North Korean fake workers move into healthcare and sales

Two employees at the same company handed over Chinese identity cards during onboarding. Photographed from the same angle. Passports issued in Shenzhen one day apart, cards valid for exactly the same period, both stamped by Songgang Police Station, both people living on the same street. And in the photos of the back of each card, the same physical damage was visible on both, because it was the same card.

That is one of five cases Huntress researchers Jai Minton and James Maclachlan have worked so far in 2026 involving suspected North Korean remote workers, the operation tracked as Famous Chollima. These workers apply for real remote jobs on stolen or invented identities, get hired, often do the work, and route their salaries back to the North Korean regime in defiance of sanctions.

The jobs are no longer just engineering roles

The most useful finding is a hiring detail, not a technical one. The five individuals were spread across IT, sales and marketing, and the medical profession. Companies that have trained recruiters to scrutinise remote developer candidates and nobody else are watching one door in a building with several.

The healthcare case began in February 2026, when an Australian partner grew suspicious of three employees presenting as Chinese nationals. Six months of Microsoft 365 audit logs showed all three repeatedly authenticating through Astrill VPN nodes, IPRoyal Proxy, and infrastructure belonging to WorkTitans B.V., a bulletproof hosting operation that appears to have been raided by the Dutch Fiscal Information and Investigation Service. A VPN proves nothing on its own, so the team profiled when the accounts were busy. Fewer than half of each account's actions fell inside expected business hours, and activity peaked at exactly midnight UTC, nine in the morning in Pyongyang.

The documents were worse. Photo metadata on every file showed the same iPhone camera. The electricity bills submitted as proof of address came from a fake State Grid Corporation of China template, down to the words "clutter" and "hassle" rendered as "dlutter" and "hassic", and both carried links to Arizona Public Service, a utility in the American southwest.

A laptop that arrived, then stopped moving

An August case at a financial services firm produced the clearest hardware timeline yet. The company-built laptop shipped on 24 July and reached its destination on the 27th. On 31 July it connected to a travel router for several hours, odd for a machine that had supposedly already arrived, then joined a residential network named Pickle_Rick. Twenty minutes later a USB serial console adapter was plugged in, and two minutes after that a PiKVM V4 Mini.

A PiKVM is a Raspberry Pi based keyboard, video and mouse device that hands somebody full remote control of a computer at the hardware level, before Windows even boots and without installing anything on it. Fifteen minutes later the laptop moved to a wired connection and never touched Wi-Fi again, the behaviour of a machine that has become a fixed asset in a rack. Days later a Guermok USB capture card appeared, which registers as a webcam and lets any video you feed it become your face on a Zoom call.

That pairing gave Huntress something to hunt on. Searching for hosts with both devices attached surfaced a third company and a sales employee onboarded thirteen days earlier, moving identity documents through Toffeeshare. Their documents carried numbers that validated as genuine, because they belonged to a real person, one whose mugshot had been posted online by law enforcement. Same full name, same date of birth, same licence location, different face.

Look in the USB registry first

Huntress recommends alerting on Windows Security Event ID 6416 where the device description contains PiKVM or Guermok, and hunting the registry path HKLM\SYSTEM\CurrentControlSet\Enum\USB for FriendlyName values such as PiKVM Composite Device and Guermok USB3 Video. Alongside that: browser extensions for screen redirection, microphone testing and translation, including vdo[.]ninja and mictests[.]com; recurring meeting invitations on public text sharing sites; Astrill VPN or IPRoyal authentication paired with inconsistent working hours; and identity documents issued close to the hire date.

None of these is damning alone. Plenty of legitimate employees use a VPN, and a microphone test is not a crime. What made these cases was co-occurrence, which is why the threat keeps landing on HR and IT at once. As the same operation's use of AI to get through live interviews showed earlier this month, the interview is now the weakest control in the chain, and the strongest evidence tends to arrive weeks later, out of a USB port.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions