PurpleDelta
actor · actor:purpledelta single-source
Recorded Future's designation for the North Korean IT-worker cluster, a state-directed network of covert technology workers who pose as independent contractors and job-seeking developers to obtain remote employment, with earnings funnelled back through layered individual accounts. Insikt Group states the group overlaps with the vendor designations Jasper Sleet, UNC5267, Wagemole and Famous Chollima. Between late 2024 and early 2025 one cluster applied to over 1,100 companies, at times 60 positions a day, running at least 22 fabricated personas, some of which Insikt records as supported by AI-generated profile photographs from a face-swapping service, identity documents from an illicit document-generation service and purpose-configured chatbot assistants used to answer interview questions in real time, alongside fabricated code-hosting contribution histories; Insikt assesses the operators were highly likely employed by at least ten organisations. Employer-issued laptops are physically held by facilitators and worked remotely over commercial remote-desktop software with a commercial VPN marketed for circumventing China's national firewall, and Insikt places many operators' nexus in Shenyang, China. Roughly 80% of target companies were North American but operators applied in every region of the world (Insikt Group, 2026-08-18).
Aliases: Jasper Sleet, UNC5267, Wagemole, Famous Chollima
Coverage
7
4 about it · 3 mentions · first 2026-06-11 → last 2026-09-19
Latest activity
2026-09-19
FBI, Japanese and German authorities jointly confirm DPRK's fake-interview crew has infected 30,000+ devices…
Peak priority
high
1 high · 3 notable
Targets
public-sector
sectors: public-sector, finance, technology · regions: europe, us
Sources cited
13
12 hosts
2026-06-117 appearances2026-09-19
Action items (2)
Do-now tasks recorded on the entries about PurpleDelta, newest first. Check the date before acting on an older one.
- Inventory remote-monitoring-and-management agents across corporate endpoints and alert on any second RMM or remote-desktop agent appearing on a device that already carries the sanctioned one, Insikt names this as its own primary technical control, and it is the artifact a facilitator-held laptop necessarily produces.2026-08-19The fraud is a hiring problem; the evidence sits in…
- Compare the geolocation of company-issued laptops against the claimed work location and the source of that employee's authentications, starting with remote contractor devices shipped rather than handed over in person.2026-08-19The fraud is a hiring problem; the evidence sits in…
Defender insights
What each entry about PurpleDelta tells a defender to do, newest first.
Triage
Triage
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
overlaps with
- Contagious InterviewNPA/FBI assess WaterPlum actors and some North Korean IT workers operate under the same parent organization (313 General Bureau of the Munitions Industry Department).
Story timeline
Every entry that names PurpleDelta, newest first. Rows tagged mention only name it in passing: they are listed for completeness and add nothing to the action items, pivots or ATT&CK profile on this page.
- 2026-09-19WaterPlum ("Contagious Interview"): a seven-agency joint advisory quantifies the DPRK fake-job campaign for the first time, 30,000+ devices, 100+ countries, $10.7M in crypto, and Japan's first dismantled "laptop farm"
- 2026-09-08Sekoia and Kudelski Security split the 'Lazarus umbrella' into six named DPRK clusters, and document two of them adopting commodity ransomware-as-a-service within two months of each other
- 2026-08-28Unit 42's dataset of 405 AI-enabled malware samples finds 97% never leave sandboxes, and every sample that reached a production environment was caught by existing behavioural detection with no novel approach required
- 2026-08-28Kudelski Security: North Korean IT-worker infrastructure overlaps a Bismarck-linked gambling-platform operation and the FakeCalls Android banking trojan
- 2026-08-19PurpleDelta: Insikt Group gets inside a North Korean IT-worker operation and finds the detectable half is on the endpoint, a second remote-management tool on the company laptop, and a device whose location never matches the login
- 2026-06-16DPRK UNK_DeadDrop weaponises VS Code / Cursor auto-run to hit developers, including EU targets
- 2026-06-11CrowdStrike 2026 Technology Threat Landscape Report: technology is now the most-targeted sector
Hunting pivots
Affected products
ATT&CK techniques (17 across 10 tactics)
17 techniques observed across 4 entries about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Resource DevelopmentEstablish Accounts: Social Media Accounts · Compromise Accounts
- Initial AccessValid Accounts · Supply Chain Compromise: Compromise Software Supply Chain · Trusted Relationship · Hardware Additions
- ExecutionUser Execution: Malicious File
- PersistenceValid Accounts
- Privilege EscalationValid Accounts
- StealthValid Accounts · Social Engineering: Impersonation
- Credential AccessInput Capture: Keylogging · Credentials from Password Stores: Credentials from Web Browsers
- CollectionInput Capture: Keylogging · Screen Capture · Clipboard Data
- Command and ControlApplication Layer Protocol · Remote Access Tools · Remote Access Tools: Remote Desktop Software
- ImpactData Encrypted for Impact · Financial Theft
Resource Development TA0042
T1585.001Establish Accounts: Social Media Accounts×2
Adversaries may create and cultivate social media accounts that can be used during targeting. Adversaries can create social media accounts that can be used to build a persona to further operations. Persona development consists of the development of public information, presence, history and appropriate affiliations.
