Huntress identified five 2026 incidents in which suspected North Korean operatives linked to FAMOUS CHOLLIMA secured legitimate remote jobs at partner organizations using fraudulent identities. The workers targeted not only IT roles but also positions in healthcare, financial services, sales, and marketing, with their salaries allegedly contributing to revenue for the sanctioned DPRK regime.
Investigations uncovered forged or altered identity documents, VPN and proxy infrastructure associated with DPRK worker operations, PiKVM hardware for remote device control, webcam-video relay equipment, and behavior consistent with laptop farms. Huntress advised organizations to strengthen remote-hire identity checks and detect the campaign through combined document-forensics, infrastructure, hardware, and behavioral monitoring rather than any single indicator.

TTPs, infrastructure, and targeting history in one profile.
10 events from the most recent confirmed update back to the earliest known activity.
The Bluesky account lazarusholic shared Huntress research titled “Insights into Suspected DPRK Workers: Red Flags to Look Out For,” associating the activity with ITWorker, Famous Chollima, PiKVM, and Guermok labels.
Matthew Isaac Knoot and Erick Ntekereze Prince were each sentenced to 18 months in prison for operating laptop farms for North Korean remote IT workers. Their schemes affected nearly 70 U.S. companies and generated a combined $1.2 million in illicit revenue.
Huntress documented five confirmed 2026 cases in which DPRK-aligned workers tracked as FAMOUS CHOLLIMA obtained remote positions at Western companies using fake or stolen identities. The workers filled IT, healthcare, and sales-and-marketing roles, sometimes performed legitimate work, and reportedly remitted part of their earnings to North Korea.
Huntress proactively identified a sales-and-marketing worker using documents matching a real person's name, birth date, and license location, with the photograph and signature digitally altered. The worker's device also contained video-relay and English-language-assistance artifacts, and the worker posted recurring Zoom credentials publicly.
At a financial-services firm, Huntress found a PiKVM attached to a newly onboarded employee's device, along with a capture card capable of relaying external video into webcam applications. The device's connectivity and the employee's refusal to appear on camera were assessed as consistent with a laptop-farm arrangement.
An Australian partner organization identified three suspicious healthcare employees whose activity traced to VPN and proxy infrastructure previously associated with DPRK IT-worker campaigns. Document similarities and metadata tied two of the workers' purported identities together.
The U.S. Justice Department announced indictments of two North Korean nationals and three facilitators for fraudulent remote work conducted between 2018 and 2024. The defendants allegedly generated at least $866,255 from ten of at least 64 infiltrated U.S. companies.
Recorded Future reported that the DPRK-linked PurpleDelta IT-worker cluster created at least 22 fabricated personas that applied for jobs through platforms including LinkedIn and Upwork, at volumes of up to 60 applications per day. The operations reportedly collected intelligence and exfiltrated proprietary data, source code, and internal communications.
Dutch authorities raided a bulletproof-hosting provider used alongside Astrill VPN infrastructure connected to the suspicious healthcare workers. The source states the raid occurred after the infrastructure was identified but does not provide a date.
Mandiant reported that DPRK-linked IT workers tracked as UNC5267 used fraudulent and reused resumes, stolen-identity locations, laptop farms, IP-based KVMs, and multiple remote-administration tools to obtain and perform remote jobs. Mandiant also observed Astrill VPN-linked access likely originating from China or North Korea and issued HR and technical mitigation guidance.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
10 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcethehackernews.com
Open sourcehelpnetsecurity.com
Open sourceitpro.com
Open sourceitsecurityguru.org
Open sourcehuntress.com
Open sourcemicrosoft.com
Open sourcecloud.google.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.