started · updated
North Korea expands fraudulent job schemes into healthcare and sales
North Korean threat actors are expanding their fraudulent employment schemes beyond the information technology sector into fields such as healthcare, sales, and marketing. This ongoing campaign involves skilled workers using stolen or forged identity documents, VPNs, and proxy services to secure remote positions at private firms and Fortune 500 companies globally.
The income generated from these fraudulent roles is used to fund North Korea’s nuclear weapons and ballistic missile programs. Security researchers note that these actors present a unique challenge because they often perform the legitimate work they were hired to do, making them difficult to detect through traditional cybersecurity methods.
In one specific instance in February 2026, three employees at an Australian healthcare company were identified as North Korean workers impersonating Chinese nationals. The deception was uncovered after investigators noted the use of Astrill VPN and IPRoyal Proxy, suspicious similarities between passports, and anomalies in residency documentation.
Entities
Astrill VPN · Democratic People’s Republic of Korea · Huntress · IPRoyal Proxy