North Korean Hackers Focus on Crypto Theft After Infiltrating Thousands of Orgs
A Greek security researcher infiltrated North Korean hacking group's internal servers for nearly two years and found that their primary focus was on cryptocurrency theft.
The researcher spent about 22 months tracking the group's operations and discovered that they had targeted over 1,640 organizations, with around 700 to 800 being severely compromised.
The hackers gained access to sensitive information, including server root access, AWS root accounts, and crypto wallet keys for companies like Coinbase and Uniswap Labs.
Interestingly, the researcher found that despite having access to medical records and criminal databases, the North Korean hackers largely left these untouched in favor of targeting cryptocurrencies.