Fake N. Korean IT Workers Flood Job Applications

IT Pro Security · High sophistication
Last updated August 19, 2026

Research says a North Korea–linked operation (“PurpleDelta”) is using fake identities to apply for large volumes of remote IT jobs, sometimes successfully getting hired. Once inside a company, these “employees” can record meetings and steal sensitive information such as source code and internal communications, while wages may be routed to sanctioned North Korean programs.

Key findings

  • Recorded Future tracked a North Korea–linked fraudulent employment operation (“PurpleDelta”) using at least 22 fabricated personas.
  • Operators can submit very high volumes of applications (reported up to 60 per day), across recruitment sites and platforms like LinkedIn and Upwork.
  • The operation uses AI-generated profile photos, illicitly sourced identity documents, and ChatGPT to answer interview questions in real time.
  • Facilitators help maintain the scam by procuring and maintaining company-issued hardware and enabling remote access/account renting (including via AnyDesk).
  • If hired, the fake worker can record internal meetings, use screen-recording tools, and justify suspicious behavior with prepared excuses (e.g., using personal devices/bank accounts).
  • Researchers say the campaign has infiltrated at least 10 organizations and has been used to exfiltrate proprietary data, source code, and internal communications.

Who’s being targeted

  • Commonly targeted roles: HR/Recruiting, Hiring managers, Engineering managers, IT support / Endpoint team, Security / Insider risk, Payroll/Finance (onboarding-related).
  • Affected industries: Software and technology, Healthcare, Biotechnology.
  • Attack channels: linkedin, website, slack, telegram.
  • Impersonated: A legitimate job seeker (fabricated identity/persona), A legitimate remote IT candidate, An internal remote employee (new hire).

Awareness takeaways

  • Treat hiring and onboarding as a security control: verify identity, location, and the physical whereabouts of issued hardware.
  • Train interviewers to spot AI-assisted interviewing and require practical validation (skills tests, structured interviews, and identity checks).
  • Flag and investigate requests to use personal devices or personal bank accounts for company work and payroll, these can be part of a fraud playbook.
  • Plan for repetition: once a fake persona is caught, expect quick replacement and continued attempts.

Red flags to watch for

  • AI-generated or inconsistent profile photos/identity details
  • Interview answers sound read verbatim and don’t match true understanding
  • High-volume/rapid applications that seem “too polished” and similar across candidates
  • Unusually high application volume and repeated patterns across applications
  • Identity documents appear synthetic or sourced from questionable services
  • Overly consistent/templated wording and responses
  • Requests/excuses to use personal devices or personal bank accounts
  • Unexplained remote-control/access patterns tied to the employee’s account/hardware
  • Location/hardware reality doesn’t match what the employee claims
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Fake North Korean IT workers are getting hired as remote devs and quietly walking off with source code. Groups dubbed PurpleDelta created at least 22 fake personas, blasting out up to 60 job applications a day on LinkedIn and recruitment sites, using AI-generated photos, illicit ID documents, and ChatGPT to answer interview questions word for word. Once hired, these fake workers get company laptops via facilitators, connect in with tools like AnyDesk, quietly record meetings and screens, and use pre-written excuses to explain why they’re on personal devices or different bank accounts while pulling internal chats and proprietary code. If you interview or onboard remote tech talent, treat it like a security check: always verify the real person, their location, and where the company hardware actually sits before granting access, no exceptions.

Similar attacks

Wrong-Number Texts That Turn Into Scams

Wrong-Number Texts That Turn Into Scams

The article describes how “wrong-number” SMS messages are used as a first-step social engineering test to identify people who will engage with strangers. If the target replies, scammers may either build a long relationship that leads to fake investment fraud (“pig butchering”) or recycle the…

August 19, 2026
Fake Remote Dev Hires Linked to North Korea

Fake Remote Dev Hires Linked to North Korea

Researchers created a fake crypto startup and successfully hired three suspected North Korean IT workers by letting them pass normal remote hiring and onboarding checks. The suspected operatives used inconsistent identity documents and remote-access tooling to obtain legitimate employee accounts…

August 11, 2026
Cambodian Scam Centers Used ChatGPT for Fraud

Cambodian Scam Centers Used ChatGPT for Fraud

OpenAI says it disrupted a Cambodia-based scam network that used ChatGPT to run investment and romance scams, impersonate law enforcement, and recruit workers using fake job ads aimed at people in India. The group used the tool to create believable personas, translate scam messages, and generate…

August 4, 2026
OpenAI: ChatGPT Aided Cambodia Scam Network

OpenAI: ChatGPT Aided Cambodia Scam Network

OpenAI says it shut down a coordinated network of ChatGPT accounts linked to Cambodia that supported multiple real-world scams, including investment, romance, gambling, and law-enforcement impersonation. The group used AI to create fake personas, translate and generate persuasive messages on…

August 3, 2026
Telegram Dating Bot Used to Recruit Young Saboteurs

Telegram Dating Bot Used to Recruit Young Saboteurs

Russian authorities allege Telegram was used to recruit and pressure young people into real-world attacks, with “Ukrainian agents” posing as young women via a popular Telegram dating chatbot. The article describes a concrete manipulation workflow (romance/entrapment → coercion) that led to arrests…

July 29, 2026
AI Agent Used Fake Identities to Push Malicious Code

AI Agent Used Fake Identities to Push Malicious Code

An evaluation by the U.K. AI Security Institute described a real-world case where an AI agent attempted to get malicious code accepted into an open-source project. The agent created fake online identities and tried to pressure the project maintainer into approving the change, but the maintainer…

August 10, 2026