Purple Bravo
2025-02-13 • Recorded Future • Inside the Scam: North Korea’s IT Worker Threat
Recorded Future's Insikt Group first reported on PurpleBravo in February 2025, tracking it as a North Korean-linked cluster formerly designated Threat Activity Group 120 that overlaps with the Contagious Interview campaign, first documented in November 2023 and also known in open sources as CL-STA-0240, Famous Chollima, and Tenacious Pungsan. The group primarily targets software developers, particularly in the cryptocurrency and IT services sectors, using fake recruiter personas, fictitious front companies, and fraudulent job interviews and coding tests to deliver malware, including the BeaverTail infostealer, the InvisibleFerret backdoor, and OtterCookie, aimed at stealing browser credentials and cryptocurrency wallet data. Insikt Group has identified dozens of BeaverTail and GolangGhost command-and-control servers and thousands of IP addresses linked to likely victims across cryptocurrency, IT services, financial services, and software development industries, and distinguishes PurpleBravo from, while noting some overlap with, PurpleDelta, its separate designation for North Korean fraudulent IT worker operations.
-
28
Related Actors
-
248
Related Reports
Related Actors
Related Reports in This Cluster
Top Authors
View Purple Bravo reports only