Actor Profile
North Korean state-sponsored threat actors, tracked as Famous Chollima, Jasper Sleet, Nickel Tapestry, PurpleDelta (formerly TAG-121), UNC5267, and Wagemole, operate a sophisticated job fraud scheme to generate revenue for the DPRK's nuclear weapons and ballistic missile programs. These actors use stolen or forged identity documents, VPNs, and proxy services to fraudulently obtain remote employment in legitimate organizations worldwide. The campaign represents a unique insider threat where actors are hired as employees rather than compromising systems through traditional intrusion methods. The threat actors, many operating from China, leverage skilled IT workers both within and outside North Korea to target Fortune 500 companies and private sector firms across multiple industries.
TTPs (Tactics, Techniques, Procedures)
The campaign employs social engineering to bypass hiring processes using stolen/forged identity documents and AI-generated synthetic personas created via services like TrustID Card. Actors use VPNs (Astrill VPN) and proxy services (IPRoyal Proxy) to mask their location. Technical infrastructure includes KVM switches (PiKVM, TinyPilot) and USB capture cards (Guermok) to connect to laptop farms and stream video for web conferencing. Multi-account management browsers and separate Chrome profiles maintain distinct personas. During interviews, actors deploy screen recording software, AI transcription tools, and ChatGPT to generate real-time answers, often repeating responses verbatim. Post-employment, they record internal meetings, use Google Translate for communications, and coordinate via Telegram and Slack. Identity-brokering services and AnyDesk account-renting facilitate operations, with facilitators maintaining company-issued hardware. PurpleDelta operators maintain extensive tracking spreadsheets and apply to 60+ positions daily across 10 job platforms.
Targets & Patterns
The campaign has expanded beyond traditional IT sector targeting to include healthcare, biotechnology, sales and marketing, financial services, software and technology, and staffing and consulting sectors. Between late 2024 and early 2025, one PurpleDelta cluster applied to jobs at over 1,100 companies globally. Specific cases include three suspected North Korean workers employed at an Australian healthcare company impersonating Chinese individuals, an employee at an unnamed financial services firm, and a sales and marketing hire who used a stolen identity from an arrested individual. The actors target Fortune 500 companies and private sector firms worldwide, seeking remote employment opportunities that provide access to sensitive systems, data, and revenue generation. The broad sectoral expansion indicates the actors are no longer limiting themselves to IT roles where their technical skills are most applicable, suggesting either skill diversification or increased operational pressure to generate income.
Historical Context
The IT worker scheme has been ongoing for years, representing a sustained revenue-generation operation for North Korea's weapons programs. The campaign has been tracked under multiple vendor designations including Famous Chollima, Jasper Sleet, Nickel Tapestry, PurpleDelta (formerly TAG-121), UNC5267, and Wagemole. Previous reporting has documented the use of KVM switches like PiKVM and TinyPilot as characteristic infrastructure for this threat. The recent expansion into healthcare and sales sectors in 2026 represents an evolution from the campaign's historical focus on IT roles. PurpleDelta activity specifically has shown a high operational tempo with at least 60 job applications per day, and Recorded Future assesses the activity is almost certainly ongoing and will very likely continue to expand in scale and sophistication as operators adapt to increased awareness and detection efforts. The increasing integration of AI tools into the tradecraft represents a compounding risk factor in the campaign's evolution.
