CYBERSECURITYTRACKER
TRACKING
Permanent story citation

PurpleDelta's Fraudulent Employment Operations

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4613

As cited

Copy frozen at (site build).

threat intel

PurpleDelta's Fraudulent Employment Operations

Insikt Group identified PurpleDelta, a North Korean IT worker network likely operating from China, conducting large-scale fraudulent employment operations targeting over 1,100 companies between late 2024 and early 2025. The operators maintained at least 22 fabricated personas using AI-generated photos, synthetic identities, and sophisticated tooling to secure remote positions, with confirmed placement at ten or more organizations and ongoing active employment. Once hired, they recorded internal meetings, used screen capture software, and coordinated via Telegram and Slack with facilitators who procured hardware on their behalf.

Why it matters: Organizations hiring for remote technical roles face material insider threat risk from confirmed or probable PurpleDelta placements; practitioners should review employment history and access privileges of matches to indicators and treat findings as potential active compromise.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

PurpleDelta's Fraudulent Employment Operations

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

PurpleDelta's Fraudulent Employment Operations

Recorded Future's Insikt Group identified multiple clusters of North Korean IT workers designated PurpleDelta, likely based in China, who conducted fraudulent employment operations between late 2024 and early 2025. The operators maintained at least 22 fabricated personas using artificial intelligence (AI)-generated photos, custom ChatGPT assistants, and illicit identity documents to apply for over 1,100 positions across software, staffing, healthcare, and financial sectors, submitting as many as 60 applications per day. Once employed at ten or more organizations, they recorded internal meetings, used screen recording software, and coordinated via Telegram and Slack with facilitators who maintained company-issued hardware on their behalf.

Why it matters: Hiring managers and security teams at software, healthcare, staffing, and financial companies need to review recent remote hires against the indicators in the report, as PurpleDelta operators pose an active insider threat with potential access to sensitive systems and data.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

PurpleDelta's Fraudulent Employment Operations

Recorded Future's Insikt Group identified multiple clusters of North Korean IT workers designated PurpleDelta, likely based in China, who conducted fraudulent employment operations between late 2024 and early 2025. The operators maintained at least 22 fabricated personas using artificial intelligence (AI)-generated photos, custom ChatGPT assistants, and illicit identity documents to apply for over 1,100 positions across software, staffing, healthcare, and financial sectors, submitting as many as 60 applications per day. Once employed at ten or more organizations, they recorded internal meetings, used screen recording software, and coordinated via Telegram and Slack with facilitators who maintained company-issued hardware on their behalf.

Why it matters: Hiring managers and security teams at software, healthcare, staffing, and financial companies need to review recent remote hires against the indicators in the report, as PurpleDelta operators pose an active insider threat with potential access to sensitive systems and data.

VendorsGoogleGitHubSlack
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary