{"id":2622,"date":"2026-08-31T18:24:01","date_gmt":"2026-08-31T18:24:01","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2622"},"modified":"2026-08-31T18:24:01","modified_gmt":"2026-08-31T18:24:01","slug":"north-korean-job-fraud-expands-beyond-it-into-healthcare-and-sales","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2622","title":{"rendered":"North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg79i0RXS7ZzzPurGwbsquOv8l9-GsYQmsw9y1qCzEeDMKYNXjn84VZVfVZU9aiGqnyDyQ6ZdgKosZxn60KtJ6TgTREMyC_ZnhyCxv3kSLtAXBHA2suVHDYFdWYllL4aN0-exJxnCfjXJL5dlo08aVU1YtzJchTD7nORvsBe0oXivCBhctDCcEn85Cmjiab\/s1700-nu-rw-lo-l85-e365\/1000104722.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Threat actors with ties to the Democratic People&#8217;s Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent investigations identifying suspected workers employed in sales and marketing and the medical profession.<\/p>\n<p>The ongoing insider threat is part of what has been described as the IT worker scheme, where North Korea leverages its network of skilled IT workers, both within and outside the country, to fraudulently land jobs in Fortune 500 companies and private sector firms across the world and remotely earn income to further Pyongyang&#8217;s unlawful nuclear weapons and ballistic missile programs.<\/p>\n<p>This entails relying on stolen or forged identity documents, VPNs, and proxy services to mask their true identity and location. The yearslong campaign is also tracked under the monikers Famous Chollima, Jasper Sleet, Nickel Tapestry, PurpleDelta (formerly TAG-121), UNC5267, and Wagemole.<\/p>\n<p>\u00abDPRK workers present a unique detection challenge for defenders: rather than compromising accounts or breaking in via gaps in the organizations&#8217; environments, they&#8217;re tricking companies into remotely hiring them, and oftentimes actually doing the legitimate work they were hired to do,\u00bb Huntress <a href=\"https:\/\/www.huntress.com\/blog\/huntress-dprk-remote-worker-investigation\" target=\"_blank\">said<\/a> in an analysis.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/zero-trust-claude-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj8iAp2j8rqTq6aptj6yiYHC-B73UxnWI2NQMt0azp6OVLq9JkO8cpYokLWa8t_IKqrHKPsaM5D_lQ9Ip7kZTi3at4oYfzN1m1b_T4b6MuzBWtmlhdLcQ0nZHicD94rliREFDRewsKBQCTYrAAVNzYKj84_0EZskDUxvkc972s9fYAqcQGEQjVZTc0cr7TB\/s728-nu-rw-lo-l85-e365\/ThreatLocker-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>In one case in February 2026, three employees of an Australian healthcare company were flagged as North Korean workers impersonating Chinese individuals after they were found repeatedly connecting through Astrill VPN and IPRoyal Proxy, fraudulently created identity documents, similarities between two of the employees&#8217; passports, and glaring word anomalies in electronic bills submitted as proof of residence during the onboarding process.<\/p>\n<p>\u00abDespite the likelihood of passports and resident identity cards being fraudulent, there&#8217;s still the possibility that these documents contained legitimate information or pictures from others who have had their identity information stolen or borrowed,\u00bb Huntress added.<\/p>\n<p>A second case this month at an unnamed financial services firm uncovered the presence of PiKVM on their device. The use of KVM switches like PiKVM or TinyPilot has been <a href=\"https:\/\/thehackernews.com\/2025\/07\/us-arrests-key-facilitator-in-north.html\" target=\"_blank\">previously attributed to the North Korean IT worker scheme, allowing the remote threat actors to connect to devices hosted on laptop farms.<\/p>\n<p>The \u00abemployee\u00bb is also said to have accessed a third-party file-sharing service SendGB to download a modified version of a legitimate GitHub profile, likely for use as their own profile picture on an internal communications tool. <\/p>\n<p>Days after the installation of PiKVM, the same device also had a <a href=\"https:\/\/guermok.com\/product\" target=\"_blank\">Guermok USB<\/a> capture card attached to it so as to enable \u00abvideo streaming through it to be sent as a webcam input in web conferencing applications such as Zoom.\u00bb Although the use of Guermok by itself isn&#8217;t suspicious, the fact that PiKVM installation and Guermok USB attachment happened one after the other raises red flags.<\/p>\n<p>In a third case investigated by Huntress in August 2026, a sales and marketing hire onboarded 13 days earlier appeared to have stolen or borrowed an existing identity to land the job, substituting the legitimate individual&#8217;s face with the suspected DPRK worker after the former&#8217;s details, including name, date of birth, and location, along with their mugshot were posted online by law enforcement post their arrest.<\/p>\n<p>\u00abMitigating the risk of fraudulent workers begins at the interview stage and continues with performing rigorous background checks of new hires prior to onboarding,\u00bb Huntress said. \u00abWhen in doubt, performing standard background checks, searching the individuals online, and verifying any employment history will help to weed out DPRK workers early in the interview process.