Recorded Future reported that a North Korean-linked operation it tracks as PurpleDelta used fabricated IT worker personas to apply for jobs at foreign companies at scale, overwhelming hiring teams and gaining employment inside targeted organizations. The campaign relied on AI-generated profile photos, custom ChatGPT assistants, illicit identity-document generation services, rented accounts accessed through AnyDesk, and coordination over Telegram and Slack to support fraudulent applications and remote work activity.
Researchers said the operation targeted software, technology, healthcare, and biotechnology firms and successfully infiltrated at least 10 organizations. Once inside, the fake workers allegedly collected intelligence and exfiltrated proprietary data, source code, and internal communications, turning the scheme into both an espionage and revenue-generating operation. Recorded Future said proceeds from the activity are often directed toward sanctioned North Korean military and nuclear programs, elevating the threat beyond hiring fraud.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
Recorded Future reported that groups of fake North Korean IT workers it tracks as PurpleDelta were running large-scale fraudulent employment operations using fabricated personas to obtain jobs at foreign companies. The research said the operation had infiltrated at least 10 organizations and was used for both revenue generation and intelligence collection, including exfiltration of proprietary data, source code, and internal communications.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
itpro.com
Open sourcebsky.app
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.