Full Report
Threat actors with ties to the Democratic People's Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent investigations identifying suspected workers employed in sales and marketing and the medical profession. The ongoing insider threat is part of what has been described as the IT worker scheme,
Analysis Summary
# Threat Actor: DPRK IT Workers
## Attribution & Identity
* **Identification:** Threat actors tied to the Democratic People's Republic of Korea (DPRK/North Korea).
* **Known Aliases:** Famous Chollima, Jasper Sleet, Nickel Tapestry, PurpleDelta (formerly TAG-121), UNC5267, Wagemole.
* **Associated Groups:** Insikt Group identifies a specific cluster linked to PurpleDelta, likely based in China.
## Activity Summary
The North Korean "IT worker scheme" involves skilled individuals fraudulently obtaining remote employment at global firms to generate illicit revenue for Pyongyang’s nuclear and ballistic missile programs. Recent investigations (2024–2026) show these actors are expanding their scope beyond traditional IT roles into **sales, marketing, and the medical profession**. In early 2026, cases were identified involving healthcare and financial services firms where workers used stolen identities and remote-access hardware to maintain their roles.
## Tactics, Techniques & Procedures
* **Identity Fraud:** Use of stolen or forged identity documents (passports, resident ID cards); substitution of faces on existing identities using AI or mugshot data.
* **Synthetic Personas:** Creation of fabricated identities, some synthetically generated using Artificial Intelligence (AI).
* **Evasion & Masking:** Use of VPNs and proxy services to hide true geographic locations.
* **Hardware-Based Remote Access:** Utilization of laptop farms and KVM (Keyboard, Video, Mouse) switches to allow remote control of corporate-issued devices from overseas.
* **Profile Forgery:** Downloading and modifying legitimate GitHub profiles or external data to create fake internal corporate avatars.
**MITRE ATT&CK IDs:**
* **T1136:** Create Account (Fraudulent hiring)
* **T1090:** Proxy (Use of VPNs/Proxies)
* **T1219:** Remote Access Software (PiKVM/TinyPilot)
* **T1566:** Phishing (Social engineering during recruitment)
## Targeting
* **Sectors:** Software and Technology, Staffing and Consulting, Healthcare and Biotechnology, Financial Services, Sales and Marketing.
* **Geography:** Global (specifically mentioned: Australia, United States, and Fortune 500 companies).
* **Victims:** Over 1,100 companies targeted; specifically mentioned an Australian healthcare company and an unnamed financial services firm.
## Tools & Infrastructure
* **Remote Access Hardware:** PiKVM, TinyPilot (KVM switches).
* **Peripherals:** Guermok USB capture cards (used to spoof webcam inputs for Zoom/meetings).
* **Network Masking:** Astrill VPN, IPRoyal Proxy.
* **File Sharing:** SendGB (used for transferring modified profile assets).
* **Infrastructure:** Laptop farms (domestic hubs used to host corporate devices).
* **Defanged Domains:** `guermok[.]com`
## Implications
This campaign represents a significant shift from external cyberattacks to internal insider threats. By performing legitimate work while masking their identity, these actors bypass traditional perimeter security. The primary strategic implication is the funding of sanctioned weapons programs; however, the presence of these actors within sensitive healthcare and financial networks also creates high risks for data exfiltration, intellectual property theft, and future supply chain compromise.
## Mitigations
* **Rigorous Background Checks:** Perform comprehensive verification of employment history and search for individual identities online.
* **Enhanced Interviewing:** Conduct video interviews and look for discrepancies between the applicant's appearance and provided documentation.
* **Document Verification:** Scrutinize electronic bills and IDs for "word anomalies" or inconsistencies in formatting.
* **Hardware Auditing:** Monitor for unauthorized hardware attachments, specifically KVM switches (PiKVM, TinyPilot) or unusual USB capture cards on corporate laptops.
* **Network Monitoring:** Flag connections originating from known commercial VPNs (e.g., Astrill) or proxy services (e.g., IPRoyal) during employee sessions.