Defensive Recommendations
- Implement rigorous identity verification during hiring, including reverse image searches of candidate photos, verification of identity documents against known fraud patterns, and validation of employment history through direct contact with previous employers
- Monitor for anomalous VPN and proxy usage patterns during onboarding and employment, particularly connections through services like Astrill VPN, IPRoyal Proxy, or repeated geographic inconsistencies in login locations
- Detect unauthorized hardware installations by monitoring for KVM switches (PiKVM, TinyPilot) and USB capture devices (Guermok) on corporate endpoints through endpoint detection and response (EDR) tools and USB device control policies
- Flag suspicious interview behaviors including verbatim repetition of AI-generated responses, unusual delays in answering questions suggesting real-time translation or chatbot consultation, and requests to use personal devices or bank accounts for work purposes
- Conduct enhanced background checks including online presence verification, social media validation, law enforcement database searches for identity theft, and analysis of submitted documents for anomalies such as passport similarities or fraudulent billing statements
---
# Geopolitical Context
Geopolitical Context
The Democratic People's Republic of Korea (DPRK) continues to leverage fraudulent employment schemes as a revenue-generation mechanism to circumvent international sanctions. This campaign, tracked under multiple designations including Famous Chollima, Jasper Sleet, Nickel Tapestry, PurpleDelta, UNC5267, and Wagemole, represents a strategic adaptation of North Korea's asymmetric economic warfare capabilities. By placing operatives in legitimate private sector roles across Fortune 500 companies and smaller firms globally, Pyongyang appears to be generating illicit revenue streams to fund its weapons of mass destruction programs while simultaneously creating potential insider threat vectors. The expansion beyond traditional IT roles into healthcare, sales, and marketing sectors indicates operational maturation and suggests the regime is diversifying both revenue sources and potential intelligence collection opportunities. The use of China-based infrastructure and facilitators reflects North Korea's reliance on regional enablers to sustain sanctions evasion networks.
State Actor Alignment
The campaign is attributed to threat actors linked to the Democratic People's Republic of Korea (North Korea). Multiple intelligence and security firms track this activity under various designations: Famous Chollima, Jasper Sleet, Nickel Tapestry, PurpleDelta (formerly TAG-121), UNC5267, and Wagemole. Recorded Future's analysis indicates that at least one cluster, PurpleDelta, operates from China with multiple operators maintaining fabricated personas. The scheme directly supports North Korea's nuclear weapons and ballistic missile programs, which are subject to comprehensive United Nations Security Council sanctions. The campaign leverages stolen and forged identity documents, VPN services (including Astrill VPN), proxy networks (IPRoyal Proxy), and hardware facilitators who maintain company-issued equipment on behalf of remote DPRK operatives. The use of illicit identity-generation services such as TrustID Card and coordination via Telegram and Slack demonstrates a sophisticated support infrastructure. This activity represents a sanctions evasion mechanism that generates revenue while potentially creating insider access to sensitive corporate systems and data across multiple sectors.
Business Impacty pro region
The global scope of this campaign affects organizations across North America, Europe, Australia, and likely other regions where Fortune 500 companies and private sector firms operate. The February 2026 case involving an Australian healthcare company demonstrates that the threat extends beyond traditional Western targets. The healthcare and biotechnology sectors represent particularly sensitive targets given the value of medical research, patient data, and intellectual property. The expansion into sales and marketing roles may provide DPRK operatives with access to customer databases, business intelligence, and corporate strategy information. For European organizations, this threat compounds existing concerns about supply chain security and insider threats, particularly as remote work arrangements remain common post-pandemic. The reliance on China-based infrastructure and facilitators suggests that enforcement of sanctions and disruption efforts will require multilateral coordination, particularly with Beijing. The high operational tempo—with PurpleDelta applying to at least 60 positions daily across 10 job platforms—indicates that hundreds or potentially thousands of organizations globally may be affected. The integration of artificial intelligence tools for interview preparation and work performance suggests the detection challenge will intensify as these technologies become more sophisticated.
Forecast
If North Korean IT worker schemes continue to expand into non-technical sectors such as healthcare, sales, and marketing, organizations across all industries will likely need to implement enhanced identity verification and behavioral monitoring protocols during hiring and onboarding processes. The increasing integration of AI-assisted tools for interview performance and work execution is likely to make detection more difficult, potentially requiring organizations to develop AI-specific detection methodologies. If international awareness and detection capabilities improve, DPRK operatives will likely continue adapting their tradecraft, potentially exploring additional sectors or geographic markets with less mature security controls. Should facilitator networks in China and other regional hubs face disruption through law enforcement action or diplomatic pressure, the operational tempo may temporarily decrease, though North Korea's strategic reliance on this revenue stream suggests alternative infrastructure would likely be developed. If major breaches or sabotage incidents are publicly attributed to employed DPRK workers, regulatory pressure for enhanced background checks and continuous employee verification may increase, particularly in critical infrastructure and healthcare sectors. The use of hardware intermediaries (laptop farms with KVM switches) suggests that if remote work policies tighten or hardware controls improve, the scheme's scalability may be constrained, though hybrid arrangements will likely remain vulnerable.
