One operator applied for 60 jobs in a single day. Another sat through a video interview reading out answers a chatbot was producing in real time, sometimes repeating them word for word. Both were North Korean IT workers, and Recorded Future's Insikt Group assesses that ten or more organizations are highly likely to have ended up employing people from this network.
Insikt Group calls the cluster PurpleDelta. Its operators are likely based in China, many with a nexus in Shenyang, and between late 2024 and early 2025 one cluster alone applied for jobs at more than 1,100 companies. The wages are not the whole point: earnings from this kind of work are funnelled through facilitators, shell companies and laundering fronts to finance North Korea's sanctioned weapons programmes.
Twenty-two people who do not exist
The researchers counted at least 22 fabricated personas across the clusters, claiming to live in the United States, Germany and Brazil, with many centred on Florida. Profile photos were AI-generated. Identity documents came from an illicit ID-generation service. Applications went out across at least eight job platforms including Indeed, Upwork, ZipRecruiter, SEEK and Remote OK, with detailed tracking spreadsheets so the operators did not trip over their own identities.
Around 41% of the companies applied to were in IT and software services, followed by staffing and consulting at about 26% and healthcare and biotechnology at about 10%. Roughly 80% were based in North America, although the operators cast applications into every region of the world.
The interview is where the AI does the work
Getting through a technical screen is the hard part of the scheme, and PurpleDelta industrialised it. Operators ran custom-configured ChatGPT assistants, screen recording software and AI transcription tools during interviews so that answers could be generated on the fly, then read aloud. Insikt Group notes they often repeated the chatbot's responses verbatim. Multi-account management browsers and separate Google Chrome profiles let one person run several personas side by side without the sessions bleeding into each other.
What happens after the offer letter
Once hired, operators recorded internal meetings at the companies that employed them and kept screen recording running during work sessions. When an employer queried the use of a personal laptop or a personal bank account, the answer was often a pre-written excuse drafted through Google Translate, blaming a temporary administrative review of a company account.
The supporting kit is mundane and effective: GO2bank, PayPal, Payoneer, Rapyd, Stripe and cryptocurrency for payments, eSIM Plus, Blacktel and Google Voice for phone numbers, Astrill VPN throughout, and AnyDesk, Google Chrome Remote Desktop, Jump Desktop and RealVNC to reach company-issued laptops that facilitators keep switched on somewhere else entirely. Insikt Group identified at least two such facilitators maintaining employer hardware on the operators' behalf, with coordination running over Telegram and Slack.
A password gave one of them away
The most human detail in the report is a password fragment. One operator used the string "skdmldjajsl", which looks like noise until you type it on a Korean keyboard layout, where it becomes a phrase meaning "my mother". Another used "cjsflak", which resolves the same way to the name of a mythical horse from East Asian folklore.
Treat a match as a live compromise
Insikt Group's advice to defenders is blunt: an organization that spots the indicators listed in its appendix should treat the situation as a potential active compromise rather than a hiring mistake, and review the employment history and access privileges of anyone matching. In practice that means checking whether a remote engineer's hardware is where it is supposed to be, whether payment details have been redirected to personal accounts, and who has been recording your meetings.
PurpleDelta overlaps with designations other vendors already track, including Jasper Sleet, UNC5267, Wagemole and Famous Chollima, and the AI layer described in the original report is the same trend we covered when Microsoft documented North Korean IT workers folding AI into the attack chain. The tooling keeps improving. The tell, this time, was a homesick password.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.