Evidence: 2026-08-28/kudelski-bismarck-dprk-it-worker-gambling-fakecalls-overlap · 2026-08-19/purpledelta-dprk-it-worker-facilitator-rmm-detection · ATT&CK page ↗
T1586Compromise Accounts×1
Adversaries may compromise accounts with services that can be used during targeting. For operations incorporating social engineering, the utilization of an online persona may be important. Rather than creating and cultivating accounts (i.e. Establish Accounts), adversaries may compromise existing accounts. Utilizing an existing persona may engender a level of trust in a potential victim if they have a relationship, or knowledge of, the compromised persona.
Evidence: 2026-08-28/kudelski-bismarck-dprk-it-worker-gambling-fakecalls-overlap · ATT&CK page ↗
Initial Access TA0001
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-08-19/purpledelta-dprk-it-worker-facilitator-rmm-detection · ATT&CK page ↗
T1195.002Supply Chain Compromise: Compromise Software Supply Chain×1
Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.
Evidence: 2026-09-19/waterplum-contagious-interview-joint-advisory-scale · ATT&CK page ↗
T1199Trusted Relationship×1
Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.
Evidence: 2026-08-19/purpledelta-dprk-it-worker-facilitator-rmm-detection · ATT&CK page ↗
T1200Hardware Additions×1
Adversaries may physically introduce computer accessories, networking hardware, or other computing devices into a system or network that can be used as a vector to gain access. Rather than just connecting and distributing payloads via removable storage (i.e. Replication Through Removable Media), more robust hardware additions can be used to introduce new functionalities and/or features into a system that can then be abused.
Evidence: 2026-08-19/purpledelta-dprk-it-worker-facilitator-rmm-detection · ATT&CK page ↗
Execution TA0002
T1204.002User Execution: Malicious File×1
An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.
Evidence: 2026-09-19/waterplum-contagious-interview-joint-advisory-scale · ATT&CK page ↗
Persistence TA0003
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-08-19/purpledelta-dprk-it-worker-facilitator-rmm-detection · ATT&CK page ↗
Privilege Escalation TA0004
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-08-19/purpledelta-dprk-it-worker-facilitator-rmm-detection · ATT&CK page ↗
Stealth TA0005
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-08-19/purpledelta-dprk-it-worker-facilitator-rmm-detection · ATT&CK page ↗
T1684.001Social Engineering: Impersonation×1
Adversaries may impersonate a trusted person or organization in order to persuade and trick a target into performing some action on their behalf. For example, adversaries may communicate with victims (via Phishing for Information, Phishing, or Internal Spearphishing) while impersonating a known sender such as an executive, colleague, or third-party vendor. Established trust can then be leveraged to accomplish an adversary’s ultimate goals, possibly against multiple victims.
Evidence: 2026-08-19/purpledelta-dprk-it-worker-facilitator-rmm-detection · ATT&CK page ↗
Credential Access TA0006
T1056.001Input Capture: Keylogging×1
Adversaries may log user keystrokes to intercept credentials as the user types them. Keylogging is likely to be used to acquire credentials for new access opportunities when OS Credential Dumping efforts are not effective, and may require an adversary to intercept keystrokes on a system for a substantial period of time before credentials can be successfully captured. In order to increase the likelihood of capturing credentials quickly, an adversary may also perform actions such as clearing browser cookies to force users to reauthenticate to systems.
Evidence: 2026-09-19/waterplum-contagious-interview-joint-advisory-scale · ATT&CK page ↗
T1555.003Credentials from Password Stores: Credentials from Web Browsers×1
Adversaries may acquire credentials from web browsers by reading files specific to the target browser. Web browsers commonly save credentials such as website usernames and passwords so that they do not need to be entered manually in the future. Web browsers typically store the credentials in an encrypted format within a credential store; however, methods exist to extract plaintext credentials from web browsers.
Evidence: 2026-09-19/waterplum-contagious-interview-joint-advisory-scale · ATT&CK page ↗
Collection TA0009
T1056.001Input Capture: Keylogging×1
Adversaries may log user keystrokes to intercept credentials as the user types them. Keylogging is likely to be used to acquire credentials for new access opportunities when OS Credential Dumping efforts are not effective, and may require an adversary to intercept keystrokes on a system for a substantial period of time before credentials can be successfully captured. In order to increase the likelihood of capturing credentials quickly, an adversary may also perform actions such as clearing browser cookies to force users to reauthenticate to systems.
