PurpleDelta is a North Korea-linked threat activity cluster associated with fraudulent remote IT-worker operations that use stolen, borrowed, and synthetic identities to obtain employment or contractor access at foreign companies. The activity is tied to the Democratic People’s Republic of Korea’s broader revenue-generation and intelligence-collection apparatus and is also referred to as Wagemole. Operators have been observed building convincing professional personas across employment and social platforms, abusing identity documents and personal data, and using deepfake injection techniques to pass remote hiring and verification processes. PurpleDelta’s core tradecraft centers on unauthorized employment under false identities, but the activity also creates significant insider and supply-chain risk. Once embedded, operators can gain access to corporate systems, sensitive technical information, and financial assets, and may expose employers and downstream customers to compromise. Reported cases include infiltration of U.S. companies, including high-value technology and defense-related environments, as well as theft of confidential technical data and virtual currency. The operation is assessed to serve both financial and espionage objectives, though illicit revenue generation for the North Korean regime is a prominent feature. PurpleDelta has documented operational overlap with the North Korean cluster tracked as PurpleBravo, including shared infrastructure, shared devices, and common use of Astrill VPN-linked administration patterns. Investigators have observed intersections between fraudulent freelance-job activity and malware operations, indicating that North Korean IT-worker schemes and more traditional intrusion activity can be mutually reinforcing. This overlap increases the risk that seemingly routine hiring workflows, contractor onboarding, and developer assessments can become vectors for broader compromise.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a related North Korea–linked operational cluster whose infrastructure/operations are tied to the Astrill VPN-linked C2 used in the described campaign.
North Korea-linked fraudulent IT worker operation used for revenue generation and access, assessed in the content as operationally overlapping with PurpleBravo via shared infrastructure and devices, including automation of job applications while managing malware C2.
Referenced as a related North Korea-linked activity cluster (North Korean IT worker operations) with observed overlap with PurpleBravo.
Referenced as connected to North Korea’s remote IT worker scheme; mentioned in relation to Contagious Interview/PurpleBravo activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.