Crypto World

Researcher ‘Lives’ Among North Korean Hackers, Discovers 1,640 Victims

Published

on

A Greek security researcher reportedly spent 22 months inside North Korean hacking servers. He came out with a victim list of 1,640 organizations in 57 countries.

Vangelis Stykas is chief technology officer at security firm Kumio. He presented the findings this week at Black Hat in Las Vegas.

How the Hunters Became the Hunted

Stykas turned the usual order around. He worked his way into the command-and-control servers the crews use to run their malware.

In some cases he landed on their personal computers. The hackers had infected those machines themselves.

Advertisement

Then he simply stayed. For nearly two years he watched them work and logged each new victim as it appeared.

He pulled roughly five terabytes of data. It held developer keys, private source code, and the crews’ own Slack and Discord messages.

That access is why the count is firm. Most threat reports estimate victims from the outside.

This one counted them from the attackers’ own files. Of the 1,640 organizations, Stykas rates 700 to 800 as seriously breached.

Advertisement

Follow us on X to get the latest news as it happens

In those cases the crews held root access to servers, Amazon Web Services (AWS) root permissions, or cryptocurrency wallet keys.

A Job Offer Was the Only Exploit They Needed

No software flaw opened these doors. A job offer did.

Advertisement

Developers were approached with senior roles and strong pay. They were then asked to run a take-home coding test. The test installed malware.

Palo Alto Networks researchers named the pattern Contagious Interview back in November 2023. Five security firms have since tracked the same crew under six different labels.

Microsoft published its own breakdown in March 2026. It traced the chain to fake code packages hosted on GitHub, GitLab, and Bitbucket.

Opening one in Visual Studio Code triggers a trust prompt. Approve it, and the editor runs the attackers’ code for them.

Advertisement

“By embedding targeted malware delivery directly into interview tools, coding exercises, and assessment workflows developers inherently trust, threat actors exploit the trust job seekers place in the hiring process,” read an excerpt in a March security blog from Microsoft security blog.

The backdoors then hunt a short shopping list. Microsoft names API tokens, cloud credentials, signing keys, crypto wallets, and password manager files.

Hiring is a repeat weak point. Consensys caught a hidden North Korean developer on its own team, a month into work on MetaMask code.

One Contractor, Thirty Front Doors

The lure is cheap. The reach is not.

Stykas found contractors carrying live credentials for as many as 30 companies. A single infected laptop became thirty ways in.

Advertisement

Boston Children’s Hospital shows the pattern. Stykas traced its exposure to a former contractor’s personal device.

The hospital disputes the framing. It says it cut the credentials within hours and found no sign its own systems were entered.

The crews were also picky. They could reach health records and criminal databases, yet ignored both.

They went for wallets and blockchain access instead. Coinbase and Uniswap Labs sit among the organizations that acted on his warnings.

Advertisement

That discipline shows up in the totals. Crews tied to the Democratic People’s Republic of Korea (DPRK) stole a reported $2.02 billion in digital assets during 2025.

CrowdStrike logged that as a 51% jump in one year. It also flags a crew it calls GOLDEN CHOLLIMA for using recruitment lures to reach fintech cloud environments.

That is the chain Stykas watched from the inside. The human route keeps winning.

TRM Labs traced April’s $285 million Drift Protocol theft to in-person meetings between North Korean proxies and staff.

Advertisement

Two attacks produced 76% of 2026 losses from just 3% of incidents. Pyongyang’s running total now clears $6 billion since 2017.

Stykas says fresh victims are still surfacing in the data. Most organizations he warned never wrote back, which is why groups like Crypto ISAC now pool DPRK threat intelligence instead.

The post Researcher ‘Lives’ Among North Korean Hackers, Discovers 1,640 Victims appeared first on BeInCrypto.

Source link

Advertisement

You must be logged in to post a comment Login

Leave a Reply

Cancel reply

Trending

Exit mobile version