A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide
For years, North Korea’s stealthy hackers and scam IT workers have infiltrated companies, stealing corporate secrets and plundering billions in cryptocurrency to help fund the totalitarian regime and its weapons program…

For years, North Korea’s stealthy hackers and scam IT workers have infiltrated companies, stealing corporate secrets and plundering billions in cryptocurrency to help fund the totalitarian regime and its weapons programs. Now, a security researcher who has spent almost two years inside the systems belonging to a group of those North Korean hackers is raising the alarm on just how effective and far reaching the targeting of individual employees and contractors has been in breaching organizations across the globe.
Since Greece-based cybersecurity researcher Vangelis Stykas gained access to North Korean systems 22 months ago, he says, he has found evidence that 1,640 companies across 57 countries have been impacted by the country’s hacking operations. Among these, Stykas will detail at the Black Hat security conference in Las Vegas today, around 700 to 800 of the impacted organizations have had “really damaging” intrusions.
“It’s company access, it’s root access to servers, it’s root access to AWS,” the researcher tells WIRED, referring to Amazon Web Services and the term “root” to mean the highest level of permissions in a computer system. “For crypto companies, it’s keys, it’s blockchain access—it’s ridiculous access.”
Stykas, the CTO at cybersecurity firm Kumio, says he accessed multiple command-and-control servers used by the hackers, though he asked WIRED not to reveal the details of how he gained that access due to the sensitivity of that information. In some cases, he notes, the hackers appeared to have infected themselves with their own malware—which, as a result, gave him access to the hackers’ workstations, too. “I have access to their Slack, I have access to their Discord, I have access to a lot of stuff,” Stykas says, adding he has seen around 5 terabytes of data in total.
As he probed those systems over months, Stykas identified potential victims—by analyzing developer keys, source code, and more—and says he has disclosed the incidents to those impacted. As part of his talk at Black Hat, Stykas is publicly naming around a dozen of the impacted companies—these are, he says, largely the ones that handled the disclosures well and/or fixed possible compromises. The researcher says these include the Boston Children’s Hospital (which held a vast Covid-19 database of Americans’ personal health data), the large Japanese tech firm AEON Smart Technology, Chinese phone manufacturer Oppo, cryptocurrency firms Coinbase and Uniswap Labs, Italy’s Supreme Judicial Council, a subsidiary of Saudi Arabian bank Al Rajhi Bank, and Digitaal Vlaanderen, part of the Flemish Government in Belgium.
Multiple companies and organizations named in this article did not respond to WIRED’s request for comment about the incidents. Japan’s Computer Emergency Response Team says it confirmed the security researcher’s findings and worked with AEON Smart Technology on “remediation.”
Source: Wired