VMTech
Discuss a project

DPRK Employment Fraud Reaches Healthcare, Sales and Marketing

DPRK Employment Fraud Reaches Healthcare, Sales and Marketing

North Korean-linked employment fraud is moving beyond software roles into healthcare, sales and marketing, with Huntress identifying suspected workers at an Australian healthcare company, an unnamed financial services firm and a sales and marketing employer. Recorded Future’s Insikt Group also observed a PurpleDelta cluster applying for roles at more than 1,100 companies between late 2024 and early 2025.

The activity is part of the long-running DPRK IT worker scheme, in which operatives use stolen or forged identities, VPNs and proxy services to obtain remote jobs. The workers may perform the legitimate duties for which they were hired, making the problem an insider-risk and hiring-control issue rather than a conventional account compromise.

Evidence extends across different business functions

In February 2026, three employees at an Australian healthcare company were flagged as suspected North Korean workers impersonating Chinese individuals. Huntress cited repeated use of Astrill VPN and IPRoyal Proxy, fraudulently created identity documents, similarities between two passports and unusual wording in electronic proof-of-residence bills.

At a financial services firm, investigators found PiKVM on an employee device. KVM products such as PiKVM and TinyPilot have been associated with the scheme because they can let remote operators control devices held in laptop farms. The device later received a Guermok USB capture card, a sequence Huntress said raised concerns because it could support video streaming as webcam input in conferencing applications including Zoom.

In a separate August 2026 investigation, a sales and marketing employee hired 13 days earlier appeared to have used the identity of a person whose name, date of birth, location and mugshot had been posted online by law enforcement after an arrest. Huntress assessed that the legitimate person’s face had been replaced with that of the suspected DPRK worker.

AI and platform tools support high-volume applications

Recorded Future linked PurpleDelta to 22 fabricated personas, some synthetically generated with AI, and said the group sourced identity documents through the illicit TrustID Card service. The operators applied to at least 60 jobs a day across 10 job platforms, using multi-account management browsers, separate Google Chrome profiles and tracking spreadsheets to coordinate personas.

During interviews, the group used screen-recording software, AI transcription and chatbot tools to produce real-time answers, at times repeating ChatGPT output verbatim. Once hired, operators recorded internal meetings and used Google Translate to prepare excuses for using personal devices and bank accounts. Recorded Future also reported use of identity-brokering services, AnyDesk account-renting and facilitators who obtained or maintained company hardware.

Hiring checks become a security and compliance control

The operational impact extends beyond unauthorized workplace access. Group-IB warned that organisations paying DPRK IT workers may face legal and compliance exposure under U.N., U.S. and U.K. financial sanctions. The U.S., Japan, South Korea, Australia, Canada, France, Germany, Italy, the Netherlands, New Zealand and the U.K. recently urged stronger identity verification and detection of suspicious account information.

For businesses, the practical implication is to treat recruitment as part of the security perimeter: conduct rigorous background and employment-history checks before onboarding, scrutinise identity documents and investigate anomalous network, device and remote-access signals before granting access to systems and data.

#cybersecurity#identitysecurity#insiderthreat#hiringsecurity
Open analytics
On the site 0 views
min read 4 31.08.2026
Instagram

DPRK Employment Fraud Reaches Healthcare, Sales and Marketing

Open the post on Instagram ↗