[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fvuobwaEXYSCk4JVVN1hOouNp20qI2QqZ1zYkSGTCwD0":3},{"article":4,"iocs":46},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":11,"published_at":13,"ingested_at":14,"relevance_score":15,"entities":16,"category_id":26,"category":27,"article_tags":30},"16e7c74f-bbb0-4067-966d-3d67c7631f70","Huntress Uncovers Five Cases of North Korean Operatives Posing as Remote IT, Sales and Healthcare Workers","huntress-uncovers-five-cases-of-north-korean-operatives-posing-as-remote-it-sale-6e0f65","Cybersecurity firm Huntress has confirmed five separate incidents this year in which suspected North Korean operatives were successfully hired into legitimate organisations under false identities, in a wave of activity researchers say shows how the country’s so-called “remote IT worker” scheme has expanded well beyond IT roles. The cases, disclosed in a new advisory, involved […] The post Huntress Uncovers Five Cases of North Korean Operatives Posing as Remote IT, Sales and Healthcare Workers appeared first on IT Security Guru.","Cybersecurity firm Huntress disclosed five confirmed incidents in which suspected North Korean operatives successfully infiltrated legitimate organizations using false identities and posing as remote workers. The cases reveal expansion of North Korea's remote worker scheme beyond IT roles into sales and healthcare positions. The campaign demonstrates sophisticated social engineering and identity fraud tactics used by state-sponsored actors to gain access to corporate networks.","Huntress reports five North Korean operatives hired as remote IT, sales, and healthcare workers in 2024.",null,"https:\u002F\u002Fwww.itsecurityguru.org\u002F2026\u002F08\u002F26\u002Fhuntress-uncovers-five-cases-of-north-korean-operatives-posing-as-remote-it-sales-and-healthcare-workers\u002F?utm_source=rss&utm_medium=rss&utm_campaign=huntress-uncovers-five-cases-of-north-korean-operatives-posing-as-remote-it-sales-and-healthcare-workers","2026-08-26T13:35:45+00:00","2026-08-26T14:00:22.620486+00:00",8,[17,20,23],{"name":18,"type":19},"Huntress","vendor",{"name":21,"type":22},"North Korea","threat_actor",{"name":24,"type":25},"North Korean Remote IT Worker Scheme","campaign","6cbdd207-aaa1-4176-9534-e156b125e917",{"id":26,"icon":11,"name":28,"slug":29},"Nation-state","nation-state",[31,36,41],{"category":32},{"id":33,"icon":11,"name":34,"slug":35},"2c8f44d4-b56e-47cf-9677-04f22c9ee78d","Identity & Access","identity-access",{"category":37},{"id":38,"icon":11,"name":39,"slug":40},"c5eccf7c-abbc-4bd3-bbed-e6da5cba8e73","Incident Response","incident-response",{"category":42},{"id":43,"icon":11,"name":44,"slug":45},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[]]