‘The scale of PurpleDelta’s operation is easy to miss’: Fake North Korean IT workers are submitting so many job applications that companies can’t keep up
The PurpleDelta group is applying for thousands of jobs to steal proprietary data, source code, and internal communications
Fake North Korean IT workers are taking their job-hunt seriously, submitting as many as 60 job applications per day according to new research.
Groups of North Korean IT workers, dubbed PurpleDelta by Recorded Future, created at least 22 fabricated personas, with job applications being made across a range of recruitment websites and platforms such as LinkedIn and Upwork.
Notably, the group is using identity-brokering services, account-renting via AnyDesk, and multi-accounting tools.
Researchers found these fraudulent workers are often coordinating via Telegram and Slack, with support from facilitators who procure and maintain company-issued hardware on the operators' behalf.
“A successful job placement provides the PurpleDelta operation with a steady income and places a false employee within a company’s normal systems," said Alexander Leslie, senior advisor at Recorded Future.
"Wages are often funnelled toward sanctioned North Korean military and nuclear programs, and access may also expose information that was never meant to leave a company.”
Fake North Korean IT workers are turning to AI
The fake workers' applications typically include AI-generated profile photos, custom-configured ChatGPT assistants, and identity documents sourced from an illicit ID-generation service.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
In terms of targets, researchers noted they’ve been applying for jobs at software and technology companies, as well as healthcare and biotechnology firms. Some appear to have been successful, according to Recorded Future, infiltrating at least 10 organizations.
Once inside, the fraudulent workers recorded internal meetings, used screen recording software during work sessions, and drafted pre-written Google Translate excuses to justify the use of personal devices and personal bank accounts.
“The scale of PurpleDelta’s operation is easy to miss when a company sees only one application," said Leslie.
"During interviews, PurpleDelta operators copied transcribed questions into ChatGPT and read the answers back, sometimes word for word, and occasionally repeated incorrect answers. A candidate can sound prepared without fully understanding what they are saying, which makes ordinary interview cues less reliable."
Manipulating company hardware
In some cases, Recorded Future said fraudulent workers received a company laptop and kept it and connected it in the country where they claim to live - usually the US, Germany or Brazil.
In one instance, researchers spotted one operative managing at least four identities simultaneously.
“PurpleDelta can recover quickly when one identity is exposed and a persona can be replaced," said Leslie.
"The same application machinery can keep running under a new name, and organizations should expect these operatives to adjust their methods as hiring teams become more familiar with them. Continued verification gives companies a better chance of catching changes."
Researchers warned that these fraudulent workers have been highly successful so far, collecting high-value intelligence and exfiltrating proprietary data, source code, and internal communications in support of North Korean state objectives.
"Companies should verify an employee’s identity after hiring, checking this during onboarding, so they can confirm where a worker and the hardware actually are," Leslie said.
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
Fortinet eyes AI security gains with Virtue AI acquisitionNews The acquisition will add AI runtime protection and automated validation capabilities to Fortinet’s existing Security for AI portfolio
-
ITSM teams report mixed productivity gains with AINews IT service management teams might be saving time on some tasks, but work is piling up in other areas
-
Two US nationals sentenced for role in prolific fake worker laptop farmsNews The Americans were raising money for the North Korean regime by allowing fake IT workers to appear as legitimate US-based employees
-
North Korean hackers are duping freelance developers with fake interviews to steal cryptocurrency and deliver malware — Sophos warns the 'Nickel Alley' group is using LinkedIn, Upwork, and Fiverr to target victimsNews A fake interview process uses coding tests and repo downloads to deliver malware
-
Cloudflare warns state-backed hackers are ‘weaponizing legitimate enterprise ecosystems’ as ‘living off the land’ attacks surgeNews Chinese, North Korean, and Russian-backed threat groups now favor longer-term compromises over brute force attacks
-
Fake North Korean IT workers are rampant on LinkedIn – security experts warn operatives are stealing profiles to apply for jobs and infiltrate firmsNews The scammers' latest efforts mark a significant escalation in tactics, experts have warned
-
Amazon CSO Stephen Schmidt says the company has rejected more than 1,800 fake North Korean job applicants in 18 months – but one managed to slip through the netNews Analysis from Amazon highlights the growing scale of North Korean-backed "fake IT worker" campaigns