<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Dprk on CuraSec</title><link>https://curasec.metacog.co.kr/tags/dprk/</link><description>Recent content in Dprk on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 31 Aug 2026 18:00:29 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/dprk/index.xml" rel="self" type="application/rss+xml"/><item><title>DPRK IT Worker Fraud Expands Into Healthcare and Sales Roles</title><link>https://curasec.metacog.co.kr/insights/2026-08-31-north-korean-job-fraud-expands-beyond-it-into-healthcare-and/</link><pubDate>Mon, 31 Aug 2026 18:00:29 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-31-north-korean-job-fraud-expands-beyond-it-into-healthcare-and/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Expands the known DPRK IT-worker insider-threat profile into healthcare and sales; no IOCs or ATT&amp;amp;CK-mapped TTPs are provided, so there is no detection work to action today, but analysts should update their mental model of which hiring pipelines are targeted.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> The scheme now threatens non-IT hiring pipelines, including healthcare where regulatory exposure is high; review remote-hire verification procedures and brief HR leadership on enhanced identity-vetting requirements for fully-remote roles across all business units.&lt;/li>
&lt;/ul></description></item></channel></rss>