DPRK-linked threat actors are expanding their “IT worker” scheme into sales, marketing, healthcare, and finance by using synthetic identities, forged documents, VPNs, proxy services, and AI tools to secure remote jobs at targeted organizations. Investigations also show use of laptop farms, PiKVM, and related infrastructure to maintain access, helping fund North Korea’s weapons programs and exposing victim companies to sanctions and compliance risks. #PurpleDelta #FamousChollima #JasperSleet #PiKVM #AstrillVPN #IPRoyal #TrustIDCard #Workday #SendGB #Guermok
Keypoints
- DPRK workers are now applying beyond IT into sales, marketing, healthcare, and finance.
- The scheme uses stolen identities, forged documents, VPNs, and proxy services to hide origin.
- Huntress found cases involving Astrill VPN, IPRoyal Proxy, PiKVM, SendGB, and Guermok.
- Recorded Future linked PurpleDelta to more than 1,100 company applications and AI-assisted deception.
- The activity helps fund North Korea’s weapons programs and creates sanctions and compliance risks.
Read More: https://thehackernews.com/2026/08/north-korean-job-fraud-expands-beyond.html