Researcher Spends 2 Years Inside North Korean Hacker Servers
A security expert spent nearly two years inside North Korean hacker servers and uncovered over 1,600 victim organizations.
Vangelis Stykas, chief technology officer at Kumio, spent 22 months inside the command and control servers used by North Korean hacking groups. Speaking at the Black Hat conference in Las Vegas, he revealed a confirmed list of 1,640 victim organizations across 57 countries. By monitoring the attackers from their own files, he found that roughly half of these intrusions were serious breaches involving stolen crypto wallet keys and cloud permissions.
The hackers relied on fake job offers rather than software bugs to gain access. Developers seeking senior roles were sent coding tests that installed malware, often through compromised code packages on GitHub or Bitbucket. Once inside, the attackers bypassed health records and criminal databases, focusing strictly on API tokens, cloud credentials, and blockchain access.
This specific focus explains the massive financial toll on the crypto sector. Groups tied to North Korea stole over $2 billion in digital assets during 2025 alone, pushing total losses past $6 billion since 2017. Security firms advise crypto projects and fintech companies to thoroughly vet contractors and share threat intelligence to prevent similar hiring exploits.
Market sentiment
Be the first to react
▍Comments (0)
No comments yet. Start the conversation!





