Zero Day Room
Live
Regulation & compliance

North Korean IT Fraud Expands to Healthcare

North Korean state-linked threat actors are expanding fraudulent remote job schemes beyond IT into healthcare, sales, and marketing to fund illicit

North Korean state-linked threat actors are expanding fraudulent remote job schemes beyond IT into healthcare, sales, and...

North Korean state-linked threat actors are fraudulently securing remote jobs beyond the IT sector, now targeting healthcare, sales, and marketing roles to generate income for the regime's weapons programs. This ongoing campaign, tracked as the IT worker scheme, uses stolen or forged identities, VPNs, and proxy services to mask the workers' true locations and nationalities.

Huntress, a cybersecurity firm, notes these workers present a unique challenge. They are not breaking in through technical vulnerabilities. Companies are hiring them directly. "DPRK workers present a unique detection challenge for defenders: rather than compromising accounts or breaking in via gaps in the organizations' environments, they're tricking companies into remotely hiring them, and oftentimes actually doing the legitimate work they were hired to do," the firm stated.

Recent Cases Reveal Evolving Tactics

Investigations in 2026 have uncovered specific instances of this fraud. In February, three employees at an Australian healthcare company were flagged as North Korean operatives impersonating Chinese nationals. Detection clues included repeated connections through Astrill VPN and IPRoyal Proxy, fraudulent identity documents, and anomalies in electronic bills submitted for proof of residence.

A separate case at a financial services firm this month found a device with PiKVM installed, a tool previously linked to this scheme for remote device control. Days later, a Guermok USB capture card was attached to the same device, enabling video streaming to mimic a webcam in applications like Zoom. The sequential installation raised suspicions.

In August 2026, Huntress investigated a sales and marketing hire who had used a stolen identity. The worker substituted their own face onto the mugshot of a legitimate individual whose details were posted online by law enforcement after an arrest.

PurpleDelta's High-Volume Operation

Recorded Future's Insikt Group has tracked one cluster, linked to the threat actor PurpleDelta, applying to jobs at over 1,100 companies between late 2024 and early 2025. The targeted sectors were primarily software and technology, staffing and consulting, and healthcare and biotechnology.

The group, likely based in China, maintained at least 22 fabricated personas. Some identities were synthetically generated using AI, with documents sourced from an illicit service called TrustID Card. Their operation maintained a high tempo.

Once employed, operators used tools like Google Translate to draft excuses for using personal devices and bank accounts. They also coordinated via Telegram and Slack and used identity-brokering services and account-renting tools like AnyDesk.

The Role of AI and Wider Implications

The integration of AI tools is lowering the barrier to credible deception. Recorded Future highlighted the use of custom ChatGPT assistants, real-time AI transcription during interviews, and AI-generated profile photos. This enables operators to perform in technical roles they may not fully understand.

These findings coincide with several related law enforcement actions and disclosures. The FBI is investigating how a North Korean IT worker gained employment at an unnamed U.S. federal agency. Recent U.S. court cases have seen individuals sentenced for running laptop farms that hosted North Korean remote workers, impacting dozens of companies and generating millions in illicit revenue.

According to DTEX, payments from this scheme are funneled through sanctioned front companies like Sobaeksu, Saenal, and Songkwang. An estimated $1.97 million flowed through the sanctioned Ryongbong General Corporation between December 2025 and February 2026 to support objectives including weapons manufacturing and Russia's war effort.

Microsoft has observed related actors, tracked as Jasper Sleet, accessing Workday Recruiting Web Service endpoints to gather details on open roles. Group-IB characterizes this not as a classic malware intrusion but as a "labor-enabled access model."

Related coverage

More from Regulation & compliance