Huntress says suspected DPRK remote workers are moving beyond IT jobs and into healthcare and sales, with cases that also include marketing. The shift keeps the same playbook: stolen or forged identity documents, VPNs, proxies, and laptop-farm setups that let the worker look like a normal remote hire while working from elsewhere.
That makes the scheme hard to catch with malware-style monitoring, because the person may really be doing assigned work while hiding who and where they are. The new part is the access it buys: if those hires sit in medical, sales, or other data-touching roles, the exposure can reach patient and customer information, not just technical systems.
For organizations that hire remote staff, especially into roles with ordinary access to sensitive records, the problem now sits in onboarding trust and identity proofing rather than in the endpoint. The reporting still leaves each employer to decide how far those accounts reached before the fraud was found.