North Korean IT Workers Infiltrate New Sectors, Leveraging AI and Sophisticated Deception
Threat actors linked to the Democratic People's Republic of Korea (**DPRK**) are expanding their remote IT worker scheme beyond traditional tech roles, infiltrating sales, marketing, and even healthcare. These operatives are employing advanced tactics, including AI-generated personas and sophisticated identity fraud, to secure positions in global companies and funnel illicit earnings to Pyongyang's weapons programs.
Threat actors with ties to the **Democratic People's Republic of Korea** (aka **DPRK** or **North Korea**) are increasingly seeking job opportunities beyond the information technology (IT) sector. Recent investigations have identified suspected **DPRK** workers employed in sales and marketing and the medical profession.
This ongoing insider threat is part of what's known as the **IT worker scheme**, where **North Korea** leverages a network of skilled IT workers, both domestically and abroad, to fraudulently secure jobs in **Fortune 500** companies and private sector firms worldwide. The income generated remotely directly supports Pyongyang's unlawful nuclear weapons and ballistic missile programs.
### The Modus Operandi: Deception and Obfuscation
Operatives rely on stolen or forged identity documents, **VPNs**, and proxy services to mask their true identity and location. This years-long campaign is also tracked under various monikers, including **Famous Chollima**, **Jasper Sleet**, **Nickel Tapestry**, **PurpleDelta** (formerly **TAG-121**), **UNC5267**, and **Wagemole**.
"**DPRK** workers present a unique detection challenge for defenders: rather than compromising accounts or breaking in via gaps in the organizations' environments, they're tricking companies into remotely hiring them, and oftentimes actually doing the legitimate work they were hired to do," stated **Huntress** in a recent analysis.
### Case Studies in Deception
In one instance from February 2026, three employees of an Australian healthcare company were flagged as **North Korean** workers impersonating Chinese individuals. Red flags included repeated connections through **Astrill VPN** and **IPRoyal Proxy**, fraudulently created identity documents, similarities in passports, and glaring word anomalies in electronic bills submitted as proof of residence.
"Despite the likelihood of passports and resident identity documents being fraudulent, there's still the possibility that these documents contained legitimate information or pictures from others who have had their identity information stolen or borrowed," **Huntress** added.
A second case, involving an unnamed financial services firm, uncovered the presence of **PiKVM** on an employee's device. The use of KVM switches like **PiKVM** or **TinyPilot** has been previously attributed to the **North Korean IT worker scheme**, enabling remote threat actors to connect to devices hosted on laptop farms.
The 'employee' in this case also accessed the third-party file-sharing service **SendGB** to download a modified legitimate **GitHub** profile, likely for use as their own profile picture on an internal communications tool. Days after the **PiKVM** installation, the same device had a **Guermok USB** capture card attached, enabling "video streaming through it to be sent as a webcam input in web conferencing applications such as Zoom." While **Guermok** use alone isn't suspicious, the sequential installation with **PiKVM** raises significant concerns.
In a third case investigated by **Huntress** in August 2026, a sales and marketing hire appeared to have stolen or borrowed an existing identity. The legitimate individual's face was substituted with that of the suspected **DPRK** worker after the former's details, including name, date of birth, and location, along with their mugshot, were posted online by law enforcement following an arrest.
### The Scale of the Threat: PurpleDelta's Operations
These are not isolated incidents. **Recorded Future's Insikt Group** observed one cluster linked to **PurpleDelta** applying to jobs at over 1,100 companies between late 2024 and early 2025. These applications primarily targeted software and technology, staffing and consulting, and healthcare and biotechnology sectors.

The threat actors, likely multiple operators based in China, are suspected of maintaining 22 fabricated personas, some synthetically generated using artificial intelligence (**AI**). They also utilize identity documents sourced from an illicit ID-generation service called **TrustID Card** ("trustidcard[.]com").
**Recorded Future** described **PurpleDelta** as maintaining a "high operational tempo," applying to at least 60 positions per day across 10 job platforms. They employ multi-account management browsers and separate **Google Chrome** profiles to manage distinct personas, alongside extensive tracking spreadsheets to coordinate applications.
"During job interviews, they used screen recording software alongside **AI** transcription and chatbot tools to generate real-time answers, often repeating **ChatGPT** responses verbatim," **Recorded Future** added. "Once employed, operators recorded internal meetings at victim organizations and used **Google Translate** to draft pre-written excuses to justify using personal devices and bank accounts for work."
**PurpleDelta** operators also rely on identity-brokering services, account-renting via **AnyDesk**, and multi-accounting tools. They coordinate via **Telegram** and **Slack** and communicate with facilitators who procure and maintain company-issued hardware on their behalf.
"**PurpleDelta** activity is almost certainly ongoing and will very likely continue to expand in scale and sophistication as **North Korean** IT workers adapt to increased awareness and detection efforts," **Recorded Future** explained. "The increasing integration of **AI** tools into **PurpleDelta's** tradecraft presents a compounding risk. The use of custom **ChatGPT** assistants, real-time **AI** transcription during interviews, and **AI**-generated profile photos lowers the barrier to plausible deception and enables operators to perform credibly in technical roles they may not fully understand."
### Broader Implications and Recent Developments
These findings coincide with several related developments:
* The **U.S. Federal Bureau of Investigation (FBI)** is investigating how a **North Korean** IT worker successfully gained employment at an unnamed federal government agency. The individual is believed to have performed contract work rather than being hired directly.
* The operators are funneling Western salaries through a network of front companies and intermediaries, including entities like **Sobaeksu**, **Saenal**, and **Songkwang**, which have been sanctioned in the U.S. for sanctions evasion. According to **DTEX**, the scheme also supports the regime's objectives, such as weapons manufacturing and supporting Russia's war effort. The scheme is estimated to have generated $1.97 million in payments between December 2025 and February 2026, flowing through the sanctioned **Ryongbong General Corporation**.
* Earlier this May, two U.S. nationals, **Matthew Isaac Knoot** and **Erick Ntekereze Prince**, were sentenced to 18 months in prison each for operating laptop farms for **North Korean** remote IT workers. These two separate schemes impacted almost 70 U.S. companies and generated a combined $1.2 million in illicit revenue.
* A month prior, 42-year-old **Kejia Wang** and 39-year-old **Zhenxing Wang** were sentenced to 108 and 92 months in prison, respectively, for operating a similar laptop farm in their homes in New Jersey. They helped IT workers obtain remote jobs at over 100 American companies, generating approximately $5 million and causing losses of more than $3 million to victim companies.
### Mitigating the Risk
"Mitigating the risk of fraudulent workers begins at the interview stage and continues with performing rigorous background checks of new hires prior to onboarding," **Huntress** advised. "When in doubt, performing standard background checks, searching the individuals online, and verifying any employment history will help to weed out **DPRK** workers early in the interview process."
As these sophisticated schemes evolve, robust vetting processes and continuous monitoring of employee activities become paramount for organizations safeguarding against illicit infiltration and financial exploitation.