Greek Researcher Exposes 22-Month Infiltration of North Korean Hacking Servers
A Greek security researcher infiltrated North Korean hacking servers for approximately 22 months, exposing a campaign that targeted over 1,640 organizations worldwide.
The researcher, whose identity remains undisclosed, gained access to the hacking group's servers and monitored their activities without being detected. During this period, they confirmed that between 700 and 800 of the targeted organizations were seriously compromised, with attackers obtaining root privileges on servers, access to AWS root accounts, and cryptocurrency wallet keys.
The North Korean hackers demonstrated a clear focus on cryptocurrency-related assets, with only minimal interest in sensitive medical records and criminal databases. Instead, they prioritized accessing wallet keys and blockchain access rights, indicating a financial motive behind their operations.