A ground-breaking investigation into North Korea's state-sponsored hacking infrastructure has revealed an unprecedented volume of compromised corporate networks across the globe. Over the past 22 months, cybersecurity researcher Vangelis Stykas gained unauthorized access to command-and-control servers operated by North Korean threat actors, uncovering evidence that 1,640 organizations spanning 57 countries have fallen victim to the regime's cyber campaigns. Presenting his exhaustive findings at the Black Hat security conference in Las Vegas, Stykas highlighted that between 700 and 800 of these impacted institutions experienced severe, high-level intrusions that granted attackers administrative control over critical infrastructure, cloud environments, and digital asset repositories.
Unprecedented Visibility Into North Korean Command Infrastructure
The scale of the discovery stems from an unconventional counter-investigation conducted by Stykas, who serves as the Chief Technology Officer at the cybersecurity firm Kumio. After successfully penetrating multiple command-and-control servers utilized by the state-backed hackers, Stykas maintained persistent visibility into their operational channels. In several notable instances, North Korean operators inadvertently infected their own internal workstations with their proprietary malware. This operational blunder inadvertently opened a doorway for the researcher to observe the hackers' internal communications, granting him direct access to their active Slack instances, Discord servers, and technical workspaces.
Throughout the nearly two-year monitoring period, Stykas sifted through approximately 5 terabytes of stolen data, source code, and developer credentials. By systematically auditing cryptographic keys, configuration files, and stolen logs stored on the hackers' servers, he began mapping out the victimology of North Korea's global campaigns. Rather than keeping these findings siloed, Stykas engaged in responsible disclosure protocols to notify affected entities, coordinating remediation efforts with international Computer Emergency Response Teams and government cyber agencies.
Extensive Blast Radius: High-Level Administrative Access Uncovered
The depth of access obtained by the North Korean cyber units was exceptionally broad. According to technical documentation gathered from the breach, intruders routinely secured root-level permissions across corporate servers and cloud environments hosted on Amazon Web Services (AWS). In the context of cryptocurrency and blockchain enterprises, the hackers obtained private keys and direct administrative access to core protocol infrastructures, creating immense financial exposure.
At the Black Hat presentation, Stykas disclosed the names of roughly a dozen impacted organizations, focusing primarily on entities that managed the notification process responsibly and executed prompt remediation measures. The named victims encompass a diverse array of global institutions, including prominent healthcare providers, technology conglomerates, financial institutions, and government bodies
- Boston Children's Hospital: Host to an extensive national Covid-19 database containing personal health records of Americans.
- AEON Smart Technology: A major Japanese technology services firm.
- Oppo: The multinational consumer electronics and smartphone manufacturer based in China.
- Coinbase and Uniswap Labs: Leading cryptocurrency exchange and decentralized finance protocol developers.
- Supreme Judicial Council of Italy: The constitutional governing body for Italy's judiciary.
- Al Rajhi Bank Subsidiary: An operational unit of the major Saudi Arabian banking institution.
- Digitaal Vlaanderen: The digital transformation agency operating under the Flemish Government in Belgium.
Official Responses and Containment Actions
Following the public disclosures, several targeted organizations and security authorities clarified the scope and containment of the incidents. Computer Emergency Response Team officials in Japan confirmed the researcher's findings regarding AEON Smart Technology, noting that joint remediation efforts successfully neutralized the threat within the company's network.
A spokesperson for the Flemish government in Belgium confirmed receiving notification regarding the Digitaal Vlaanderen compromise on March 3, 2026, through the Centre for Cybersecurity Belgium (CCB). Authorities immediately isolated the impacted workstation, revoked exposed credentials, and rotated system access keys. Comprehensive forensic analysis indicated that the intrusion was successfully contained without further lateral movement.
Boston Children's Hospital clarified that the incident originated on a personal device belonging to a former independent contractor rather than an internal hospital server. Hospital IT security teams acted within hours of receiving notification to revoke all active credentials. Internal investigations revealed no evidence of unauthorized access to hospital systems or sensitive patient databases, noting that the data present on the contractor's device consisted of information that was already publicly accessible.
Coinbase detailed an independent investigation into a US-based contractor conducted prior to receiving external disclosures. Although security controls uncovered no initial evidence linking the individual directly to the Democratic People's Republic of Korea (DPRK) government, internal monitoring flagged risky technology configurations suggesting the contractor had unauthorizedly outsourced coding tasks to third parties. Coinbase terminated the contractor's engagement within 30 days of onboarding, verifying that no sensitive customer data or internal system controls were compromised.
The Anatomy of Attack: Fake Job Interviews and Malware Distribution
The primary vector enabling this widespread compromise relies on social engineering tactics targeted directly at software engineers and technical staff. Across hundreds of target networks, North Korean operators deployed alluring job offers featuring highly competitive salary packages. Once a target engineer demonstrated interest, the hackers instructed them to complete a technical coding assessment by downloading and executing a software test package.
This routine coding evaluation contained concealed malicious code designed to silently install backdoors and remote access trojans upon execution. Known across the cybersecurity sector as the Contagious Interview campaign, Microsoft threat intelligence tracking indicates that North Korean cyber units have actively refined and executed this lure methodology since at least 2022.
The risk posed by these attacks was significantly amplified by the widespread utilization of external software contractors. In numerous cases analyzed during the investigation, a single compromised contractor held cryptographic keys or active developer credentials giving them administrative access to multiple client companies. Stykas observed individual contractors whose compromised systems maintained active connections to up to 30 distinct corporate networks, dramatically expanding the effective blast radius of a single successful infection.
Focus on Cryptocurrency and Broader National Security Risks
Despite gaining access to networks housing vast repositories of sensitive records, including national healthcare databases and extensive US criminal record archives, North Korean hackers exhibited a strict, hyper-focused operational mandate centered almost exclusively on stealing cryptocurrency assets. Target networks containing non-financial data were frequently left unexploited as operators prioritized locating digital wallets, exchange accounts, and blockchain private keys.
This operational focus aligns with broader strategic intelligence detailing North Korea's state-directed cyber apparatus. According to detailed research published by cybersecurity firm Dtex, the regime operates several hundred elite cyber warfare specialists, often recruited and trained from a young age. These operators are supported by several thousand remote IT workers who secure fraudulent remote employment at legitimate Western and global technology firms to bypass international sanctions and generate mandatory revenue quotas for the state.
Threat intelligence researcher Marcus Hutchins from security firm Expel noted that while cyber teams strictly pursue financial gain to meet state revenue targets, persistent system access creates severe secondary risks. Even if initial operators ignore sensitive corporate data, persistent backdoors allow state espionage units to piggyback on established accesses. If control of an existing foothold is transferred to state intelligence teams, those actors could rapidly exfiltrate sensitive intellectual property, government databases, or critical national infrastructure controls.
The Reality of Modern Cyber Warfare and Corporate Preparedness
What began as an independent side project for Vangelis Stykas has evolved into a full-time threat intelligence effort due to the sheer volume of ongoing attacks. A significant challenge remains hundreds of impacted organizations that have failed to respond to breach notifications or implement necessary security remediations, alongside new victims identified on a daily basis.
“They’re here, they’re hacking us nonstop,” Stykas noted during his Black Hat address. “At the end of the day, everyone's getting hacked. How you treat you being hacked is what separates a good company from a bad company. And we have seen a lot of bad companies.”
The findings underscore an urgent need for enterprises worldwide to tighten third-party contractor vetting, enforce strict zero-trust access controls, and continuously monitor developer environments for unauthorized software execution.



















