Updated
Updated · Recorded Future · Aug 18
PurpleDelta Targeted 1,100 Companies With 22 AI-Backed Fake Personas
Updated
Updated · Recorded Future · Aug 18

PurpleDelta Targeted 1,100 Companies With 22 AI-Backed Fake Personas

1 articles · Updated · Recorded Future · Aug 18

Summary

  • Insikt Group said the North Korea-linked operation likely placed workers at 10 or more organizations after one cluster applied to jobs at more than 1,100 companies between late 2024 and early 2025.
  • At least 22 fabricated personas were used across eight or more job platforms, with operators submitting up to 60 applications a day and using AI-generated photos, custom ChatGPT assistants and illicit ID services.
  • During interviews, operators recorded calls, transcribed questions in real time and sometimes repeated ChatGPT answers verbatim; once hired, they recorded internal meetings and sought to keep using personal devices and bank accounts.
  • Evidence tied many operators to China, especially Shenyang, and showed coordination through Telegram and Slack with facilitators who maintained company-issued laptops and helped bypass platform controls.
  • Recorded Future warned the campaign presents an active insider-threat and possible compromise risk for remote technical hiring, with proceeds assessed to support North Korea's military and nuclear programs.

Insights

How many global corporations unknowingly funded a sanctioned nation by hiring AI-assisted operatives hidden behind stolen identities?
When deepfakes and chatbots defeat standard background checks, what radical new methods must organizations adopt to verify remote employees?
Could the proprietary data secretly recorded by these state-sponsored IT workers already be fueling the next generation of global cyberattacks?

$600 Million in Synthetic Salaries: North Korea’s AI-Driven Remote Work Infiltration and the Corporate Deepfake Crisis

Overview

The rise of remote and hybrid work has enabled North Korean operatives to exploit online hiring and identity verification, infiltrating hundreds of Western organizations by stealing over 100,000 identities. Using generative AI and deepfake tools, these operatives bypass hiring screens and gain trusted access, often with help from U.S.-based facilitators who host 'laptop farms.' Once inside, they steal sensitive data and funnel millions of dollars back to fund North Korea’s weapons programs. In response, governments have launched enforcement initiatives and prosecuted domestic enablers, while companies face serious legal and reputational risks if they fail to strengthen compliance and detection measures.

...