"DPRK workers present a unique detection challenge for defenders: rather than compromising accounts or breaking in via gaps in the organizations' environments, they're tricking companies into remotely hiring them, and oftentimes actually doing the legitimate work they were hired to do," Huntress said.
Huntress investigations: healthcare, sales and medical hires flagged
Huntress has documented cases this year that expand a long-running North Korean employment-fraud campaign beyond information technology roles into healthcare, sales and marketing, and medical positions. In February 2026, three employees of an Australian healthcare company were flagged as North Korean workers impersonating Chinese individuals after repeated connections through Astrill VPN and IPRoyal Proxy, use of fraudulently created identity documents, passport similarities, and anomalous wording in electronic bills submitted as proof of residence.
In August 2026, Huntress investigated a sales and marketing hire who had onboarded 13 days earlier and appeared to have stolen or borrowed an existing identity; the attacker substituted the legitimate individual's face after the person's details and mugshot were posted online by law enforcement following an arrest. Huntress advised that rigorous background checks beginning at the interview stage, online searches and verification of employment history help to "weed out DPRK workers early in the interview process."
Recorded Future: PurpleDelta's scale, personas and AI tradecraft
Recorded Future's Insikt Group linked a cluster of activity to the group it calls PurpleDelta and said that cluster applied to jobs at over 1,100 companies — chiefly in software and technology, staffing and consulting, and healthcare and biotechnology — between late 2024 and early 2025. The operators are believed to have run 22 fabricated personas, some generated with artificial intelligence, and used an illicit ID-generation service called TrustID Card ("trustidcard[.]com") for identity documents.
Recorded Future described PurpleDelta as maintaining a "high operational tempo": applying to at least 60 positions per day across 10 job platforms, using multi-account browser management and separate Chrome profiles to handle distinct personas, and keeping extensive tracking spreadsheets. During interviews, operators deployed screen recording with AI transcription and chatbot tools to generate answers, sometimes repeating ChatGPT responses verbatim, the firm said. Once employed, operators recorded internal meetings and used Google Translate to compose excuses for using personal devices and bank accounts.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildTradecraft observed: PiKVM, Guermok, Astrill, SendGB and Workday abuse
Multiple technical artifacts recur across investigations. KVM switches such as PiKVM and TinyPilot have been used to connect to devices hosted in laptop farms; one firm discovered PiKVM installed on a device and, days later, a Guermok USB capture card was attached so video streaming could be presented as a webcam input for web conferencing. Huntress noted that Guermok by itself is not necessarily suspicious, but the sequence of PiKVM plus Guermok raised alarm.
Other observed tools and behaviors include: repeated VPN/proxy use via Astrill and IPRoyal; use of third-party file-sharing service SendGB to download a modified GitHub profile image; account-renting via AnyDesk; identity-brokering services; and communication and coordination over Telegram and Slack. Microsoft reported in April that Jasper Sleet actors accessed Workday Recruiting Web Service endpoints on external career sites to gather details about open roles and recruitment workflows, and that during recruiting the adversary has used legitimate platforms such as Microsoft Teams, Zoom, and Cisco Webex for interviews.
Financial flows, prosecutions, and sanctions links
Investigators say operators are funneling Western salaries through front companies and intermediaries — including entities like Sobaeksu, Saenal, and Songkwang that have been sanctioned in the U.S. for sanctions evasion. DTEX reported that payments tied to the scheme flowed through the sanctioned Ryongbong General Corporation and that between December 2025 and February 2026 the network moved about $1.97 million in payments.
U.S. prosecutions have also followed: in May 2026 two U.S. nationals, Matthew Isaac Knoot and Erick Ntekereze Prince, were each sentenced to 18 months in prison for running a laptop farm used by North Korean remote IT workers — schemes that affected almost 70 U.S. companies and generated roughly $1.2 million in illicit revenue. Earlier, Kejia Wang and Zhenxing Wang received 108 and 92 months respectively for operating a laptop farm and helping North Korean IT workers obtain remote roles at more than 100 American companies, producing roughly $5 million and causing losses of more than $3 million to victim firms; four others — Oleksandr Didenko, Audricus Phagnasay, Jason Salazar, and Alexander Paul Travis — were sentenced in February and March.
What this means for technologists, policymakers, and affected enterprises
- Technologists and security teams: Huntress and Recorded Future underscore that conventional intrusion detection is not sufficient — teams should add identity verification controls during recruiting, monitor for KVM devices or unexpected USB capture hardware, and scrutinize anomalous payroll or device-hosting arrangements.
- Policymakers and regulators: The FBI is investigating how a North Korean IT worker obtained contract work at an unnamed federal agency, and nearly a dozen governments issued a joint alert urging strengthened identity verification on hiring platforms. Regulators will face pressure to reconcile recruitment platform rules with sanctions enforcement.
- Affected enterprises and procurement leaders: Organizations that unknowingly employ these workers risk legal and compliance exposure, since Group-IB warned that paying DPRK IT workers could breach U.N., U.S., and U.K. financial sanctions; firms should enforce rigorous background checks and review payroll routing.
Across multiple investigations, the pattern is clear: a labor-enabled access model built on synthetic identities, laptop farms and an expanding toolkit — now supplemented with AI-generated personas and real-time transcription — is enabling adversaries to land real jobs inside real companies. Recorded Future concluded that PurpleDelta activity is "almost certainly ongoing" and will likely increase in scale and sophistication as operators adapt to detection efforts. That raises a pointed operational question for defenders and regulators alike: can hiring systems be hardened quickly enough to match a threat that is already treating employment as an attack surface?




