As cited
Copy frozen at (site build).
threat intel
PurpleDelta's Fraudulent Employment Operations
Insikt Group identified PurpleDelta, a North Korean IT worker network likely operating from China, conducting large-scale fraudulent employment operations targeting over 1,100 companies between late 2024 and early 2025. The operators maintained at least 22 fabricated personas using AI-generated photos, synthetic identities, and sophisticated tooling to secure remote positions, with confirmed placement at ten or more organizations and ongoing active employment. Once hired, they recorded internal meetings, used screen capture software, and coordinated via Telegram and Slack with facilitators who procured hardware on their behalf.
Why it matters: Organizations hiring for remote technical roles face material insider threat risk from confirmed or probable PurpleDelta placements; practitioners should review employment history and access privileges of matches to indicators and treat findings as potential active compromise.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
PurpleDelta's Fraudulent Employment Operations
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
PurpleDelta's Fraudulent Employment Operations
Recorded Future's Insikt Group identified multiple clusters of North Korean IT workers designated PurpleDelta, likely based in China, who conducted fraudulent employment operations between late 2024 and early 2025. The operators maintained at least 22 fabricated personas using artificial intelligence (AI)-generated photos, custom ChatGPT assistants, and illicit identity documents to apply for over 1,100 positions across software, staffing, healthcare, and financial sectors, submitting as many as 60 applications per day. Once employed at ten or more organizations, they recorded internal meetings, used screen recording software, and coordinated via Telegram and Slack with facilitators who maintained company-issued hardware on their behalf.
Why it matters: Hiring managers and security teams at software, healthcare, staffing, and financial companies need to review recent remote hires against the indicators in the report, as PurpleDelta operators pose an active insider threat with potential access to sensitive systems and data.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
PurpleDelta's Fraudulent Employment Operations
Recorded Future's Insikt Group identified multiple clusters of North Korean IT workers designated PurpleDelta, likely based in China, who conducted fraudulent employment operations between late 2024 and early 2025. The operators maintained at least 22 fabricated personas using artificial intelligence (AI)-generated photos, custom ChatGPT assistants, and illicit identity documents to apply for over 1,100 positions across software, staffing, healthcare, and financial sectors, submitting as many as 60 applications per day. Once employed at ten or more organizations, they recorded internal meetings, used screen recording software, and coordinated via Telegram and Slack with facilitators who maintained company-issued hardware on their behalf.
Why it matters: Hiring managers and security teams at software, healthcare, staffing, and financial companies need to review recent remote hires against the indicators in the report, as PurpleDelta operators pose an active insider threat with potential access to sensitive systems and data.
- Source published
- First seen by Cybersecurity Tracker