Skip to content

Security1 publisher3 min readPublished

North Korea's hiring funnel: 60 applications a day, 22 personas, ten jobs landed

Recorded Future says one PurpleDelta cluster applied at more than 1,100 companies and was likely employed at ten or more. The control point is the recruiting funnel, not the SOC.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Photograph accompanying North Korea's hiring funnel: 60 applications a day, 22 personas, ten jobs landed
Photo: businessmodelanalyst.com

What happened

  • Insikt Group has identified several clusters of activity linked to PurpleDelta, Recorded Future's designation for North Korean IT workers, comprising multiple operators likely based in China.
  • Between late 2024 and early 2025, one PurpleDelta cluster applied to jobs at over 1,100 companies.
  • The PurpleDelta clusters were highly likely to have been actively employed at ten or more organizations, with confirmed or probable placements posing an ongoing and material insider threat.
  • Insikt Group identified at least 22 fabricated personas linked to multiple PurpleDelta clusters that submitted applications to over 1,100 companies.
  • Operators submitted as many as 60 or more applications per day across at least 8 job platforms.

Compiled by The WatchSomething wrong?How this is made

Why it matters

Recorded Future's Insikt Group has published research on PurpleDelta, its designation for North Korean IT workers, describing operators likely based in China who applied for jobs at more than 1,100 companies between late 2024 and early 2025 [1][2]. Insikt assesses those clusters were highly likely to be actively employed at ten or more organizations [3], which locates the failure in the hiring funnel rather than in anything a detection team was ever going to see first.

The volumes describe a production line. Insikt counted at least 22 fabricated personas across multiple clusters, submitting as many as 60 or more applications per day across at least eight job platforms [4][5]. At that tempo, covering 1,100 companies is roughly 18 working days of output [1], and 1,100 companies spread across 22 personas averages about 50 targets each [2]. Ten placements against 1,100 targeted companies is a conversion rate near 0.9 percent [3]: unremarkable for a job seeker, and entirely sufficient when applications cost nothing and the persona inventory never runs dry.

The tooling is pointed at recruiters, not at firewalls. Personas were supported by AI-generated profile photos, custom-configured ChatGPT assistants, and identity documents sourced from an illicit ID-generation service, according to Insikt [6]. Operators ran multi-account management browsers and separate Chrome profiles to keep identities apart, with tracking spreadsheets to coordinate applications across them [7]. In interviews they used screen recording software alongside AI transcription and chatbot tools to generate answers in real time, sometimes repeating ChatGPT output verbatim [8]. Verbatim ChatGPT is a detectable interview artifact, but only if a human is on the call and listening for it.

After the offer, the tells become administrative. Insikt reports that once employed, operators recorded internal meetings at victim organizations and drafted pre-written Google Translate excuses to justify using personal devices and personal bank accounts for work [9]. At least two individuals were identified as facilitators who procured and maintained company-issued hardware on the operators' behalf [10], and coordination ran over Telegram and Slack [11]. Those are payroll, asset-management and IT-logistics signals: laptops shipped to an address that is not the employee's, bank detail changes, a device that never appears from the claimed location.

The targeting is also worth reading as a sector map. Insikt's executive summary lists software and technology, staffing and consulting, and healthcare and biotechnology as the primary sectors [12]; its key findings add financial services [13]. Staffing and consulting is the entry with leverage against it, because a placement there sits next to other companies' pipelines.

PurpleDelta overlaps with designations other vendors use, including Jasper Sleet, UNC5267, Wagemole, and Famous Chollima [14]. Earnings are funneled through layers of individual facilitators, shell companies, and money-laundering front companies to finance North Korea's sanctioned military and nuclear programs, per Recorded Future [15].

What to watch: Insikt says companies that have observed the indicators in its Appendix A should treat the situation as a potential active compromise and review the employment history and access privileges of matching individuals [16]. That is a records exercise owned by HR, talent operations and IT asset management, and it looks backwards at people already onboarded rather than forwards at candidates. Insikt also notes the operators demonstrate a high operational tempo to this day [17], so any control built around a single interview round is being tested continuously by a pipeline that only needs 0.9 percent to work.

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories