
Huntress found five DPRK-linked workers hired in 2026 using fake identities, remote-access setups and proxy tools to infiltrate legitimate companies.
Companies keep accidentally hiring North Korea-linked individuals as remote workers, and Huntress just published the receipts. The security firm’s investigation documents five confirmed cases in 2026 alone where DPRK-aligned workers, tracked under the name FAMOUS CHOLLIMA, talked their way into legitimate jobs using fake or stolen identities, spanning IT roles, sales and marketing, and even healthcare positions.
The main challenge is that this isn’t a typical cyberattack. These workers get hired, complete the onboarding process and often perform the job they’re paid to do, while sending part of their earnings back to North Korea.
Huntress says the workers aren’t breaking into companies through technical vulnerabilities. Instead, they use fake identities and other tricks to get legitimate jobs, which makes them much harder to spot with traditional security tools.
“DPRK workers present a unique detection challenge for defenders: rather than compromising accounts or breaking in via gaps in the organisations’ environments, they’re tricking companies into remotely hiring them, and oftentimes actually doing the legitimate work they were hired to do.” reads Huntress’s report. “Furthermore, DPRK workers often use stolen identity documents, VPNs, and proxy services to mask their true identity and location, meaning other methods must be used to help verify if an employee is who they say they are.”
The first case, involving three suspected workers at an Australian healthcare partner, came together through document forensics rather than network telemetry. Two employees submitted identity documents, Chinese passports, resident ID cards, and electricity bills, that looked legitimate individually but shared an impossible number of coincidences: identical passport issue cities, dates of issue just one day apart, matching residential streets, and photo metadata showing the same iPhone model used eight minutes apart. Even the fake electricity bills shared the exact same typo, “hassle” rendered as “hassic,” a translation artifact from whatever template both documents were built from.
The second case reads like something out of a spy thriller, except the tradecraft is disturbingly mundane. A newly onboarded worker’s laptop connected to a GL.iNet travel router for hours despite apparently already having arrived at its destination, then landed on a residential WiFi network, then got hooked up to a PiKVM, a Raspberry Pi-based device that gives someone full remote control over a computer at the hardware level, before the OS even boots. Ten minutes after the PiKVM activated, the laptop switched to a permanent ethernet connection and never touched WiFi again, the telltale sign of a machine settling into what Huntress calls a laptop farm.
What gives this timeline away isn’t the PiKVM alone, it’s the almost comically ordinary activity that surrounds it. Within an hour of the device connecting, the worker was googling online audio tests and microphone test websites to make sure their setup actually worked, the exact kind of mundane troubleshooting anyone does with new hardware. A few days later they entered a personal Gmail address into a web form that happened to match a naming pattern Huntress had already tied to other DPRK operatives, and checked their own public IP address minutes before joining a Zoom call, presumably confirming their proxy setup was holding.
The third case, caught through proactive threat hunting rather than a partner tip, showed a slightly different playbook built around remote collaboration tools rather than hardware. This worker used Toffeeshare, an encrypted peer-to-peer file transfer service, to move identity documents that turned out to belong to a real person whose photo had been digitally swapped for the impostor’s face, likely to pass an I-9 employment verification check. They also posted recurring Zoom meeting links, complete with embedded passwords, on a public code-sharing site, and used VDO.Ninja, free streaming software, seemingly to broadcast their own screen for a remote operator watching elsewhere.
The identity theft angle here is worth sitting with for a moment. Huntress found that the stolen identity in this third case belonged to someone whose mugshot had previously circulated online following a real arrest, matching on full name, date of birth, and even the drivers license location, with only the face swapped out. That’s not a fabricated identity built from scratch; it’s a real, searchable person’s life quietly repurposed to get someone else hired at a company that had no way of knowing the documents didn’t belong to the face on the video call.
“The user accessed ip[.]me directly to determine their public-facing IP address just minutes before joining a Zoom meeting.” continues the report. “The employee also retrieved an image from a file-sharing site, potentially for use on an internal communications tool, which is highly suspicious and a red flag in itself”
Huntress recommends looking at several warning signs together rather than relying on one indicator. For example, monitor Windows logs for PiKVM and Guermok capture devices, especially when both appear on the same computer. Also watch for VPN or proxy services such as Astrill and IPRoyal combined with unusual working hours. Recently issued identity documents can also deserve extra checks.
None of these signs proves malicious activity on its own, since VPNs and proxies can have legitimate uses. But when several indicators appear together, for example, a new employee connects a KVM device, tests the microphone, works mainly around midnight UTC and provides an identity document issued at the same time as a coworker’s, the combination should trigger a proper background check before the person gets access to production systems.
“Since fraudulent workers are legitimately onboarded employees, identifying them post-hire involves manual effort and multiple points of evidence that, while individually are not indicative of malice, combined together present a much stronger picture of DPRK worker activity.” concludes the report. “Mitigating the risk of fraudulent workers begins at the interview stage and continues with performing rigorous background checks of new hires prior to onboarding. When in doubt, performing standard background checks, searching the individuals online, and verifying any employment history will help to weed out DPRK workers early in the interview process.”
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, North Korea-linked IT Workers)



