The threat of North Korean job fraud has evolved far beyond the information technology sector, with recent investigations uncovering a systematic expansion into healthcare, sales, marketing, and financial services. This sophisticated employment scheme, orchestrated by operatives linked to the Democratic People’s Republic of Korea, now represents one of the most insidious and persistent insider threats facing global corporations today.
Beyond IT: How North Korea’s Job Fraud Scheme Is Infiltrating New Industries
For years, the predominant narrative surrounding North Korean cyber operations focused on IT workers using stolen identities to secure remote programming jobs at Fortune 500 companies. Recent investigations by cybersecurity firm Huntress and intelligence analysts at Recorded Future reveal a far more expansive operation. North Korean operatives have now been identified working in sales and marketing roles, and perhaps most alarmingly, in healthcare professions where patient safety could be compromised.
In February 2026, three employees of an Australian healthcare company were flagged as suspected North Korean workers. These individuals were impersonating Chinese nationals and were identified through a combination of red flags including repeated connections via Astrill VPN and IPRoyal Proxy, fraudulently created identity documents, and striking anomalies in electronic bills submitted as proof of residence during onboarding. The case underscores that no industry is immune.
What Is the North Korean IT Worker Scheme?
The North Korean IT worker scheme, tracked under multiple threat intelligence monikers including Famous Chollima, Jasper Sleet, Nickel Tapestry, PurpleDelta, UNC5267, and Wagemole, involves a network of skilled operatives who fraudulently obtain remote employment at companies around the world. These workers rely on stolen or forged identity documents, VPNs, and proxy services to mask their true location and identity. The ultimate goal is to funnel Western salaries back to Pyongyang to fund the regime’s unlawful nuclear weapons and ballistic missile programs.
Unlike traditional cyberattacks that exploit technical vulnerabilities, this scheme exploits trust in the hiring process. As Huntress explained in its analysis, these workers often perform the legitimate work they were hired to do, making detection extraordinarily difficult for defenders.
Inside the PurpleDelta Operation: A High-Tempo Employment Fraud Machine
Recorded Future’s Insikt Group has documented one particularly aggressive cluster of activity tied to PurpleDelta. Between late 2024 and early 2025, this group applied to jobs at over 1,100 companies, focusing primarily on software and technology, staffing and consulting, and healthcare and biotechnology sectors. The operatives maintained 22 fabricated personas, some synthetically generated using artificial intelligence, and relied on identity documents sourced from an illicit ID-generation service called TrustID Card.
The operational tempo is staggering. PurpleDelta operators applied to at least 60 positions per day across 10 job platforms. They used multi-account management browsers and separate Google Chrome profiles to manage distinct personas, and maintained extensive tracking spreadsheets to coordinate applications across multiple identities. Communication and coordination were handled through Telegram and Slack, while facilitators procured and maintained company-issued hardware on the operators’ behalf.
AI-Powered Deception During Interviews and Onboarding
The sophistication of the scheme has been amplified by artificial intelligence. During job interviews, PurpleDelta operators used screen recording software alongside AI transcription and chatbot tools to generate real-time answers. In some cases, they repeated ChatGPT responses verbatim. Once employed, they recorded internal meetings at victim organizations and used Google Translate to draft pre-written excuses justifying the use of personal devices and bank accounts for work.
As the threat landscape evolves, the increasing integration of AI tools into PurpleDelta’s tradecraft presents a compounding risk. The use of custom ChatGPT assistants, real-time AI transcription during interviews, and AI-generated profile photos lowers the barrier to plausible deception, enabling operators to perform credibly in technical roles they may not fully understand.
Technical Red Flags: PiKVM, Guermok USB, and Laptop Farms
One of the most telling indicators of North Korean employment fraud is the use of hardware manipulation tools. In March 2026, an investigation at an unnamed financial services firm uncovered PiKVM installed on a new hire’s device. PiKVM and similar tools like TinyPilot have been previously attributed to the North Korean IT worker scheme, allowing remote threat actors to connect to devices hosted on laptop farms. These laptop farms are typically operated by facilitators who have been sentenced in U.S. courts for their roles in the scheme.
The same device was also found to have a Guermok USB capture card attached to it. This device enables video streaming to be sent as a webcam input in web conferencing applications such as Zoom. While the use of Guermok alone is not inherently suspicious, the sequence of PiKVM installation followed by Guermok USB attachment raised significant red flags. Days after the hardware installation, the employee accessed a third-party file-sharing service, SendGB, to download a modified version of a legitimate GitHub profile, likely for use as their own profile picture on an internal communications tool.
Identity Theft and Synthetic Personas
In a third case investigated by Huntress in August 2026, a sales and marketing hire who had been onboarded only 13 days earlier was found to have stolen or borrowed an existing identity. The suspected North Korean worker substituted the legitimate individual’s face with their own after the victim’s details — including name, date of birth, location, and mugshot — were posted online by law enforcement following an arrest. This case illustrates the lengths to which these operatives will go to bypass identity verification.
As Huntress noted, mitigating the risk of fraudulent workers begins at the interview stage and continues with performing rigorous background checks of new hires prior to onboarding. Standard background checks, online searches, and verification of employment history are critical steps to weed out North Korean workers early in the hiring process.
