Outbound TCP traffic to known PurpleDelta-associated IP infrastructure
Detects outbound TCP traffic to known PurpleDelta-associated infrastructure IP addresses on common remote-access/web ports (80, 443, 3389), indicating potential communication with North Korean IT-worker facilitator infrastructure. Scope is limited to static IP indicators from Appendix A; does not cover Astrill VPN egress ranges or shell-company recruitment domains (minicursor[.]com), which would require separate signatures.
Suricata

