The Inside View of North Korea's Cyber Offensive

Security researcher Vangelis Stykas has spent 22 months inside the infrastructure of a North Korean hacking group. His findings, presented at Black Hat 2025, show 1,640 companies across 57 countries have been compromised. Of those, 700-800 suffered "really damaging" intrusions, including root access to servers and AWS accounts.

"It's company access, it's root access to servers, it's root access to AWS," Stykas told WIRED. "For crypto companies, it's keys, it's blockchain access—it's ridiculous access."

How He Got In

Stykas, CTO at cybersecurity firm Kumio, accessed multiple command-and-control servers. In some cases, the hackers infected themselves with their own malware, giving him access to their workstations. He now has access to their Slack, Discord, and around 5 terabytes of data.

"I have access to their Slack, I have access to their Discord, I have access to a lot of stuff," he says.

The Attack Vector: Fake Job Interviews

The primary intrusion method is the "Contagious Interview" campaign, documented by Microsoft since 2022. Hackers lure software developers with fake job offers, then ask them to download a test program that installs malware. This simple social engineering has been devastatingly effective.

Stykas found that compromised contractors often had access to multiple companies—one contractor had access to up to 30 firms. This greatly expanded the blast radius of each attack.

Named Victims and Their Responses

Stykas is publicly naming about a dozen companies that handled disclosures well. These include:

  • Boston Children's Hospital – held a vast Covid-19 database of Americans' health data. The hospital says the incident involved a former independent contractor's personal device, and no unauthorized access to hospital systems occurred.
  • AEON Smart Technology – large Japanese tech firm. Japan's CERT confirmed the findings and worked on remediation.
  • Oppo – Chinese phone manufacturer.
  • Coinbase and Uniswap Labs – cryptocurrency firms. Coinbase said they terminated a contractor within 30 days of onboarding after detecting potential outsourcing, before Stykas's tip.
  • Italy's Supreme Judicial Council – no response.
  • Al Rajhi Bank subsidiary – no response.
  • Digitaal Vlaanderen – part of the Flemish Government in Belgium. They confirmed notification and remediation.

Focus on Crypto, But Risk Remains

Stykas observed that the hackers largely focused on stealing cryptocurrency wallets, ignoring other sensitive data. However, Marcus Hutchins, threat intelligence researcher at Expel, warns this focus could shift. "It seems like the teams tend to stick to their task of getting crypto wallets. But there's obviously the risk that if they're maintaining persistent access to a corporation, one of the espionage teams could then piggyback off that access," Hutchins says.

The Scale of the Problem

North Korea's cyber operations are sprawling. A Dtex report found the country has several hundred skilled cyber operators and "several thousand" IT workers engaged in fraudulent remote employment. Both are set yearly earnings quotas. Stykas's findings show the fake interview tactic has been more successful than previously known.

Unnamed Victims and Unheeded Warnings

Stykas disclosed incidents to impacted companies, but hundreds never responded. He says new victims are added daily. "This started as a side project, and right now it's my full-time job," he says.

"They're here, they're hacking us nonstop," Stykas says. "At the end of the day, everyone's getting hacked. How you treat you being hacked is what separates a good company from a bad company. And we have seen a lot of bad companies."

What Developers Should Do Now

If you're a developer, be suspicious of unsolicited job offers that ask you to download and run code. Verify the legitimacy of the company and the recruiter. If you're a contractor, understand that your access is a liability—use separate accounts, and never reuse credentials. For companies, vet contractors thoroughly and monitor their access.

Stykas's research demonstrates that the threat is real and pervasive. The question is not if you'll be targeted, but when. Prepare accordingly.