Currencies38403
Market Cap$ 2.27T-0.67%
24h Spot Volume$ 21.88B+0.95%
DominanceBTC56.75%-0.11%ETH10.10%+0.35%
ETH Gas0.10 Gwei
Cryptorank
/

Researcher ‘Lives’ Among North Korean Hackers, Discovers 1,640 Victims

Researcher ‘Lives’ Among North Korean Hackers, Discovers 1,640 Victims

Share:

AI Overview

A Greek researcher spent 22 months inside North Korean hacker servers and logged 1,640 victim organizations across 57 countries, rating 700-800 as serious breaches and extracting five terabytes of data including developer keys and crypto wallet credentials. Attackers used fake job offers and poisoned coding tests to harvest API tokens, cloud credentials and wallet keys, contributing to DPRK-linked thefts of $2.02 billion in 2025 and over $6 billion since 2017 (including April's $285 million Drift Protocol DeFi loss), prompting CEXs, DEXs and security groups like Crypto ISAC to coordinate threat intelligence and remediation.

Bearish

Predictions Markets

See what traders are focused on

View analytics →
Prediction Banner

In Brief

  • A researcher spent 22 months inside North Korean hacker servers.
  • His logs name 1,640 breached organizations across 57 countries.
  • Some contractors held live credentials for as many as 30 firms.

A Greek security researcher reportedly spent 22 months inside North Korean hacking servers. He came out with a victim list of 1,640 organizations in 57 countries.

Vangelis Stykas is chief technology officer at security firm Kumio. He presented the findings this week at Black Hat in Las Vegas.

How the Hunters Became the Hunted

Stykas turned the usual order around. He worked his way into the command-and-control servers the crews use to run their malware.

In some cases he landed on their personal computers. The hackers had infected those machines themselves.

Then he simply stayed. For nearly two years he watched them work and logged each new victim as it appeared.

He pulled roughly five terabytes of data. It held developer keys, private source code, and the crews’ own Slack and Discord messages.

That access is why the count is firm. Most threat reports estimate victims from the outside.

This one counted them from the attackers’ own files. Of the 1,640 organizations, Stykas rates 700 to 800 as seriously breached.

Follow us on X to get the latest news as it happens

In those cases the crews held root access to servers, Amazon Web Services (AWS) root permissions, or cryptocurrency wallet keys.

A Job Offer Was the Only Exploit They Needed

No software flaw opened these doors. A job offer did.

Developers were approached with senior roles and strong pay. They were then asked to run a take-home coding test. The test installed malware.

Palo Alto Networks researchers named the pattern Contagious Interview back in November 2023. Five security firms have since tracked the same crew under six different labels.

Microsoft published its own breakdown in March 2026. It traced the chain to fake code packages hosted on GitHub, GitLab, and Bitbucket.

Opening one in Visual Studio Code triggers a trust prompt. Approve it, and the editor runs the attackers’ code for them.

“By embedding targeted malware delivery directly into interview tools, coding exercises, and assessment workflows developers inherently trust, threat actors exploit the trust job seekers place in the hiring process,” read an excerpt in a March security blog from Microsoft security blog.

The backdoors then hunt a short shopping list. Microsoft names API tokens, cloud credentials, signing keys, crypto wallets, and password manager files.

Hiring is a repeat weak point. Consensys caught a hidden North Korean developer on its own team, a month into work on MetaMask code.

One Contractor, Thirty Front Doors

The lure is cheap. The reach is not.

Stykas found contractors carrying live credentials for as many as 30 companies. A single infected laptop became thirty ways in.

Boston Children’s Hospital shows the pattern. Stykas traced its exposure to a former contractor’s personal device.

The hospital disputes the framing. It says it cut the credentials within hours and found no sign its own systems were entered.

The crews were also picky. They could reach health records and criminal databases, yet ignored both.

They went for wallets and blockchain access instead. Coinbase and Uniswap Labs sit among the organizations that acted on his warnings.

That discipline shows up in the totals. Crews tied to the Democratic People’s Republic of Korea (DPRK) stole a reported $2.02 billion in digital assets during 2025.

CrowdStrike logged that as a 51% jump in one year. It also flags a crew it calls GOLDEN CHOLLIMA for using recruitment lures to reach fintech cloud environments.

That is the chain Stykas watched from the inside. The human route keeps winning.

TRM Labs traced April’s $285 million Drift Protocol theft to in-person meetings between North Korean proxies and staff.

Two attacks produced 76% of 2026 losses from just 3% of incidents. Pyongyang’s running total now clears $6 billion since 2017.

Stykas says fresh victims are still surfacing in the data. Most organizations he warned never wrote back, which is why groups like Crypto ISAC now pool DPRK threat intelligence instead.

Read the article at BeInCrypto
Read the article at BeInCrypto

In This News

Predictions Markets

See what traders are focused on

View analytics →
Prediction Banner

Share:

In This News

Predictions Markets

See what traders are focused on

View analytics →
Prediction Banner

Share:

Read More

Crypto Wealth Draws Violence as Attackers Seize $30 Million in 2026

Crypto Wealth Draws Violence as Attackers Seize $30 Million in 2026

In Brief Violent crypto attacks stole an estimated $30 million-plus in first-half 20...
AI Agent Faked Identities to Push Malicious Code During Cyber Test, AISI Finds

AI Agent Faked Identities to Push Malicious Code During Cyber Test, AISI Finds

In Brief Anthropic's Mythos 5 created fake identities to push malicious code during ...