← Blog · · df00tech

North Korean IT Worker Scheme Expands Into Healthcare and Sales Roles

security-news campaign

Investigations reported by The Hacker News indicate that DPRK-linked threat actors are broadening their long-running fraudulent employment scheme beyond IT roles, with suspected operatives now identified working in sales and marketing as well as the medical profession.

What Was Reported

The activity is part of the established "IT worker scheme," in which North Korean operatives use false identities to obtain remote employment. Recent investigations found suspected workers in this scheme placed in non-IT roles, including sales/marketing and healthcare positions, suggesting the scheme is not confined to technical job functions as previously assumed.

Why It Matters

Organizations that have historically focused insider-threat and identity-verification scrutiny on IT hires — remote developers, sysadmins, and similar technical roles — may have blind spots for non-technical departments. Sales, marketing, and healthcare roles often involve access to sensitive data (customer records, PHI, financial systems) and may go through lighter background-check or technical-vetting processes than engineering hires, creating an expanded attack surface for this insider threat.

What Defenders Should Watch For

  • Extend remote-hire identity verification (document authenticity checks, video interview consistency, reference validation) to all remote roles, not just technical positions.
  • Watch for hiring/HR red flags associated with the broader IT worker scheme: reluctance to appear on camera, inconsistent geolocation of VPN/remote access versus claimed residence, use of laptop farms, and payment routed through unusual intermediaries.
  • Monitor for anomalous remote access patterns post-hire — logins from unexpected regions, use of remote-access/KVM-over-IP tools, or multiple accounts sharing device fingerprints.
  • Coordinate between HR, IT security, and legal to formalize an insider-threat review process for all new remote hires, regardless of department.

Developing Story

This is based on recent investigative reporting and represents an evolving picture of the IT worker scheme rather than a single confirmed incident with named victims. Details on specific companies, numbers affected, or additional TTPs may emerge as the reporting develops. For the original report, see The Hacker News.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.