Security Researcher Infiltrated North Korean Hackers, Found They Breached Hundreds of Networks Worldwide
A Greek cybersecurity researcher spent 22 months inside North Korean hacking infrastructure, uncovering that 1,640 companies across 57 countries were affected, including hundreds with serious intrusions.

Cybersecurity researcher Vangelis Stykas, based in Greece, has revealed findings from nearly two years spent inside the systems of a North Korean hacking group. He says the group's operations have impacted 1,640 companies across 57 countries. Of those, approximately 700 to 800 organizations experienced what he describes as "really damaging" intrusions.
Stykas, CTO at cybersecurity firm Kumio, says he gained access to multiple command-and-control servers used by the hackers. In some cases, the hackers had apparently infected themselves with their own malware, which gave him access to their workstations as well. He says he has seen their Slack and Discord channels and collected about 5 terabytes of data.
By analyzing developer keys, source code, and other material, Stykas identified potential victims and disclosed the incidents to the affected organizations. At the Black Hat security conference in Las Vegas, he publicly named around a dozen companies, including Boston Children's Hospital, Japanese tech firm AEON Smart Technology, Chinese phone maker Oppo, cryptocurrency firms Coinbase and Uniswap Labs, Italy's Supreme Judicial Council, a subsidiary of Saudi Arabia's Al Rajhi Bank, and Digitaal Vlaanderen, part of the Flemish Government in Belgium.
Several organizations responded to the disclosures. Japan's Computer Emergency Response Team confirmed the findings and worked with AEON Smart Technology on remediation. The Flemish government said it isolated the affected workstation and revoked potentially exposed credentials. Boston Children's Hospital said the incident involved a former independent contractor's personal device, not hospital systems. Coinbase said it investigated the contractor and found no evidence of a North Korea link, but acknowledged potential risks in his technology setup and terminated the contractor before receiving Stykas's tip.
The attacks largely relied on a simple, well-documented tactic: fake job offers targeting software developers. Victims were asked to download a program as a coding test, which silently installed malware. Microsoft says the technique, known as Contagious Interview, has been used since at least 2022. Stykas notes that some contractors had access to up to 30 companies, greatly expanding the impact of successful breaches.
Marcus Hutchins, a threat intelligence researcher at Expel, says the scale is not surprising given the scope of North Korean campaigns, but warns that persistent access could allow espionage teams to piggyback on it. Stykas says his main concern is the hundreds of companies that never responded to his warnings. "They're here, they're hacking us nonstop," he says, adding that how a company handles being hacked separates good from bad.

