defenders: rather than compromising accounts or breaking in via gaps in the organizations' environments, they're tricking companies into remotely hiring them, and oftentimes actually doing the legitimate work they were hired to do.”

“DPRK workers present a unique detection challenge for defenders: rather than compromising accounts or breaking in via gaps in the organizations' environments, they're tricking companies into remotely hiring them, and oftentimes actually doing the legitimate work they were hired to do.”

— Huntress, as quoted in the source article

Sales and Marketing Hire

In a third case investigated by Huntress in August 2026, a sales and marketing hire who had been onboarded 13 days earlier appeared to have stolen or borrowed an existing identity. The suspected DPRK worker substituted the legitimate individual's face with their own after the latter's details, including name, date of birth, and location, along with their mugshot, were posted online by law enforcement following an arrest.

Huntress advised that “mitigating the risk of fraudulent workers begins at the interview stage and continues with performing rigorous background checks of new hires prior to onboarding. When in doubt, performing standard background checks, searching the individuals online, and verifying any employment history will help to weed out DPRK workers early in the interview process.”

Technical Red Flags

At an unnamed financial services firm this month, investigators uncovered the presence of a PiKVM device on a worker's system. The use of KVM switches like PiKVM or TinyPilot has been previously attributed to the North Korean IT worker scheme, allowing remote threat actors to connect to devices hosted on laptop farms.

The worker also accessed a third-party file-sharing service, SendGB, to download a modified version of a legitimate GitHub profile, likely for use as their own profile picture on an internal communications tool. Days after the PiKVM installation, a Guermok USB capture card was attached to the same device, enabling video streaming through it to be sent as a webcam input in web conferencing applications such as Zoom. While the use of a Guermok by itself isn't suspicious, the sequence of PiKVM installation followed by the USB attachment raised red flags for Huntress.

Scale and Sophistication

Recorded Future's Insikt Group observed one cluster linked to PurpleDelta that applied to jobs at over 1,100 companies, mostly in software and technology, staffing and consulting, and healthcare and biotechnology sectors, between late 2024 and early 2025. The threat actors, comprising multiple operators likely based in China, maintained 22 fabricated personas, some synthetically generated using AI, and used identity documents sourced from an illicit ID-generation service called TrustID Card.

Describing PurpleDelta as maintaining a “high operational tempo,” Recorded Future said the threat actors applied to at least 60 positions per day across 10 job platforms, used multi-account management browsers and separate Google Chrome profiles to manage distinct personas, and maintained extensive tracking spreadsheets to coordinate applications across identities.

AI-Enhanced Deception

Recorded Future also highlighted the growing use of AI in these operations. “During job interviews, they used screen recording software alongside AI transcription and chatbot tools to generate real-time answers, often repeating ChatGPT responses verbatim,” the company noted. “Once employed, operators recorded internal meetings at victim organizations and used Google Translate to draft pre-written excuses to justify using personal devices and bank accounts for work.”

The increasing integration of AI tools into PurpleDelta's tradecraft presents a compounding risk, as custom ChatGPT assistants, real-time AI transcription during interviews, and AI-generated profile photos lower the barrier to plausible deception, enabling operators to perform credibly in technical roles they may not fully understand.

Broader Implications

The findings coincide with several related developments. The FBI is investigating how a North Korean IT worker successfully gained employment at an unnamed federal government agency, believed to be doing contract work rather than being hired directly. Operators are funneling Western salaries through a web of front companies and intermediaries, including entities like Sobaeksu, Saenal, and Songkwang, which have been sanctioned in the U.S. for sanctions evasion.

According to DTEX, the scheme is also being used to support the regime's objectives, such as weapons manufacturing and supporting Russia's war effort. In total, the scheme is estimated to have made $1.97 million in payments between December 2025 and February 2026 flowing through the sanctioned Ryongbong General Corporation.

In May, two U.S. nationals, Matthew Isaac Knoot and Erick Ntekereze Prince, were sentenced to 18 months in prison each for running a laptop farm for North Korean remote IT workers. The two separate schemes impacted almost 70 U.S. companies and generated a combined $1.2 million in illicit revenue. A month earlier, 42-year-old Kejia Wang and 39-year-old Zhenxing Wang were sentenced to 108 and 92 months in prison, respectively, for operating a similar laptop farm at their homes in New Jersey, helping IT workers obtain remote jobs at more than 100 American companies, generating roughly $5 million and causing losses of more than $3 million to the victim companies.

Reports from Nisos have revealed how DPRK operatives are using employment fraud to target cryptocurrency firms with an aim to conduct asset theft. One IT worker was caught applying for a lead AI architect role at a human risk management company, inadvertently exposing their use of PiKVM to maintain control of a device located in a laptop farm containing 20 machines.

In April, Microsoft disclosed it observed Jasper Sleet actors accessing Workday Recruiting Web Service endpoints exposed through external career sites, likely to obtain details about open roles and recruitment workflows. During the recruiting phase, the adversary communicates with the target organization's hiring team using emails and legitimate platforms like Microsoft Teams, Zoom, or Cisco Webex for interviews. Upon being hired, they create new Workday profiles and update payroll information, typically tied to a facilitator.

Why It Matters

These cases underscore that the DPRK's fraudulent employment operations are not just a cybersecurity problem but a systemic risk to any organization that hires remotely. The expansion into healthcare, sales, and marketing means no sector can assume it's immune. The use of AI to create convincing personas and answer interview questions in real time only deepens the challenge for defenders. For businesses, this suggests that rigorous identity verification and background checks are no longer optional but essential components of the hiring process. The involvement of sanctioned entities and the prosecution of facilitators highlight the legal and compliance stakes: unknowingly employing a DPRK worker could constitute a breach of sanctions, exposing companies to severe penalties. As these schemes continue to evolve, the onus is on employers to adapt their detection strategies accordingly.

#north korea#job fraud#insider threat#ai#hiring

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories