news.mlab.sh
Back to the feed
threat-intel

North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales

High
Summary

North Korean actors are increasingly leveraging sophisticated social engineering tactics to infiltrate companies worldwide, bypassing traditional cybersecurity measures. Rather than directly attacking systems, they are successfully obtaining employment through fabricated identities, stolen documents, and remote work arrangements, primarily to fund North Korea’s weapons programs. The scheme involves a complex network of facilitators, AI-generated identities, and tools like VPNs and PiKVM switches, and is expanding beyond the IT sector into sales, marketing, and healthcare. The U.S. government is actively investigating cases and issuing joint alerts with other nations to combat this growing threat.

Threat actors with ties to the Democratic People's Republic of Korea (DPRK or North Korea) are expanding their tactics beyond the traditional IT sector, now actively seeking employment in sales, marketing, and even healthcare to further Pyongyang’s unlawful nuclear weapons and ballistic missile programs. This ongoing scheme, often referred to as the ‘IT worker scheme,’ relies on a complex network of facilitators and increasingly sophisticated social engineering techniques to bypass conventional cybersecurity defenses.

Instead of directly compromising systems, North Korean actors are successfully obtaining employment by presenting themselves as legitimate candidates with fabricated identities and stolen or forged documents. They utilize VPNs and proxy services to mask their true location and identity, and increasingly rely on synthetic identities generated using AI. The scheme has been tracked under various monikers, including Famous Chollima, Jasper Sleet, Nickel Tapestry, PurpleDelta (formerly TAG-121), UNC5267, and Wagemole.

Recent investigations have revealed multiple cases of success. In February 2026, three employees of an Australian healthcare company were flagged as North Korean workers after repeatedly connecting through Astrill VPN and IPRoyal Proxy, presenting fraudulent identity documents, and exhibiting word anomalies in submitted bills. Another case this month at a financial services firm uncovered the use of PiKVM, a KVM switch, to allow remote access to devices hosted on laptop farms. These devices are then used to conduct remote work, often leveraging AI transcription and screen recording to mimic legitimate work performance.

PurpleDelta, a group linked to the scheme, has applied to over 1,100 companies, mostly in software and technology, staffing and consulting, and healthcare and biotechnology sectors, between late 2024 and early 2025. The operators use multi-account management browsers and separate Google Chrome profiles to manage distinct personas and maintain extensive tracking spreadsheets to coordinate applications. They also employ AI tools to generate realistic interview answers and profile pictures.

The U.S. Federal Bureau of Investigation (FBI) is currently investigating how a North Korean IT worker gained employment at a federal government agency, working remotely to support the regime’s objectives. The scheme is also being used to support Russia’s war effort, funneling Western salaries through a web of front companies and intermediaries, including entities like Sobaeksu, Saenal, and Songkwang, which have been sanctioned in the U.S. for sanctions evasion.

Recent reports from Nisos have revealed how DPRK operatives are using employment fraud to target cryptocurrency firms, with one IT worker caught applying for a lead AI architect role at a human risk management company, inadvertently exposing their use of PiKVM to maintain control of their device located in a laptop farm containing 20 machines. Microsoft has also disclosed that Jasper Sleet actors accessed Workday Recruiting Web Service endpoints to obtain details about open roles and recruitment workflows.

Nearly a dozen governments issued a joint alert last month, urging all countries, companies, and other entities to intensify efforts to understand the scope of the DPRK worker schemes and implement appropriate countermeasures. Companies operating online platforms should strengthen their identity verification procedures and detect suspicious accounts. The persistent nature and scale of the threat necessitate a multi-faceted approach to mitigate the risks associated with this evolving scheme.

Read the full article at The Hacker News