PurpleDelta is a North Korean state-directed fraudulent remote-employment operation conducted by covert IT workers. Also tracked as Famous Chollima, Jasper Sleet, Nickel Tapestry, UNC5267, Wagemole, and formerly TAG-121, it uses fabricated, stolen, borrowed, and AI-assisted identities to obtain remote jobs and contractor access at foreign organizations. Operators have been assessed as likely operating from China, including Shenyang, while posing as workers in other countries. PurpleDelta has targeted organizations worldwide, particularly North American software and technology, staffing and consulting, healthcare and biotechnology, financial-services, media, and nonprofit entities. Operators use large numbers of coordinated personas and recruitment-platform accounts to submit high volumes of job applications, pass interviews using real-time transcription and AI-generated responses, and retain simultaneous employment under multiple identities. They use forged identity material, synthetic profile imagery, VPN and proxy services, remote-access tools, account-renting arrangements, and facilitators who receive, configure, and maintain employer-issued devices in claimed employment locations. Once placed, PurpleDelta personnel can access internal corporate environments, record meetings, and collect proprietary information, source code, and internal communications. The operation generates revenue for the North Korean regime and supports its prohibited military and weapons programs, while creating an insider-threat and espionage risk for employers. PurpleDelta has operational and infrastructure overlaps with PurpleBravo, a separate North Korean cluster associated with the Contagious Interview malware campaign.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
30 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
60 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A DPRK-sponsored employment-fraud and insider-access operation in which operators use stolen, borrowed, forged, or synthetic identities to obtain remote jobs and generate revenue for North Korea. Operators seek roles beyond IT, including sales, marketing, healthcare, and financial services, while creating risks of internal-data access, sanctions violations, and potential asset theft. PurpleDelta operators reportedly maintained fabricated personas at scale and targeted more than 1,100 companies.
North Korean fraudulent IT-worker activity using fabricated personas to obtain employment, collect intelligence, and exfiltrate proprietary data, source code, and internal communications in support of DPRK state objectives.
Fraudulent employment operations using fake personas to obtain jobs at companies worldwide, maintain access to victim-issued devices, record internal meetings, and generate revenue for North Korea.
A North Korean fraudulent IT worker operation using fabricated personas to obtain remote jobs, generate revenue, infiltrate companies, and collect intelligence and exfiltrate proprietary data in support of North Korean state objectives.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.