
A Greek security researcher has revealed the extent of North Korean cyber operations after spending 22 months inside hacker servers. According to reports from Kumio, Vangelis Stykas, the company's chief technology officer, mapped 1,640 organizations across 57 countries during his extensive research. The findings were presented this week at Black Hat in Las Vegas, providing unprecedented insight into the scale of North Korean cyber activities. As reported by WIRED, Stykas gained access to command-and-control servers used by North Korean hacking crews and maintained his position for nearly two years while logging new victims as they appeared.
Stykas achieved his access by working his way into the command-and-control servers used by North Korean hacking crews to run their malware operations. As reported by Kumio, he gained access to their personal computers that had been infected by the hackers themselves, then maintained his position for nearly two years while logging new victims as they appeared. The researcher collected approximately five terabytes of data containing developer keys, private source code, and the crews' own communication messages from Slack and Discord platforms. According to WIRED, he has access to their Slack, Discord, and other internal systems, providing comprehensive visibility into the hackers' operations. However, Stykas has requested WIRED not to reveal exactly how he gained access to the command-and-control servers, maintaining the operational security of his research methodology.
Of the 1,640 organizations identified, Stykas rates 700 to 800 as seriously breached, where the crews held root access to servers, Amazon Web Services (AWS) root permissions, or cryptocurrency wallet keys. According to Microsoft research published in March 2026, North Korean cyber operations have resulted in $2.02 billion in digital asset thefts during 2025, representing a 51% increase from the previous year. The attacks have generated a $6 billion total since 2017, with two attacks alone producing 76% of 2026 losses from just 3% of incidents. As reported by WIRED, for crypto companies, the hackers gained access to keys and blockchain access, while for other organizations, it involved company access and root access to servers. The scope extends beyond cryptocurrency operations, affecting companies across multiple sectors including consumer hardware, pediatric healthcare, and European judicial bodies.
The research reveals that North Korean hackers exploit the hiring process rather than traditional software vulnerabilities. As reported by Microsoft security blog, the attackers approach developers with senior roles and strong compensation, then ask them to complete take-home coding tests that install malware. This pattern, named Contagious Interview by Palo Alto Networks in November 2023, involves fake code packages hosted on GitHub, GitLab, and Bitbucket that trigger trust prompts when opened in Visual Studio Code. The backdoors then target API tokens, cloud credentials, signing keys, crypto wallets, and password manager files. According to WIRED, North Korean hacker groups have used this fake interview hacking technique in a broader campaign known as Contagious Interview since as early as 2022, with the hackers maintaining a tight focus on gaining access to cryptocurrency wallets. The mechanism is described as indistinguishable from the intrusion funnel, with engineers running take-home coding tests from strangers on work laptops or personal machines that then touch corporate cloud systems.
The research highlights the challenges organizations face in responding to North Korean cyber threats. According to Kumio, Stykas found contractors carrying live credentials for as many as 30 companies, demonstrating how a single infected laptop can provide access to multiple organizations. The hospitality sector has been particularly affected, with Boston Children's Hospital tracing its exposure to a former contractor's personal device. Organizations like Crypto ISAC now pool DPRK threat intelligence collectively due to the limited response rates from warned organizations, with most never responding to security alerts. At Black Hat, Stykas identified around a dozen organizations, including Coinbase, Uniswap Labs, Oppo, Boston Children's Hospital, and Italy's Supreme Judicial Council, largely the ones he says handled the disclosure well or fixed the compromises. As reported by WIRED, the forward-looking piece for developer-heavy companies is treating candidate code as untrusted input, the same way they treat email attachments, to prevent future compromises through this exploitation method.