Greek Researcher Infiltrates North Korea's Hacking Infrastructure, Uncovers Thousands of Compromised Companies
A Greek security researcher spent nearly two years secretly inside North Korea's hacking infrastructure, uncovering 1,640 compromised companies across 57 countries.
Vangelis Stykas, CTO of Kumio, discovered this after gaining access to North Korean command-and-control servers through a mistake made by the hackers themselves, they had infected their own workstations with malware, providing Stykas with an entry point.
Stykas watched the hackers' internal chatter and pulled 5 terabytes of stolen data from their servers. He found that around 700-800 organizations suffered 'really damaging intrusions,' including root-level access to servers, AWS environments, and cryptocurrency wallets.
Notable victims include Coinbase, Uniswap Labs, Boston Children's Hospital, Oppo, AEON Smart Technology, Al Rajhi Bank, Italy's Supreme Judicial Council, and the Belgian government IT agency Digitaal Vlaanderen. Stykas' findings indicate that North Korean hacking crews often cut corners, making it easier for outside researchers to track their activities.