\u00bb<\/p>\n<p>These are far from isolated cases. Recorded Future&#8217;s Insikt Group said it observed one cluster linked to PurpleDelta applied to jobs at over 1,100 companies, mostly in software and technology, staffing and consulting, and healthcare and biotechnology sectors, between late 2024 and early 2025.<\/p>\n<p>The threat actors, comprising multiple operators likely based in China, are suspected to have maintained 22 fabricated personas, some synthetically generated using artificial intelligence (AI) and using identity documents sourced from an illicit ID-generation service called TrustID Card (\u00abtrustidcard[.]com\u00bb).<\/p>\n<p>Describing PurpleDelta as maintaining a \u00abhigh operational tempo,\u00bb the threat intelligence company said the threat actors have applied to at least 60 positions per day across 10 job platforms, used multi-account management browsers and separate Google Chrome profiles to manage distinct personas, and maintained extensive tracking spreadsheets to coordinate applications across identities.<\/p>\n<p>\u00abDuring job interviews, they used screen recording software alongside AI transcription and chatbot tools to generate real-time answers, often repeating ChatGPT responses verbatim,\u00bb Recorded Future <a href=\"https:\/\/www.recordedfuture.com\/research\/purpledelta-fraudulent-employment-operations\" target=\"_blank\">added<\/a>. \u00abOnce employed, operators recorded internal meetings at victim organizations and used Google Translate to draft pre-written excuses to justify using personal devices and bank accounts for work.\u00bb<\/p>\n<p>In addition, PurpleDelta operators have been found to rely on identity-brokering services, account-renting via AnyDesk, and multi-accounting tools, as well as coordinate via Telegram and Slack to complete work, and communicate with facilitators who procure and maintain company-issued hardware on the operators&#8217; behalf.<\/p>\n<p>\u00abPurpleDelta activity is almost certainly ongoing and will very likely continue to expand in scale and sophistication as North Korean IT workers adapt to increased awareness and detection efforts,\u00bb Recorded Future explained.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/corelight-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjuvAqH13TTYyJD3aI-pJcYl54BoxQWMHc2aFwW2HbYUa5IKCjvHlzpzkFwXLTuV8aytky8kqLBgkoOtC8VQM5CGR0N5BXBl8RSXl-PYx_vIPbiLywiqXIvTPmm18cdEm_C0heVB-3U8zfG7K27RCAurtJ7OvxEyfQ0sVV_RRx1N4ZMWkqKgEBmkcDgjD6I\/s728-nu-rw-lo-l85-e365\/code-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abThe <a href=\"https:\/\/www.wired.com\/story\/ai-tools-are-helping-mediocre-north-korean-hackers-steal-millions\/\" target=\"_blank\">increasing integration of AI tools<\/a> into PurpleDelta&#8217;s tradecraft presents a compounding risk. The use of custom ChatGPT assistants, real-time AI transcription during interviews, and AI-generated profile photos lowers the barrier to plausible deception and enables operators to perform credibly in technical roles they may not fully understand.\u00bb<\/p>\n<p>The findings coincide with a number of related developments &#8211;<\/p>\n<ul>\n<li>The U.S. Federal Bureau of Investigation (FBI) is <a href=\"https:\/\/federalnewsnetwork.com\/technology-main\/2026\/08\/fbi-investigating-north-korean-remote-it-staffer-working-for-u-s-agency\/\" target=\"_blank\">investigating<\/a> how a North Korean IT worker successfully gained employment at an unnamed federal government agency. It&#8217;s believed that the remote IT employee was doing contract work rather than being hired directly.<\/li>\n<li>The operators are <a href=\"https:\/\/x.com\/zachxbt\/status\/2041873508180095032\" target=\"_blank\">funneling<\/a> <a href=\"https:\/\/www.team-cymru.com\/post\/dprk-fake-it-worker-cyber-threat-actors-infrastructure\" target=\"_blank\">Western salaries<\/a> through a web of front companies and intermediaries, including entities like Sobaeksu, Saenal, and Songkwang that have been sanctioned in the U.S. for sanctions evasion. According to <a href=\"https:\/\/www.dtex.ai\/blog\/dprk-it-worker-money-trail\/\" target=\"_blank\">DTEX<\/a>, the scheme is also being used to support the regime&#8217;s objectives, such as weapons manufacturing and supporting Russia&#8217;s war effort. In all, the scheme is estimated to have made $1.97 million in payments between December 2025 and February 2026 flowing through the sanctioned Ryongbong General Corporation.<\/li>\n<li>Earlier this May, two U.S. nationals, Matthew Isaac Knoot and Erick Ntekereze Prince, were <a href=\"https:\/\/www.justice.gov\/opa\/pr\/two-us-nationals-sentenced-facilitating-fraudulent-remote-information-technology-worker-0\" target=\"_blank\">sentenced<\/a> to 18 months in prison each for running a laptop farm for North Korean remote IT workers. The two separate schemes impacted almost 70 U.S. companies and generated a combined $1.2 million in illicit revenue.