A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide

Staff
By Staff 5 Min Read

For years, a shadowy network of North Korean hackers and clandestine IT workers has quietly infiltrated global corporations, siphoning off trade secrets and billions in cryptocurrency to fuel the regime’s illicit weapons programs. While the world often views these threats as abstract geopolitical maneuvers, a chilling new report reveals that the battlefield is actually the humble personal computer of the average employee. Vangelis Stykas, a Greece-based cybersecurity researcher at the firm Kumio, spent the last 22 months embedded deep within the North Korean hackers’ own digital infrastructure. His findings, set to be presented at the Black Hat security conference, pull back the curtain on a sophisticated, industrialized operation that has successfully compromised nearly 1,640 companies across 57 countries, leaving no corner of the global economy untouched.

The scale of the damage is staggering. Stykas reports that among the thousands of impacted organizations, roughly 700 to 800 suffered “really damaging” intrusions. We aren’t talking about simple phishing emails or minor data leaks; these hackers gained “root” access—the highest possible level of administrative control—over servers, Amazon Web Services, and, in the case of cryptocurrency firms, the master keys to blockchain assets. The intruders weren’t just window-shopping; they effectively owned the infrastructure of their targets. By accessing the hackers’ own command-and-control servers—sometimes even capitalizing on the hackers’ own accidental self-infection with their own malware—Stykas managed to sift through roughly five terabytes of stolen data, including internal communications from the hackers’ Slack and Discord channels.

What makes this investigation particularly humanizing—and deeply unsettling—is how Stykas obtained his intelligence. By analyzing developer keys and source code found on the hackers’ own workstations, he transformed from a passive observer into an active whistleblower. Over the past two years, he has worked quietly to notify the victims, helping them understand that their systems were not just vulnerable, but already conquered. At the upcoming Black Hat conference, he plans to name a dozen organizations that handled these disclosures with transparency. The list is startlingly broad, including the Boston Children’s Hospital, the Japanese tech giant AEON Smart Technology, the Chinese phone manufacturer Oppo, and even government bodies like Italy’s Supreme Judicial Council and a Flemish government agency.

The aftermath of these disclosures reveals the messy reality of modern cybersecurity. While some organizations, such as the Flemish government, confirmed the researcher’s findings and quickly isolated compromised workstations to prevent further damage, others were quick to defend their security postures. For example, Boston Children’s Hospital clarified that the breach involved a former independent contractor’s personal device rather than the hospital’s core systems, insisting that no private health data was actually exposed. These responses underscore a critical reality: the North Korean strategy often involves exploiting the “human element”—contractors, remote workers, and third-party vendors—rather than attacking the digital fortress directly.

Coinbase, the cryptocurrency exchange, offered a nuanced take on the phenomenon. When notified by Stykas, they investigated a contractor who appeared to be based in the United States. While their internal probe didn’t definitively link the individual to the North Korean government, their own security protocols had already flagged the contractor for potentially outsourcing their work to a third party—a common tactic used by North Korean operatives to bypass hiring filters. Coinbase terminated the contractor before the situation could escalate, asserting that no customer data was compromised. This highlights a terrifying “grey zone” in hiring, where companies struggle to distinguish between a legitimate remote employee and a front acting on behalf of a state-sponsored hacking ring.

Ultimately, Stykas’s work serves as a sobering wake-up call for the interconnected global workforce. The “North Korean hacker” is no longer just a remote adversary in a distant capital; they are an invisible presence lurking in the Slack channels and developer repositories of companies that we trust with our health, our money, and our personal data. As these groups continue to evolve their tactics—using our own trust in remote work and independent contracting against us—the defense of our digital infrastructure depends less on complex firewalls and more on basic, persistent vigilance. Stykas has shone a light into the darkness, but his findings suggest that the struggle to secure our digital lives is only just beginning.

Share This Article
Leave a Comment

Leave a Reply

Your email address will not be published. Required fields are marked *