Cybersecurity firm Huntress has confirmed five separate incidents this year in which suspected North Korean operatives were successfully hired into legitimate organisations under false identities, in a wave of activity researchers say shows how the country’s so-called “remote IT worker” scheme has expanded well beyond IT roles.
The cases, disclosed in a new advisory, involved workers placed in healthcare, financial services, and sales and marketing positions across partner organisations. Unlike traditional cyberattacks, the threat does not rely on breaching networks or stealing credentials. Instead, operatives linked to the group tracked as FAMOUS CHOLLIMA apply for and win real remote jobs, complete onboarding, and in several cases carry out the actual work expected of the role, all while funnelling their salary back to the North Korean regime, which is barred from earning foreign currency under international sanctions.
Forged documents, shared details
In one case flagged by an Australian partner organisation, three employees in the healthcare sector came under suspicion after Huntress traced their account activity to VPN and proxy infrastructure previously linked to DPRK IT worker campaigns, including Astrill VPN and a bulletproof hosting provider later raided by Dutch authorities.
A review of identity documents submitted by two of the workers, including passports and residency cards, uncovered a series of overlapping details that researchers say point to a common source: both passports were issued in the same city one day apart, both residency cards carried identical validity periods and were issued by the same police station, and metadata on the photos showed both were taken on the same model of iPhone within eight minutes of one another. Investigators also found that fabricated utility bills submitted by both individuals contained matching layout errors and unrelated links to a US utility provider’s website.
Hardware built for remote control
A separate case at a financial services firm centred on physical hardware rather than documents. After a Huntress agent was installed on a newly onboarded employee’s device, researchers discovered a PiKVM, an open-source, Raspberry Pi-based device that allows a computer to be remotely controlled at the hardware level, independent of any software running on the machine. Windows event logs showed the device had been connected roughly a week before Huntress was deployed, alongside a separate capture card that let the operator route external video into webcam-based applications such as Zoom.
Investigators reconstructed a timeline showing the laptop being moved between a mobile travel router and a residential network before settling on a fixed ethernet connection, consistent with what researchers describe as a “laptop farm” setup used to make a device appear to be operating from a legitimate home address. The employee later declined to show their surroundings on video calls or appear on camera, which the partner organisation cited as a factor in confirming its suspicions.
A borrowed identity
A third case, surfaced through proactive threat hunting rather than a partner tip-off, involved a worker in a sales and marketing role whose identity documents matched the personal details, including full name, date of birth and license location, of a real individual whose mugshot had previously been published online following an arrest. Researchers concluded the documents were genuine but had been digitally altered to replace the photo, with the signature also appearing to have been digitally overlaid rather than handwritten.
On the same device, researchers found browser artefacts pointing to peer-to-peer file-sharing tools, screen-casting software typically used to relay video into conferencing apps, and Chrome extensions for English translation and pronunciation support. The employee had also posted recurring Zoom meeting links, including passwords, to a public code-sharing website.
Detection remains a manual process
Huntress said the difficulty in catching these cases lies in the fact that, unlike hacked accounts, fraudulent workers are legitimately onboarded and often use company systems exactly as a genuine employee would. No single indicator reliably proves DPRK involvement on its own, researchers said, but a combination of signals, VPN and proxy use, irregular working hours relative to a claimed location, remote-access hardware, and inconsistencies in identity documentation, can help defenders build a stronger case.
The firm is urging organisations to strengthen identity verification during hiring, including notarising identity documents for new remote hires, and to monitor for known hardware and infrastructure indicators, including specific Windows event IDs associated with PiKVM and similar capture devices.
Huntress said it expects the scheme to continue evolving as North Korean operatives diversify into industries beyond IT, and encouraged organisations that suspect they may have unknowingly hired a fraudulent remote worker to engage incident response support.

