North Korean Hackers Infiltrate Over 1,640 Companies in Global Crypto Heist
A global network of North Korean hackers has infiltrated over 1,640 companies in 57 countries, according to a cybersecurity researcher who analyzed 5 TB of data.
The campaign, which lasted nearly two years, focused on cryptocurrency companies, targeting private keys, blockchain infrastructure, and crypto wallets. Among the affected organizations were Coinbase, Uniswap Labs, Boston Children's Hospital, and several government entities.
The researcher gained access to command-and-control servers used by North Korean operators, noting that some attackers accidentally infected their own workstations with malware, allowing him to access their systems.
Almost all intrusions followed the 'Contagious Interview' playbook, where hackers posed as well-known companies and offered high-paying jobs, only to install malware on the victim's device. External contractors were particularly vulnerable, as they often had access to multiple corporate environments at once.