Security1 distinct publisher3 min readPublished
The tells in three Huntress cases were login timestamps, duplicate passport scans and a KVM box on a fresh laptop, which puts the people most likely to catch a North Korean hire in HR and IT onboarding rather than in the SOC.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
The healthcare case was closed with records the employer already held. Huntress pulled six months of login history for three accounts and got the VPN and proxy endpoints they kept returning to, Astrill VPN and IPRoyal Proxy [4]. The same records showed less than half of the activity falling inside normal business hours, with the busiest stretch matching 9 a.m. in North Korea [5].
The documents came from the workers themselves. Two of the three uploaded a resident ID card, a passport and an electricity bill [6]. The passports were issued in the same city one day apart, and the ID cards carried identical validity dates and the same issuing police station [7]. The photos were taken at similar angles on the same phone model, minutes apart [8]. Huntress assessed that both people had probably photographed the rear of the same physical ID card, because the same visible damage shows up in both images [9]. The electricity bills shared typos and appeared to derive from a template available online, though Huntress allows the errors could come from optical character recognition [10].
None of that is a conviction, and the firm says so. Huntress notes the documents may still hold legitimate details or photographs taken from people whose identity data was stolen or borrowed [11]. In the sales and marketing case, the identification numbers passed validation checks, which is why Huntress reads the documents as belonging to a real person and digitally altered [20]. The mismatch only surfaced when investigators found a police mugshot of someone whose name, date of birth and location matched the paperwork and whose face did not match the submitted photo [19]. The check that fails here is comparison across records, not any single field.
The financial services case is the one where hardware carried the load. A PiKVM, a Raspberry Pi based KVM-over-IP box that lets a remote operator drive the machine, appeared on a new hire's laptop within hours of the laptop reaching a residential address [12]. Windows logs traced the device from the managed service provider's network to a travel router, then to home Wi-Fi named "Pickle_Rick", then to fixed Ethernet, a sequence Huntress reads as consistent with a laptop farm [13]. A Guermok USB capture card on the same laptop registered as a webcam and let arbitrary video be fed into Zoom as camera input [14]. Huntress is explicit that the capture card alone means nothing, and that its weight comes from co-occurring with a PiKVM in this incident and in others [15]. The worker also pulled an altered photo from someone else's GitHub profile, apparently for an internal chat tool [16].
Across the three engagements that is at least five suspected workers at three organizations [1], and the roles Huntress names are medical and sales and marketing [1]. The firm's own framing explains why the security stack stays quiet: these people are hired rather than intruding, and they often do the job [2]. Verification has to come from somewhere other than the environment, because the identity is masked by stolen documents, VPNs and proxies [3].
The most direct check on the record is the one the financial services firm tried. It asked the employee to show the room he was working in. He refused, was reluctant to go on camera, and the investigation ended with his identity recorded as questionable [17].
Ranked by verification strength, evidence, and original report placement.
Huntress says DPRK remote workers are expanding their job searches beyond IT, and recent investigations identified suspected DPRK workers employed in sales and marketing and in the medical profession.
Two of the three healthcare workers had uploaded a resident ID card, a passport and an electricity bill to prove their identity.
The two passports were issued in the same city one day apart, and the resident ID cards carried identical validity dates and the same issuing police station.
The identity document photos were shot at similar angles using the same phone model, minutes from each other.
Huntress said it appears likely both individuals accidentally used a photo of the same resident identity card rear, based on visible damage consistent across both photos.
The electricity bills contained the same typos and appeared to be based on a template available online; Huntress noted the errors could have resulted from a translation issue if optical character recognition was used to turn an image into an editable template.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 28, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
product
Half the incident clock goes to search, and telemetry tools cannot read the answer1 distinct publisher
build
AI-written code fails the same four ways, and every gate you own reports green1 distinct publisher
build
Grok 4.6 lands in Copilot two days after launch, and the model picker becomes a procurement problem1 distinct publisher
build
244 kB, 500 a minute, 5 percent: three ceilings that fail for the same reason1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Concrete artifacts, single custody
The specifics are unusually hard-edged: six months of login records, two passports issued in one city a day apart, a shared photograph of one damaged ID card rear, Windows network-profile changes on a laptop delivered hours earlier. Huntress also marks its own limits, conceding the capture card means nothing alone and that forged documents may carry a real victim's data. What is absent is anyone outside Huntress — no affected organization named or quoted, no case dates, and no reporting of Help Net Security's own layered onto the vendor's account.
Three organizations, no denominator
Three investigations, three sectors, at least five suspected workers — and Huntress says the PiKVM-and-capture-card pairing recurred 'across others' without counting those cases. So the pattern is instantiated but its prevalence is not: nothing indicates how many hires were screened to surface these five, or over what period, which is exactly the number a defender would want before rebuilding onboarding around it.
Hedged tighter than the headline
The restraint runs the other way here. 'Suspected' survives into the headline, one identity stays 'questionable' rather than being pinned to Pyongyang, and the laptop farm is something the network sequence merely could indicate. If anything the practical point is underplayed: the checks that caught these people — comparing two candidates' scans side by side, plotting login hours, noticing a KVM box on a week-old laptop — are cheap, and the piece treats them as incidental detail rather than the finding.
Vendor research, reproduced intact
Every fact originates with a commercial security vendor writing up its own casework, and the piece lands on that vendor's recommendation — rigorous pre-onboarding background checks — which sits close to what it sells. The forensic specificity is not the kind of thing you invent, but no participant in this story has an interest in the awkward counter-case, and it duly goes unmentioned: legitimate remote employees who route through a VPN and work someone else's hours look identical on the first pass.
Solid on artifacts, thin on scale
We are comfortable that the described forensics happened as reported and far less comfortable extrapolating from them. One outlet, one vendor, unnamed employers, undated incidents, and an attribution the source itself keeps at 'suspected'. The durable value of this reporting is a set of onboarding checks; as a measure of how widespread North Korean placement into sales, marketing and clinical roles has become, five cases carry very little weight.