North Korean Job Fraud Expands to Healthcare and Finance Sectors
North Korean threat actors have broadened their fraudulent employment scheme beyond the IT sector, with new investigations revealing operatives embedded in healthcare, sales, and financial services roles at companies worldwide. The campaign, tracked by Huntress and others under monikers including Famous Chollima, Jasper Sleet, Nickel Tapestry, PurpleDelta, UNC5267, and Wagemole, generates revenue for Pyongyang's nuclear weapons and ballistic missile programs. Workers fraudulently secure remote positions at Fortune 500 firms and private sector companies using stolen or forged identities, VPNs, and proxy services to mask their true locations.
In one February 2026 case, three employees at an Australian healthcare company were flagged as North Korean operatives impersonating Chinese nationals. Investigators identified repeated connections through Astrill VPN and IPRoyal Proxy, fraudulent identity documents, suspicious similarities between two employees' passports, and word anomalies in electronic bills submitted as proof of residence. Huntress noted the documents may contain legitimate information or images lifted from identity theft victims, a reminder that HR and security teams should verify candidate credentials against known compromised data using an email breach checker to flag recycled identities. Defenders can also run a VPN and proxy detection scan to identify suspicious anonymized connections during onboarding.
A second case at an unnamed financial services firm uncovered PiKVM software installed on a worker's device — a hallmark of the DPRK IT worker scheme that allows remote operators to control hardware hosted in laptop farms. The "employee" was also found accessing SendGB to download a modified GitHub profile image for use on internal communications platforms. Days after PiKVM installation, a Guermok USB capture card was attached to stream video into web conferencing tools like Zoom — a sequencing pattern that should trigger immediate endpoint monitoring alerts.
Huntress's third investigation is expected to be detailed in a forthcoming report. Organizations are urged to harden identity verification during remote hiring, monitor for unauthorized KVM-based remote access tools, and cross-reference applicants against known DPRK infrastructure indicators. A periodic DNS leak test across corporate networks can help security teams ensure remote endpoints aren't inadvertently routing traffic through adversary-controlled anonymization infrastructure.