National Cyber Warfare Foundation (NCWF)

PurpleDelta's Fraudulent Employment Operations


0 user ratings
2026-08-18 13:58:25
milo
Blue Team (CND)
Learn how North Korean IT worker threat cluster "PurpleDelta" uses AI-generated personas, sophisticated tradecraft, and custom ChatGPT assistants to infiltrate organizations. Discover key indicators of compromise and mitigation strategies to protect your company from these fraudulent employment operations.

Executive Summary


Insikt Group has identified several clusters of activity linked to PurpleDelta, Recorded Future's designation for North Korean IT workers, comprising multiple operators likely based in China. Between late 2024 and early 2025, one cluster applied to jobs at over 1,100 companies, primarily in the software and technology, staffing and consulting, and healthcare and biotechnology sectors. PurpleDelta operators maintained at least 22 fabricated personas across multiple clusters, some of which were supported by AI-generated profile photos, custom-configured ChatGPT assistants, and identity documents sourced from an illicit ID-generation service, and were highly likely to be actively employed by at least ten organizations.


PurpleDelta operators demonstrate a high operational tempo to this day. In some cases, the operators have applied to at least 60 positions per day across multiple job platforms, used multi-account management browsers and separate Google Chrome profiles to manage distinct personas simultaneously, and maintained detailed tracking spreadsheets to coordinate applications across identities. During job interviews, they used screen recording software alongside AI transcription and chatbot tools to generate real-time answers, often repeating ChatGPT responses verbatim. Once employed, operators recorded internal meetings at victim organizations and used Google Translate to draft pre-written excuses to justify using personal devices and bank accounts for work. Evidence from recorded sessions also indicates that PurpleDelta operators coordinated via Telegram and Slack, and at least two individuals were identified as facilitators who maintained company-issued hardware for the PurpleDelta operators.


Insikt Group assesses that this cluster of activity is consistent with the broader North Korean IT worker threat and presents material risk to organizations hiring for remote technical roles. Companies that have observed indicators listed in Appendix A should treat this as a potential active compromise and review the employment history and access privileges of matching individuals.


Key Findings



  • Insikt Group has identified at least 22 fabricated personas linked to multiple PurpleDelta clusters that submitted applications to over 1,100 companies across the software, staffing, healthcare, and financial sectors, with operators submitting as many as 60 or more applications per day across at least 8 job platforms.

  • These clusters of PurpleDelta operators are highly likely to have been actively employed at ten or more organizations, with confirmed or probable placements at companies that pose an ongoing and material insider threat.

  • PurpleDelta demonstrated a high degree of operational sophistication, using multi-account management browsers, multiple Chrome profiles, AI-generated profile photos, custom ChatGPT assistants, and real-time AI transcription tools to deceive hiring managers during interviews, sometimes repeating AI-generated responses verbatim.

  • Once employed, PurpleDelta operators recorded internal meetings at victim organizations, used screen recording software during work sessions, and drafted pre-written Google Translate excuses to justify the use of personal devices and personal bank accounts.

  • Video evidence indicates that PurpleDelta operators use identity-brokering services, account-renting via AnyDesk, and multi-accounting tools, and coordinate via Telegram and Slack, with support from facilitators who procure and maintain company-issued hardware on the operators' behalf.


Background


PurpleDelta is Recorded Future's designation for the cluster of activity associated with North Korean IT workers, a state-directed network of covert technology laborers operating across global freelancing platforms and corporate hiring pipelines. The group overlaps with threat actor designations used by other vendors, including Jasper Sleet, UNC5267, Wagemole, and Famous Chollima. PurpleDelta operators pose as independent contractors and job-seeking developers to secure remote employment at organizations worldwide, with earnings systematically funneled through layers of individual facilitators, shell companies, and money-laundering front companies, ultimately financing the North Korean regime's sanctioned military and nuclear programs.


PurpleDelta operators employ extensive persona management tradecraft to obscure their nationality and true affiliation. Each operator maintains multiple fabricated identities across platforms, including GitHub, LinkedIn, Medium, Upwork, and a range of smaller freelancing sites, with personas deliberately constructed to project credibility through aged accounts, curated technology stacks, and cross-platform social proof. These identities are reinforced through the use of AI tools, temporary phone number services, anti-detect browsers, and resume-building platforms. In addition to generating illicit revenue, Insikt Group has observed signs of overlap with several North Korean state-sponsored groups, including PurpleBravo, a related cluster of activity that deploys malware through fraudulent recruitment campaigns targeting software developers primarily in the cryptocurrency space, indicating the broader potential for intelligence collection, downstream compromise, and supply-chain risk.


Threat Analysis


As part of Recorded Future’s ongoing tracking of PurpleDelta, Insikt Group has documented multiple clusters of North Korean IT workers since 2025 that are likely based in China. Operators in one of these clusters applied to jobs at over 1,100 companies. Almost half of the companies (~41%) to which the operators applied were in the IT and software services space, followed by staffing and consulting (~26%), and healthcare and biotechnology (~10%). Roughly 80% of the companies are based in North America, but the operators applied to companies in every region of the world. Many of the operators have a nexus in Shenyang, China, as indicated by their professional profiles, social media presence, and artifacts observed on their systems.





A pie chart titled 'Industry Breakdown of Companies PurpleDelta Operators Applied To' shows the distribution of industries targeted by fraudulent operators: Software/SaaS accounts for 41%, Staffing/Consulting 26%, Healthcare/Biotech 10%, Fintech/Insurance 7%, AI/Data/Security 6%, Consumer/Media 4%, Industrial/Public Sector 3%, and Other 2%



Figure 1: Breakdown of industries of the companies applied to by PurpleDelta operators (Source: Recorded Future)




Source: RecordedFuture
Source Link: https://www.recordedfuture.com/research/purpledelta-fraudulent-employment-operations


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.