Recent intelligence reports highlight a persistent security threat involving North Korean IT workers, designated as PurpleDelta. These operators run sophisticated campaigns to secure remote technical roles at global organizations. Between 2024 and 2025, identified clusters submitted applications to over 1,100 companies, focusing heavily on software development, staffing, and healthcare sectors. The group shows high operational capacity, managing multiple fabricated personas simultaneously through advanced browser configurations and automated tracking spreadsheets.

The tradecraft used by PurpleDelta is precise. Operators use AI-generated profile photos, custom ChatGPT assistants, and real-time transcription tools during job interviews to bypass screening processes. They often record internal company meetings and use translation software to justify the use of personal devices or non-standard bank accounts. Some personas were confirmed as active employees at ten or more organizations, creating a significant insider risk.

Evidence confirms these operators often work from bases in China, supported by a network of facilitators who handle hardware and administrative tasks. The group frequently uses identity-brokering services and stolen credentials to construct credible work histories. By funneling earnings through shell companies and money laundering services, these activities help finance sanctioned military and nuclear programs for the North Korean regime.

Security teams should treat these activities as active compromises. Organizations should implement rigorous identity verification, including live video checks against government-issued documents. It is important to geolocate company hardware, restrict remote access tools, and monitor for unauthorized software installation. Reviewing employment histories and access privileges for individuals matching these indicators is necessary to mitigate long-term supply chain and insider threats.