Recorded Future linked PurpleDelta to at least 22 fabricated personas that applied to more than 1,100 companies between late 2024 and early 2025, with operators likely securing work at 10 or more organizations. The operation used AI generated profile photos, custom ChatGPT assistants, identity documents, and intervi...
Research answer

Create a landscape editorial hero image for this Studio Global article: What did Recorded Future’s August 17 report reveal about the North Korean state-directed PurpleDelta operation—which used at least 22 AI-gen. Article summary: Recorded Future’s report portrayed PurpleDelta as an industrialized North Korean remote-worker operation, not ordinary résumé fraud: AI-enabled, multi-persona hiring campaigns likely secured access inside at least 10 org. Topic tags: general, government, general web, user generated, academic. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, wate
Remote hiring fraud is no longer limited to fake listings that trick job seekers into surrendering money or bank details. Recorded Future’s analysis of PurpleDelta describes a North Korea-linked operation that used fabricated identities and AI tools to pursue real employment inside foreign companies. One cluster applied to more than 1,100 companies, while the broader activity involved at least 22 personas and likely placements at 10 or more organizations.
The distinction matters: in this model, the employer—not the applicant—is the immediate target. A successful placement can give an operator legitimate credentials, access to internal systems, and a trusted position inside a company.
Recorded Future’s Insikt Group identified several clusters associated with PurpleDelta, its designation for North Korean IT-worker activity involving fraudulent identities. The activity examined in the report occurred primarily between late 2024 and early 2025. The targets included software and technology companies, staffing and consulting firms, and organizations in healthcare and biotechnology.
Across the operation, researchers identified at least 22 fabricated personas. One cluster applied to more than 1,100 companies through at least eight recruitment platforms and submitted as many as 60 applications per day. Researchers assessed that operators were highly likely to have been employed by at least 10 organizations.
That scale suggests a repeatable hiring system rather than isolated résumé fraud. The identities could be created, adapted, and replaced as needed, allowing operators to keep pursuing access even after one persona was detected.
The personas were not built from a single false résumé. According to the reporting around Recorded Future’s findings, operators combined fabricated identities with AI-generated profile photos, custom-configured ChatGPT assistants, and identity documents obtained through illicit channels.
AI helped operators tailor applications and maintain consistency across different stages of recruitment. During video interviews, some operators reportedly used live transcription and AI-generated responses, while translation tools helped them explain communication or language difficulties.
The investigation also described operators managing several identities at the same time. Meeting recordings and screen-capture tools added another layer of concern because they could expose information discussed or displayed inside an employer’s systems. The available evidence does not establish that every persona used every technique, but the combination shows how AI can reduce the time and effort required to operate multiple identities.
A fake employee can be more dangerous than a fake applicant because hiring itself supplies trust. Once inside, an operator may receive access to source code, internal tools, customer or financial information, strategy discussions, and company credentials. The exact exposure depends on the role and the organization’s access controls, but remote work can make it harder to verify who is operating the account and device.
The financial incentive also has a geopolitical dimension. PurpleDelta is associated with North Korean revenue generation and intelligence collection, and reporting on the wider North Korean IT-worker scheme has linked illicit employment revenue to sanctioned state programs and weapons-of-mass-destruction funding.
Recorded Future’s broader research describes synthetic identities as a dual enterprise threat: they can support financial fraud while also enabling sanctions evasion, illicit revenue generation, and intellectual-property theft.
PurpleDelta targets companies through the hiring process, while more familiar employment scams target people looking for work. The tactics are different, but both exploit remote recruitment, online trust, and weak identity verification.
In one recent example, BBB North Alabama warned about purported remote data-entry jobs promoted under the name of “Parkway Greenhouse LLC.” Applicants reported receiving quick offers and then being asked for bank-account information.
The consumer impact of employment scams has also grown sharply. FTC data shows that reported losses from job and fake-employment-agency scams increased from $90 million in 2020 to $501 million in 2024, while reports nearly tripled over the same period. The Better Business Bureau separately reported that employment-scam complaints more than doubled in 2025 compared with the previous year.
The common lesson for both sides of the marketplace is that a convincing digital profile is not proof of a real person, a real employer, or a legitimate location.
Recorded Future’s recommended response is to verify the person behind an account—not simply the documents, résumé, or online profile. A stronger process should combine several signals:
These checks should work together rather than serve as a single pass-or-fail test. A familiar device, a plausible document, or a successful video call can each be misleading when an operator is coordinating multiple personas.
PurpleDelta shows why identity verification cannot end when an applicant accepts an offer. The most important question is not whether a résumé looks authentic; it is whether the same verified person, in the same verified location, is using the same authorized equipment throughout the employment lifecycle.
A fabricated persona is disposable. Removing one account or name may not stop the operator from returning with a different identity. Continuous checks across identity, location, devices, and access behavior give employers a better chance of detecting the operator rather than merely deleting the latest profile.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
Recorded Future linked PurpleDelta to at least 22 fabricated personas that applied to more than 1,100 companies between late 2024 and early 2025, with operators likely securing work at 10 or more organizations.
Recorded Future linked PurpleDelta to at least 22 fabricated personas that applied to more than 1,100 companies between late 2024 and early 2025, with operators likely securing work at 10 or more organizations. The operation used AI generated profile photos, custom ChatGPT assistants, identity documents, and interview support to manage multiple identities at scale.
The campaign fits a wider employment scam surge: FTC reported losses rose from $90 million in 2020 to $501 million in 2024, while BBB employment scam reports more than doubled in 2025.