North Korean‑linked ‘PurpleDelta’ Operates AI‑Fabricated Personas to Infiltrate 1,100 Companies
What Happened — Insikt Group identified a coordinated campaign by “PurpleDelta,” a North‑Korean IT‑worker threat group operating out of China. The actors created at least 22 synthetic identities—complete with AI‑generated photos, forged documents, and custom ChatGPT assistants—and applied for remote technical roles at more than 1,100 firms across software, staffing, healthcare, and finance. At least ten of those fabricated hires are believed to be actively employed, giving the group insider access to corporate networks and data.
Why It Matters for Compliance & Audit Readiness
- The scenario maps directly to SOC 2 CC6.1 (Logical Access) and CC6.2 (User Provisioning) requirements: organizations must demonstrate that only verified, authorized individuals receive access and that provisioning is documented.
- Continuous‑compliance programs need real‑time evidence that hiring processes, background checks, and privileged‑access monitoring are effective—exactly the controls Verisq’s SOC 2 Access Controls capability helps capture and audit.
Who Is Affected — Technology/SaaS vendors, staffing and consulting firms, healthcare/biotech providers, and financial services companies that hire remote technical staff.
Recommended Actions
- Strengthen pre‑hire vetting: require multi‑factor identity verification, cross‑check résumé data against known fraud indicators, and incorporate AI‑driven persona detection.
- Enforce least‑privilege provisioning and periodic access reviews for all new hires, especially remote workers.
- Deploy continuous user‑behavior analytics (UBA) to flag anomalous activity from newly provisioned accounts.
- Update security‑awareness training to cover social‑engineering tactics used by synthetic personas.
Source: Recorded Future – PurpleDelta Fraudulent Employment Operations
Technical Notes — The actors leveraged multi‑account browsers, separate Chrome profiles, AI‑generated profile images, custom ChatGPT assistants, and illicit ID‑generation services. Communication was conducted over Telegram and Slack; interview answers were often verbatim ChatGPT responses. No specific CVE is involved; the risk stems from identity fabrication and insider‑threat tactics.