Summary
- Recorded Future identified at least 22 fabricated personas used by the PurpleDelta North Korean IT-worker cluster.
- One cluster submitted applications to more than 1,100 companies and was highly likely employed by at least ten organisations.
- AI-generated identities, remote-access tools, facilitators, and recorded internal meetings turn recruitment fraud into an identity and insider-risk problem.
A North Korean IT-worker operation has used at least 22 fabricated identities to pursue jobs at more than 1,100 companies, according to new research showing how remote recruitment can become a route into corporate systems rather than simply a payroll fraud problem.
Recorded Future‘s Insikt Group links the activity to PurpleDelta, its designation for clusters associated with North Korean IT workers. Researchers assess that one cluster, likely operating from China, submitted more than 1,100 applications between late 2024 and early 2025, and that PurpleDelta personnel were highly likely to have secured active employment at at least ten organisations.
The applications were concentrated in software and technology, staffing and consulting, healthcare and biotechnology, fintech, AI, security, and other sectors. Roughly 80% of the organisations approached were in North America, but applications extended across every global region, while fabricated personas claimed locations including Germany.
The operation used an increasingly mature identity stack. Researchers observed AI-generated profile photographs, custom ChatGPT assistants configured around individual false personas, separate browser profiles, multi-account management tools, temporary communications services, identity-document providers, and extensive spreadsheets used to coordinate applications.
During interviews, operators used transcription tools to capture questions and feed them into AI assistants, sometimes repeating generated answers directly. Recorded Future also observed screen-recording software being used during job interviews and, more significantly, during internal meetings at organisations where operators had apparently secured work.
That changes the risk once a fraudulent hire crosses the onboarding boundary. An organisation is no longer dealing with an outsider trying to deceive a recruiter. It may have issued corporate hardware, created identity-provider accounts, granted repository access, enrolled the person in internal communications platforms, and authorised access to proprietary code or sensitive business information.
The findings build on an established North Korean strategy of securing remote technology employment to generate revenue while concealing workers’ real identities and locations. A previous remote-hiring campaign that reached a UK bank showed how the model had already moved beyond US technology companies.
PurpleDelta’s tradecraft suggests employment screening is now being tested as an identity-control system. A plausible CV, technically competent interview, functioning video call, matching online history, and successful background check may each be legitimate controls, but attackers able to build an entire synthetic professional identity can work across those checks rather than defeating any one of them.
Human facilitators further complicate the model. Recorded Future identified individuals who maintained company-issued hardware for operators, while remote-access software allowed workers elsewhere to use those devices. That can make technical telemetry appear consistent with an employee’s stated location even when the actual person controlling the machine is in another country.
The use of AI is similarly incremental rather than magical. Generated profile images make false identities cheaper to maintain. Custom assistants help operators preserve a backstory or respond during interviews. Live transcription reduces language barriers. None of these capabilities creates the operation by itself, but together they allow a small group to manage more simultaneous identities and applications.
For organisations operating under UK and European sanctions regimes, the exposure extends beyond unauthorised access. Payments to a worker who is secretly acting for North Korea can create sanctions and compliance questions alongside the security incident, particularly when money is routed through facilitators or intermediary companies.
Recorded Future assesses the wider activity is ongoing and likely to continue expanding. The finding therefore places recruitment, identity governance, endpoint logistics, privileged access, and sanctions screening inside the same control problem. Once a fabricated employee has been accepted as genuine, many subsequent security systems behave exactly as designed — trusting the identity the organisation itself created.




