Suspected North Korean Employment Fraud Reportedly Moves Into Healthcare, Sales Roles
Security researchers say suspected North Korean remote-worker operations are increasingly targeting jobs outside traditional IT roles, with recent cases involving healthcare, financial services, and s...
Security researchers say suspected North Korean remote-worker operations are increasingly targeting jobs outside traditional IT roles, with recent cases involving healthcare, financial services, and sales and marketing positions.
The activity is part of a long-running employment fraud scheme in which workers allegedly use stolen or fabricated identities to obtain remote roles at companies abroad. Investigators say the operators can conceal their location through VPNs, proxy services, intermediaries, and company-managed devices. Governments have warned that revenue from such work may support North Korea's sanctioned weapons programs.
Cases point to broader targeting
Huntress described a February 2026 investigation involving three workers at an Australian healthcare company who were allegedly posing as Chinese nationals. Indicators included repeated use of Astrill VPN and IPRoyal Proxy services, questionable identity records, similarities in submitted passport materials, and unusual wording in documents offered as residence evidence.
In another case at a financial services organization, researchers found PiKVM software on a company device. KVM-over-IP tools can allow a remote person to operate a laptop hosted elsewhere, a setup commonly associated with so-called laptop farms. Investigators also noted a USB capture device was connected shortly afterward, potentially enabling video to be presented to conferencing software as a webcam feed.
A separate sales and marketing hire was suspected of using the details of another person whose identifying information and photograph had appeared online following an arrest. Researchers said the employee may have replaced the original person's image while retaining other biographical details.
Use of AI and identity services
Recorded Future's Insikt Group said a cluster it tracks as PurpleDelta submitted applications to more than 1,100 companies from late 2024 through early 2025. The group reportedly operated at least 22 false personas and targeted technology, consulting, staffing, healthcare, and biotechnology employers.
According to the report, operators used tools for managing multiple accounts, maintained application-tracking spreadsheets, and may have used AI-generated profile images. During interviews, they allegedly relied on screen recording, transcription tools, and chatbots to formulate responses in real time. The researchers also reported the use of identity-brokering services, remote-access accounts, and facilitators who maintain employer-issued hardware.
Hiring controls remain central
Researchers recommend that organizations strengthen pre-employment screening, independently validate identity documents and work history, scrutinize unusual network or device activity after onboarding, and establish procedures for confirming that remote workers are operating from approved locations. These checks should be applied consistently while respecting legal, privacy, and employment requirements.