How North Korean IT Workers Funnel Salaries to Pyongyang
Once employed, these workers send their Western salaries through a complex web of front companies and intermediaries. According to DTEX, entities such as Sobaeksu, Saenal, and Songkwang — all sanctioned by the U.S. for sanctions evasion — play a key role in funneling funds. Between December 2025 and February 2026, the scheme is estimated to have generated $1.97 million in payments flowing through the sanctioned Ryongbong General Corporation. The proceeds are used to support the regime’s objectives, including weapons manufacturing and supporting Russia’s war effort.
The scale of the financial impact is substantial. In two separate schemes that impacted almost 70 U.S. companies, the operators generated a combined $1.2 million in illicit revenue. Facilitators who run laptop farms from their homes have been sentenced to significant prison terms. In May 2026, two U.S. nationals, Matthew Isaac Knoot and Erick Ntekereze Prince, were sentenced to 18 months in prison each. A month earlier, Kejia Wang and Zhenxing Wang received sentences of 108 and 92 months, respectively, for operating laptop farms in New Jersey that helped workers obtain remote jobs at more than 100 American companies, generating roughly $5 million and causing losses of more than $3 million.
Cryptocurrency Firms Under Siege: A New Front in the DPRK Employment Fraud Campaign
A series of reports from Nisos have revealed that North Korean operatives are also using employment fraud to target cryptocurrency firms with the aim of conducting asset theft. One IT worker was caught applying for a lead AI architect role at a human risk management company, inadvertently exposing their use of PiKVM to maintain control of a device located in a laptop farm containing 20 machines. The incident highlights how the scheme has evolved to target high-value, high-trust roles in emerging technology sectors.
How Does the DPRK IT Worker Scheme Affect Federal Agencies?
The U.S. Federal Bureau of Investigation is currently investigating how a North Korean IT worker successfully gained employment at an unnamed federal government agency. It is believed that the remote IT employee was performing contract work rather than being hired directly. This case underscores the national security implications of the scheme, as unauthorized personnel with ties to a hostile foreign government gain access to sensitive systems and data.
Jasper Sleet Exploits Recruitment Platforms at Scale
Microsoft has disclosed that it observed Jasper Sleet actors accessing Workday Recruiting Web Service endpoints exposed through external career sites. The goal was likely to obtain details about open roles and recruitment workflows. During the recruiting phase, the adversary communicates with the target organization’s hiring team using emails and legitimate platforms like Microsoft Teams, Zoom, or Cisco Webex for interviews. Upon being hired, the threat actors create new Workday profiles and update payroll information, typically tied to a facilitator.
As Group-IB explained, this is not a classic malware intrusion chain. It is a labor-enabled access model built around social engineering, synthetic identity operations, and platform abuse. Operating under synthetic identities, these individuals present themselves as highly experienced developers from all over the world to secure lucrative, long-term remote roles. Beyond the immediate risk of data theft, organizations that unknowingly hire these workers face severe legal and compliance risks, as employing or paying DPRK IT workers could constitute a direct breach of U.N., U.S., and U.K. financial sanctions.
Global Response: A Joint Alert from Eleven Governments
The persistent nature and scale of the threat have prompted nearly a dozen governments to issue a joint alert in July 2026. Cybersecurity and intelligence agencies from the United States, Japan, South Korea, Australia, Canada, France, Germany, Italy, the Netherlands, New Zealand, and the United Kingdom urged all countries, companies, and other entities to intensify efforts to understand the scope of the DPRK worker schemes and implement appropriate countermeasures.
The joint alert recommended that companies operating online platforms strengthen their countermeasures by enhancing identity verification procedures, including strict review of identification documents and requirements for in-person interviews. It also called for the introduction of systems that detect suspicious accounts by notifying anomalous information entries.
Detection Strategies: How Companies Can Identify Fake North Korean Hires
Identifying North Korean workers masquerading as legitimate remote employees requires a multi-layered approach. Huntress recommends that companies begin the vetting process during interviews. Red flags include candidates who consistently refuse to turn on video cameras, those who provide vague or inconsistent answers about their location, and individuals whose submitted identification documents contain anomalies such as poor formatting, inconsistent fonts, or mismatched information.
During onboarding, companies should perform standard background checks, search for the individual’s online presence, and verify employment history with previous employers. Technical indicators such as the use of VPNs or proxy services from known North Korean IP ranges, the presence of PiKVM or similar KVM switches on company-issued devices, and unusual file transfers to third-party sharing services should trigger immediate investigation.
The challenge, as Huntress noted, is that North Korean workers present a unique detection problem. They are not compromising accounts or breaking in through gaps in the organization’s environment. They are tricking companies into remotely hiring them, and often actually doing the legitimate work they were hired to do.
As the threat continues to expand in scale and sophistication, adapting to increased awareness and detection efforts, the onus falls on employers to remain vigilant. The financial, legal, and national security consequences of failing to identify these fraudulent workers are too severe to ignore. The question is no longer whether your company could be targeted, but whether you would detect it before the damage is done.