Evidence: 2026-09-19/waterplum-contagious-interview-joint-advisory-scale · ATT&CK page ↗
T1113Screen Capture×1
Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as <code>CopyFromScreen</code>, <code>xwd</code>, or <code>screencapture</code>.
Evidence: 2026-09-19/waterplum-contagious-interview-joint-advisory-scale · ATT&CK page ↗
T1115Clipboard Data×1
Adversaries may collect data stored in the clipboard from users copying information within or between applications.
Evidence: 2026-09-19/waterplum-contagious-interview-joint-advisory-scale · ATT&CK page ↗
Command and Control TA0011
T1071Application Layer Protocol×1
Adversaries may communicate using OSI application layer protocols to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
Evidence: 2026-09-19/waterplum-contagious-interview-joint-advisory-scale · ATT&CK page ↗
T1219Remote Access Tools×1
An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.
Evidence: 2026-08-19/purpledelta-dprk-it-worker-facilitator-rmm-detection · ATT&CK page ↗
T1219.002Remote Access Tools: Remote Desktop Software×1
An adversary may use legitimate desktop support software to establish an interactive command and control channel to target systems within networks. Desktop support software provides a graphical interface for remotely controlling another computer, transmitting the display output, keyboard input, and mouse control between devices using various protocols. Desktop support software, such as `VNC`, `Team Viewer`, `AnyDesk`, `ScreenConnect`, `LogMein`, `AmmyyAdmin`, and other remote monitoring and management (RMM) tools, are commonly used as legitimate technical support software and may be allowed by application control within a target environment.
Evidence: 2026-08-19/purpledelta-dprk-it-worker-facilitator-rmm-detection · ATT&CK page ↗
Impact TA0040
T1486Data Encrypted for Impact×1
Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.
Evidence: 2026-09-08/sekoia-kudelski-dprk-lazarus-umbrella-six-cluster-split · ATT&CK page ↗
T1657Financial Theft×1
Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.
Evidence: 2026-09-08/sekoia-kudelski-dprk-lazarus-umbrella-six-cluster-split · ATT&CK page ↗
Entries about PurpleDelta (4)
Earlier coverage (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Contagious Interview×2
- Andariel×1
- BeaverTail×1
- Bismarck×1
- Citrine Sleet×1
- CryptoCore×1
- InvisibleFerret×1
- Jade Sleet×1
Where this entity is cited
Source distribution
- kudelskisecurity.com2 (15%)
- crowdstrike.com1 (8%)
- heise.de1 (8%)
- huntress.com1 (8%)
- ic3.gov1 (8%)
- proofpoint.com1 (8%)
- recordedfuture.com1 (8%)
- sekoia.com1 (8%)
- other4 (31%)
All cited sources (13)
- crowdstrike.comCrowdStrikehttps://www.crowdstrike.com/en-us/blog/crowdstrike-2026-technology-threat-landscape-report/
- heise.deheise onlinehttps://www.heise.de/news/Nordkoreanische-Cybergruppe-bestiehlt-IT-Fachleute-auf-Jobsuche-11458275.html
- huntress.comHuntresshttps://www.huntress.com/blog/huntress-dprk-remote-worker-investigation
- ic3.govFBI/IC3 Joint Cybersecurity Advisoryhttps://www.ic3.gov/CSA/2026/260918.pdf
- kudelskisecurity.comKudelski Security (Switzerland)https://kudelskisecurity.com/research/beyond-lazarus-organization-of-dprk-cyber-capabilities
- kudelskisecurity.comKudelski Securityhttps://kudelskisecurity.com/research/inside-north-koreas-cybercrime-ecosystem-fake-it-workers-gambling-networks-and-malware
- proofpoint.comProofpointhttps://www.proofpoint.com/us/blog/threat-insight/dont-fear-repo-unkdeaddrop-phishing-campaign-targets-developers-steal
- recordedfuture.comRecorded Future / Insikt Grouphttps://www.recordedfuture.com/research/purpledelta-fraudulent-employment-operations
- sekoia.comSekoiahttps://www.sekoia.com/blog/beyond-lazarus-organization-of-dprk-cyber-capabilities
- thehackernews.comThe Hacker Newshttps://thehackernews.com/2026/06/north-korean-hackers-are-turning.html
- therecord.mediaThe Record (Recorded Future News)https://therecord.media/north-korean-hackers-infect-thousands-of-devices-waterplum-scheme
- unit42.paloaltonetworks.comPalo Alto Networks Unit 42https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/
- verfassungsschutz.deBundesamt für Verfassungsschutz (Germany)https://www.verfassungsschutz.de/SharedDocs/kurzmeldungen/DE/2026/2026-09-18-joint-cybersecurity-advisory.html