North Korean workers target sales, medical
North Korean remote workers are securing jobs in sales, marketing, and medicine using forged documents and remote control hardware, Huntress reports.

North Korean remote workers are expanding their job searches beyond IT, according to security firm Huntress. Recent investigations have identified suspected DPRK workers employed in sales, marketing, and the medical profession.
Huntress states these workers present a unique detection challenge. They are not breaking in; companies are hiring them remotely, and they often perform legitimate work. The workers frequently use stolen identity documents, VPNs, and proxy services to mask their true identity and location.
Fake passports from a single template
In one case involving an Australian healthcare organization, Huntress analyzed six months of login records for three accounts. The accounts repeatedly connected through Astrill VPN and IPRoyal Proxy. Less than half of their activity occurred during normal business hours, with their busiest period aligning with 9 a.m. in North Korea.
Two workers uploaded a resident ID card, a passport, and an electricity bill for verification. The passports were issued in the same city one day apart. The ID cards had identical validity dates and the same issuing police station. Photos were taken at similar angles using the same phone model, minutes apart.
Researchers noted that both individuals likely accidentally used a photo of the same resident identity card rear, based on consistent visible damage. The electricity bills contained the same typos and appeared based on an online template. Huntress suggested the errors could stem from a translation issue if optical character recognition was used.
Despite the likely fraud, researchers cautioned the documents might contain legitimate information or pictures from stolen identities.
Hardware enabling remote laptop control
A second case at a financial services firm involved a hardware anomaly. Investigators found a PiKVM device connected to a new hire's laptop within hours of delivery. This open-source device plugs into a computer, allowing remote operation.
Windows logs showed the machine moving from a managed service provider's network to a travel router, then to a home Wi-Fi network named "Pickle_Rick," before landing on a fixed Ethernet connection. This sequence could indicate the laptop had become part of a laptop farm.
The same laptop had a Guermok USB capture card attached. This device registers as a webcam, enabling video streaming to be sent as webcam input in applications like Zoom. Huntress notes the Guermok device alone is not evidence of DPRK involvement but becomes significant when it co-occurs with a PiKVM.
The worker also downloaded an altered photo from another person's GitHub profile, potentially for an internal communications tool. When asked to show their workspace, the worker refused and was reluctant to appear on camera, leaving their identity questionable.
Identity documents with swapped photos
At a separate partner organization, a sales and marketing hire onboarded 13 days earlier appeared to have used another person's identity with the photo swapped out. Investigators found a police mugshot of a person whose name, date of birth, and location matched the submitted documents. The mugshot did not match the photo on the ID.
The identification numbers passed validation checks. This suggests the documents contained information belonging to an existing person and had been digitally altered.
Huntress concludes the threat of DPRK remote workers persists due to detection challenges. Mitigation begins at the interview stage with rigorous background checks, online searches, and verification of employment history. For more on common attack vectors, see our fixtures page. Understanding these patterns is crucial for building a resilient defense squad.




