North Korean threat actors are expanding their remote-job fraud operations beyond the information technology sector, with recent investigations identifying suspected workers employed in sales, marketing, and the medical profession. This marks a significant evolution in a scheme that traditionally targeted tech roles at major corporations worldwide.
The ongoing insider threat forms part of what researchers call the IT worker scheme, where North Korea leverages skilled workers to fraudulently land jobs at Fortune 500 and private-sector firms. Because these workers then remotely earn income, the scheme directly funds Pyongyang’s unlawful nuclear weapons and ballistic missile programs. The operation relies on stolen or forged identity documents, VPNs, and proxy services to mask the workers’ true locations.
According to cybersecurity firm Huntress, these workers present a unique detection challenge. Rather than breaking into systems, they trick companies into hiring them, often performing legitimate work afterward. In one February 2026 case, three employees of an Australian healthcare company were flagged as North Korean workers impersonating Chinese nationals, exposed through repeated Astrill VPN connections and suspicious identity documents.
“DPRK workers present a unique detection challenge for defenders: rather than compromising accounts or breaking in via gaps in the organizations’ environments, they’re tricking companies into remotely hiring them, and oftentimes actually doing the legitimate work they were hired to do,” Huntress said in an analysis.
“Despite the likelihood of passports and resident identity cards being fraudulent, there’s still the possibility that these documents contained legitimate information or pictures from others who have had their identity information stolen or borrowed,” Huntress added.
“Mitigating the risk of fraudulent workers begins at the interview stage and continues with performing rigorous background checks of new hires prior to onboarding,” Huntress said. “When in doubt, performing standard background checks, searching the individuals online, and verifying any employment history will help to weed out DPRK workers early in the interview process.”
Investigators also uncovered sophisticated hardware setups enabling remote control. One financial services firm discovered PiKVM devices, allowing operators to connect to laptop farms remotely. Meanwhile, another case revealed a sales hire who had stolen an identity, replacing the legitimate person’s face after their arrest details appeared online.
Artificial intelligence increasingly powers these operations. Recorded Future’s Insikt Group tracked one cluster, dubbed PurpleDelta, that applied to over 1,100 companies while maintaining 22 fabricated personas, some AI-generated. Operators reportedly applied to at least 60 positions daily across 10 job platforms. During interviews, they used AI transcription and chatbot tools to generate real-time answers, often repeating ChatGPT responses verbatim.
The financial stakes remain substantial. The scheme has funneled Western salaries through sanctioned front companies, with one estimate showing $1.97 million flowing through the sanctioned Ryongbong General Corporation between December 2025 and February 2026.
The persistent threat prompted nearly a dozen governments, including the US, Japan, South Korea, and the UK, to issue a joint alert last month. They urged companies to strengthen identity verification through strict document review and in-person interviews to weed out fraudulent workers early.