<\/li>\n<li>A month before that, 42-year-old Kejia Wang and 39-year-old Zhenxing Wang were <a href=\"https:\/\/www.justice.gov\/opa\/pr\/two-us-nationals-sentenced-facilitating-fraudulent-remote-information-technology-worker\" target=\"_blank\">sentenced<\/a> to 108 and 92 months in prison, respectively, for operating a similar laptop farm at their homes in New Jersey and helping IT workers obtain remote jobs at more than 100 American companies, generating roughly $5 million and causing losses of more than $3 million to the victim companies. Four other men, Oleksandr Didenko, 29, Audricus Phagnasay, 25, Jason Salazar, 30, and Alexander Paul Travis, 35, were sentenced in February and March.<\/li>\n<li>A series of reports from Nisos have <a href=\"https:\/\/nisos.com\/blog\/dprk-employment-fraud-crypto-companies\/\" target=\"_blank\">revealed<\/a> how DPRK operatives are using employment fraud to target cryptocurrency firms with an aim to conduct asset theft. One of the IT workers was also <a href=\"https:\/\/nisos.com\/research\/exposing-fraudulent-dprk-candidate\/\" target=\"_blank\">caught<\/a> applying for a <a href=\"https:\/\/nisos.com\/blog\/dprk-it-worker-fraud-laptop-farm\/\" target=\"_blank\">lead AI architect role<\/a> at the human risk management company, inadvertently <a href=\"https:\/\/www.nbcnews.com\/investigations\/north-korea-it-worker-scheme-nisos-fbi-rcna245025\" target=\"_blank\">exposing<\/a> their use of PiKVM to maintain control of their device located in a laptop farm containing 20 machines.<\/li>\n<li>In April, Microsoft <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/04\/21\/detection-strategies-cloud-identities-against-infiltrating-it-workers\/\" target=\"_blank\">disclosed<\/a> it observed Jasper Sleet actors accessing Workday Recruiting Web Service endpoints that are exposed through external career sites likely to obtain details about open roles and recruitment workflows. During the recruiting phase, the adversary is known to communicate with the target organization&#8217;s hiring team using emails, and legitimate platforms like Microsoft Teams, Zoom, or Cisco Webex for interviews. Upon being hired, the threat actors create new Workday profiles and update payroll information, typically tied to a facilitator.<\/li>\n<\/ul>\n<p>\u00abOperating under synthetic identities, these individuals present themselves as highly experienced developers from all over the world to secure lucrative, long-term remote roles,\u00bb Group-IB <a href=\"https:\/\/www.group-ib.com\/blog\/dprk-fake-remote-developers\/\" target=\"_blank\">said<\/a>. \u00abThis is not a classic malware intrusion chain; it is a labor-enabled access model built around social engineering, synthetic identity operations, and platform abuse.\u00bb<\/p>\n<p>\u00abBeyond the immediate risk of data theft, organizations that unknowingly hire these workers face severe legal and compliance risks, as employing or paying DPRK IT workers could constitute a direct breach of U.N., U.S., and U.K. financial sanctions.\u00bb<\/p>\n<p>The <a href=\"https:\/\/flare.io\/learn\/resources\/north-korean-infiltrator-threat\" target=\"_blank\">persistent nature and the scale of the threat<\/a> have prompted nearly a dozen governments to issue a <a href=\"https:\/\/www.state.gov\/releases\/office-of-the-spokesperson\/2026\/07\/alert-to-countries-companies-and-other-entities-regarding-north-korean-it-workers\/\" target=\"_blank\">joint alert<\/a> late last month, urging all countries, companies, and other entities to intensify efforts to understand the scope of the DPRK worker schemes and implement appropriate countermeasures.<\/p>\n<p>\u00abCompanies operating online platforms should continue to strengthen their countermeasures, such as enhancing identity verification procedures (strict review of identification documents, requirement of in-person interviews, etc.) and detecting suspicious accounts (introduction of systems that notify anomalous information entries, etc.),\u00bb cybersecurity and intelligence agencies from the U.S., Japan, South Korea, Australia, Canada, France, Germany, Italy, the Netherlands, New Zealand, and the U.K.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Threat actors with ties to the Democratic People&#8217;s Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2623,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[206,250,97,152,337,247,1492],"class_list":["post-2622","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-expands","tag-fraud","tag-healthcare","tag-job","tag-korean","tag-north","tag-sales"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2622","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2622"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2622\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2623"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2622"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2622"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2622"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}