Research says a North Korea–linked operation (“PurpleDelta”) is using fake identities to apply for large volumes of remote IT jobs, sometimes successfully getting hired. Once inside a company, these “employees” can record meetings and steal sensitive information such as source code and internal communications, while wages may be routed to sanctioned North Korean programs.
Key findings
- Recorded Future tracked a North Korea–linked fraudulent employment operation (“PurpleDelta”) using at least 22 fabricated personas.
- Operators can submit very high volumes of applications (reported up to 60 per day), across recruitment sites and platforms like LinkedIn and Upwork.
- The operation uses AI-generated profile photos, illicitly sourced identity documents, and ChatGPT to answer interview questions in real time.
- Facilitators help maintain the scam by procuring and maintaining company-issued hardware and enabling remote access/account renting (including via AnyDesk).
- If hired, the fake worker can record internal meetings, use screen-recording tools, and justify suspicious behavior with prepared excuses (e.g., using personal devices/bank accounts).
- Researchers say the campaign has infiltrated at least 10 organizations and has been used to exfiltrate proprietary data, source code, and internal communications.
Who’s being targeted
- Commonly targeted roles: HR/Recruiting, Hiring managers, Engineering managers, IT support / Endpoint team, Security / Insider risk, Payroll/Finance (onboarding-related).
- Affected industries: Software and technology, Healthcare, Biotechnology.
- Attack channels: linkedin, website, slack, telegram.
- Impersonated: A legitimate job seeker (fabricated identity/persona), A legitimate remote IT candidate, An internal remote employee (new hire).
Awareness takeaways
- Treat hiring and onboarding as a security control: verify identity, location, and the physical whereabouts of issued hardware.
- Train interviewers to spot AI-assisted interviewing and require practical validation (skills tests, structured interviews, and identity checks).
- Flag and investigate requests to use personal devices or personal bank accounts for company work and payroll, these can be part of a fraud playbook.
- Plan for repetition: once a fake persona is caught, expect quick replacement and continued attempts.
Red flags to watch for
- AI-generated or inconsistent profile photos/identity details
- Interview answers sound read verbatim and don’t match true understanding
- High-volume/rapid applications that seem “too polished” and similar across candidates
- Unusually high application volume and repeated patterns across applications
- Identity documents appear synthetic or sourced from questionable services
- Overly consistent/templated wording and responses
- Requests/excuses to use personal devices or personal bank accounts
- Unexplained remote-control/access patterns tied to the employee’s account/hardware
- Location/hardware reality doesn’t match what the employee claims
Read the video transcript
Fake North Korean IT workers are getting hired as remote devs and quietly walking off with source code. Groups dubbed PurpleDelta created at least 22 fake personas, blasting out up to 60 job applications a day on LinkedIn and recruitment sites, using AI-generated photos, illicit ID documents, and ChatGPT to answer interview questions word for word. Once hired, these fake workers get company laptops via facilitators, connect in with tools like AnyDesk, quietly record meetings and screens, and use pre-written excuses to explain why they’re on personal devices or different bank accounts while pulling internal chats and proprietary code. If you interview or onboard remote tech talent, treat it like a security check: always verify the real person, their location, and where the company hardware actually sits before granting access, no exceptions.