North Korean operatives seeking remote work to fund weapons programs are no longer limiting themselves to information technology positions, according to new investigations published by cybersecurity firm Huntress and threat intelligence company Recorded Future in August 2026. Recent cases have identified suspected workers employed in sales, marketing, and the medical profession, expanding what has been called the IT worker scheme. The yearslong campaign leverages stolen or forged identity documents, VPNs, and proxy services to mask workers' true identities and locations, allowing them to fraudulently land jobs at Fortune 500 companies and private firms worldwide.

Huntress documented three recent cases showing the breadth of infiltration. In February 2026, three employees at an Australian healthcare company were flagged as North Korean workers posing as Chinese individuals after investigators found repeated connections through Astrill VPN and IPRoyal Proxy, fraudulently created identity documents, similarities between two employees' passports, and conspicuous word anomalies in electronic bills submitted as proof of residence. A second case this month at a financial services firm uncovered the presence of PiKVM—a KVM switch that allows remote threat actors to connect to devices hosted on laptop farms—on an employee's device. Days later, the same device had a Guermok USB capture card attached to enable video streaming as a webcam input for web conferencing applications like Zoom. In August 2026, a sales and marketing hire onboarded 13 days earlier appeared to have stolen or borrowed an existing identity, substituting the legitimate individual's face with the suspected worker after the real person's details were posted online by law enforcement following their arrest.

Recorded Future's Insikt Group observed one cluster linked to the threat actor PurpleDelta applying to jobs at over 1,100 companies between late 2024 and early 2025, mostly in software and technology, staffing and consulting, and healthcare and biotechnology sectors. The threat actors maintained 22 fabricated personas, some synthetically generated using artificial intelligence, and used identity documents sourced from an illicit ID-generation service called TrustID Card. PurpleDelta applied to at least 60 positions per day across 10 job platforms, used multi-account management browsers and separate Google Chrome profiles to manage distinct personas, and maintained extensive tracking spreadsheets to coordinate applications across identities. During job interviews, operators used screen recording software alongside AI transcription and chatbot tools to generate real-time answers, often repeating ChatGPT responses verbatim. The scheme is estimated to have made $1.97 million in payments between December 2025 and February 2026 flowing through the sanctioned Ryongbong General Corporation, with operators funneling Western salaries through a web of front companies and intermediaries.

"DPRK workers present a unique detection challenge for defenders: rather than compromising accounts or breaking in via gaps in the organizations' environments, they're tricking companies into remotely hiring them, and oftentimes actually doing the legitimate work they were hired to do," Huntress stated in the analysis. Recorded Future characterized PurpleDelta as maintaining a "high operational tempo" and warned that the activity "is almost certainly ongoing and will very likely continue to expand in scale and sophistication as North Korean IT workers adapt to increased awareness and detection efforts." According to the report, once employed, operators recorded internal meetings at victim organizations and used Google Translate to draft pre-written excuses to justify using personal devices and bank accounts for work.

The persistent nature and scale of the threat have prompted action from governments and resulted in criminal prosecutions. Nearly a dozen governments issued a joint alert late last month urging all countries, companies, and other entities to intensify efforts to understand the scope of the worker schemes and implement appropriate countermeasures, including enhancing identity verification procedures and requiring in-person interviews. The U.S. Federal Bureau of Investigation is investigating how a North Korean IT worker successfully gained employment at an unnamed federal government agency doing contract work. In May, two U.S. nationals were sentenced to 18 months in prison each for running a laptop farm for North Korean remote IT workers, impacting almost 70 U.S. companies and generating a combined $1.2 million in illicit revenue. Earlier this year, two other individuals were sentenced to 108 and 92 months in prison for operating a similar laptop farm and helping IT workers obtain remote jobs at more than 100 American companies, generating roughly $5 million and causing losses of more than $3 million. Organizations that unknowingly hire these workers face severe legal and compliance risks, as employing or paying them could constitute a direct breach of U.N., U.S., and U.K. financial sanctions. Companies will need to balance the efficiency of remote hiring against the heightened scrutiny required to verify candidate identities, a trade-off that may reshape recruitment workflows across industries reliant on distributed talent pools.