International Cyber Expo International Cyber Expo
  • About Us
Saturday, 10 October, 2026
IT Security Guru
International Cyber Expo
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Huntress Uncovers Five Cases of North Korean Operatives Posing as Remote IT, Sales and Healthcare Workers

Researchers say fraudulent hires used doctored passports, stolen photos and hidden remote-access hardware to pass as legitimate employees

by Guru Writer
August 26, 2026
in Featured
Huntress Uncovers Five Cases of North Korean Operatives Posing as Remote IT, Sales and Healthcare Workers
Share on FacebookShare on Twitter

Cybersecurity firm Huntress has confirmed five separate incidents this year in which suspected North Korean operatives were successfully hired into legitimate organisations under false identities, in a wave of activity researchers say shows how the country’s so-called “remote IT worker” scheme has expanded well beyond IT roles.

The cases, disclosed in a new advisory, involved workers placed in healthcare, financial services, and sales and marketing positions across partner organisations. Unlike traditional cyberattacks, the threat does not rely on breaching networks or stealing credentials. Instead, operatives linked to the group tracked as FAMOUS CHOLLIMA apply for and win real remote jobs, complete onboarding, and in several cases carry out the actual work expected of the role, all while funnelling their salary back to the North Korean regime, which is barred from earning foreign currency under international sanctions.

Forged documents, shared details

In one case flagged by an Australian partner organisation, three employees in the healthcare sector came under suspicion after Huntress traced their account activity to VPN and proxy infrastructure previously linked to DPRK IT worker campaigns, including Astrill VPN and a bulletproof hosting provider later raided by Dutch authorities.

A review of identity documents submitted by two of the workers, including passports and residency cards, uncovered a series of overlapping details that researchers say point to a common source: both passports were issued in the same city one day apart, both residency cards carried identical validity periods and were issued by the same police station, and metadata on the photos showed both were taken on the same model of iPhone within eight minutes of one another. Investigators also found that fabricated utility bills submitted by both individuals contained matching layout errors and unrelated links to a US utility provider’s website.

Hardware built for remote control

A separate case at a financial services firm centred on physical hardware rather than documents. After a Huntress agent was installed on a newly onboarded employee’s device, researchers discovered a PiKVM, an open-source, Raspberry Pi-based device that allows a computer to be remotely controlled at the hardware level, independent of any software running on the machine. Windows event logs showed the device had been connected roughly a week before Huntress was deployed, alongside a separate capture card that let the operator route external video into webcam-based applications such as Zoom.

Investigators reconstructed a timeline showing the laptop being moved between a mobile travel router and a residential network before settling on a fixed ethernet connection, consistent with what researchers describe as a “laptop farm” setup used to make a device appear to be operating from a legitimate home address. The employee later declined to show their surroundings on video calls or appear on camera, which the partner organisation cited as a factor in confirming its suspicions.

A borrowed identity

A third case, surfaced through proactive threat hunting rather than a partner tip-off, involved a worker in a sales and marketing role whose identity documents matched the personal details, including full name, date of birth and license location, of a real individual whose mugshot had previously been published online following an arrest. Researchers concluded the documents were genuine but had been digitally altered to replace the photo, with the signature also appearing to have been digitally overlaid rather than handwritten.

On the same device, researchers found browser artefacts pointing to peer-to-peer file-sharing tools, screen-casting software typically used to relay video into conferencing apps, and Chrome extensions for English translation and pronunciation support. The employee had also posted recurring Zoom meeting links, including passwords, to a public code-sharing website.

Detection remains a manual process

Huntress said the difficulty in catching these cases lies in the fact that, unlike hacked accounts, fraudulent workers are legitimately onboarded and often use company systems exactly as a genuine employee would. No single indicator reliably proves DPRK involvement on its own, researchers said, but a combination of signals, VPN and proxy use, irregular working hours relative to a claimed location, remote-access hardware, and inconsistencies in identity documentation, can help defenders build a stronger case.

The firm is urging organisations to strengthen identity verification during hiring, including notarising identity documents for new remote hires, and to monitor for known hardware and infrastructure indicators, including specific Windows event IDs associated with PiKVM and similar capture devices.

Huntress said it expects the scheme to continue evolving as North Korean operatives diversify into industries beyond IT, and encouraged organisations that suspect they may have unknowingly hired a fraudulent remote worker to engage incident response support.

ShareTweet
Previous Post

Why Provision 29 is raising the bar for board accountability

Next Post

AI Agents Used by 68% of Top-Performing Cybersecurity Teams

Recent News

Attackers exploit AhsayCBS backup flaws to deploy disguised crypto miners

Attackers exploit AhsayCBS backup flaws to deploy disguised crypto miners

October 9, 2026
WorkNest Launches WorkNest Secure to Expand Cybersecurity and Compliance Services

WorkNest Secure Achieves CREST STAR-FS Accreditation for Red Teaming

October 8, 2026
Global cyber attacks up 48% as ransomware and phishing climb, Check Point finds

Global cyber attacks up 48% as ransomware and phishing climb, Check Point finds

October 8, 2026
Filigran event

Filigran announces speakers for first THREAD event

October 8, 2026

Eskenzi PR banner ad

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol