LIVE · cybersecurity feed
Live wire
breach

A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide

For nearly two years, researcher Vangelis Stykas has maintained access to North Korean hackers’ servers. His work shows they pulled off intrusions in a shocking number of systems across the globe.

zeroday.news · 3h ago

A cybersecurity researcher has revealed that he maintained access to North Korean hacking infrastructure for nearly two years, uncovering evidence of intrusions into 1,640 organizations across 57 countries. Vangelis Stykas, CTO at Kumio, stated that between 700 and 800 of these intrusions were "really damaging," involving root access to servers, AWS environments, and critical cryptocurrency keys.

Stykas gained access to multiple command-and-control servers used by the North Korean hackers, and in some instances, the attackers inadvertently infected their own workstations, granting him access to their internal communications like Slack and Discord. Over 22 months, he collected approximately 5 terabytes of data, which he used to identify potential victims and disclose the incidents.

Among the organizations publicly named by Stykas at the Black Hat security conference are Boston Children’s Hospital, Japanese tech firm AEON Smart Technology, Chinese phone manufacturer Oppo, cryptocurrency firms Coinbase and Uniswap Labs, Italy’s Supreme Judicial Council, a subsidiary of Saudi Arabian bank Al Rajhi Bank, and Digitaal Vlaanderen, a part of the Flemish Government in Belgium.

Responses from named organizations varied. Japan’s Computer Emergency Response Team confirmed Stykas’s findings and collaborated with AEON Smart Technology on remediation. Digitaal Vlaanderen confirmed a notification on March 3, 2026, leading to the isolation of an affected workstation and revocation of credentials, with the incident deemed contained. Boston Children’s Hospital stated the incident involved a former independent contractor’s personal device, not hospital systems, and that no unauthorized access to their systems was found, with the data at issue already public. Coinbase investigated a contractor and found no evidence of North Korean affiliation, but terminated the contractor due to potential outsourcing risks before Stykas’s tip, confirming no sensitive information or customer data was compromised.

The primary method of attack involved luring software developers with fake job offers and high salaries. Once a target accepted, they were prompted to download a program as a coding test, which secretly installed malware on their machine. This tactic, known as "Contagious Interview," has been documented by Microsoft as early as 2022. Stykas observed that compromised external contractors, who often held developer keys and system access to multiple companies, significantly expanded the potential impact of these attacks, with some contractors having access to up to 30 organizations.

While many compromised firms held highly sensitive data, including health records and criminal records, the North Korean hackers largely focused on acquiring cryptocurrency wallets, often overlooking other systems. However, experts warn that persistent access to corporate networks, even if initially used for crypto theft, could be leveraged by espionage teams for broader intelligence gathering.

North Korea's cyber operations are extensive and adaptable, supporting economic and military development, revenue generation, espionage, and sanctions evasion. The country is believed to employ several hundred skilled cyber operators, alongside thousands of "IT workers" who secure fraudulent remote employment to funnel earnings to the regime. Both groups are reportedly given annual earnings quotas. The scale of these campaigns, with victim lists often numbering in the thousands, is consistent with the broad scope of North Korean hacking activities.

breach
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Canadian man pleads guilty to Snowflake hacks that led to 165 breaches

A 26-year-old from Ontario faces as many as 32 years in prison after pleading guilty to fraud, identity theft and conspiracy charges related to the 2024 hacks of cloud platform Snowflake.

ai

Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages

Elastic Security Labs identified the return of Shai-Hulud. Attackers compromised the keyv maintainer and deployed CHAINDROP, a worm that uses stolen npm credentials to backdoor co-owned packages totaling over 1.3 billion monthly downloads.

ai

AI Sends Global Crime Syndicates Into Fraud Nirvana

Organized crime is convincingly scamming at scale, making billions thanks to AI-enabled voice cloning, deepfake real-time video overlays, LLM-driven persona management, and automated translation.

vulnerability

AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking

Attackers can take control of agents through malicious instructions hidden in content supplied to AI browsers, and there's no simple fix for the threat.

cloud

Canadian pleads guilty to Snowflake cloud data-theft attacks

A Canadian man pleaded guilty today to his role in accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations in a scheme to extort millions of dollars from victims. [...]

vulnerability

Prompt injection isn't the bug, AI agent frameworks are

Check Point researchers tried to break the frameworks enterprises use to build AI apps. Now they're telling Black Hat attendees what they found