PurpleDelta is a North Korean state-directed fraudulent-employment operation involving covert IT workers who use fabricated, stolen, borrowed, and synthetic identities to obtain remote employment and freelance roles at organizations worldwide. It is also tracked as Wagemole, Famous Chollima, Jasper Sleet, Nickel Tapestry, UNC5267, and formerly TAG-121. Operators are assessed to be associated with North Korea, with multiple observed operators likely working from China, including Shenyang. The operation obtains income for the North Korean regime and creates insider-access opportunities that can support intelligence collection and theft of proprietary data, source code, and internal communications. PurpleDelta workers have targeted technical and other remote roles, including software and IT services, staffing and consulting, healthcare and biotechnology, financial services, media, nonprofit organizations, sales, and marketing. The group has applied at scale through employment and freelance platforms, maintained numerous false personas, and secured employment at multiple victim organizations. PurpleDelta uses forged or illicitly sourced identity documents, AI-generated profile imagery, synthetic or manipulated identities, and AI-assisted interview techniques. Operators have used real-time transcription, screen recording, chatbot-generated answers, translation tools, multi-account browsers, separate browser profiles, and application-tracking systems to manage parallel personas and pass hiring processes. They conceal their true locations through VPNs, proxies, remote-access software, laptop farms, remote KVM devices, third-party account rentals, and facilitators who receive and maintain employer-issued hardware in the claimed country of employment. After placement, workers have recorded internal meetings and maintained simultaneous roles under multiple identities. Foreign intermediaries and facilitators have also been recruited to lend identities, financial accounts, freelance-platform accounts, devices, and interview participation. PurpleDelta has operational and infrastructure overlaps with PurpleBravo, the North Korean Contagious Interview activity cluster. PurpleBravo uses fraudulent recruiter personas and malicious coding assessments to compromise software developers, while PurpleDelta primarily conducts employment fraud; the overlap indicates a broader North Korean apparatus combining illicit remote work, revenue generation, access acquisition, and espionage risk.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
31 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
60 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A North Korean IT-worker cluster associated with fraudulent employment under false identities to generate revenue. It is operationally intertwined with WaterPlum, including shared laptop-farm infrastructure and applications for positions at Japanese cryptocurrency exchanges.
A DPRK-sponsored employment-fraud and insider-access operation in which operators use stolen, borrowed, forged, or synthetic identities to obtain remote jobs and generate revenue for North Korea. Operators seek roles beyond IT, including sales, marketing, healthcare, and financial services, while creating risks of internal-data access, sanctions violations, and potential asset theft. PurpleDelta operators reportedly maintained fabricated personas at scale and targeted more than 1,100 companies.
North Korean fraudulent IT-worker activity using fabricated personas to obtain employment, collect intelligence, and exfiltrate proprietary data, source code, and internal communications in support of DPRK state objectives.
Fraudulent employment operations using fake personas to obtain jobs at companies worldwide, maintain access to victim-issued devices, record internal meetings, and generate revenue for North Korea.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.