Stykas Turns Tables on North Korea, Maps 1,640 Breached Firms
TL;DR
- Greece-based researcher Vangelis Stykas told Black Hat he found 1,640 companies across 57 countries impacted by North Korean hacking operations.
- Around 700 to 800 of those victims suffered 'really damaging' intrusions, including root access to servers, AWS, and cryptocurrency keys.
- Named victims include Coinbase, Uniswap Labs, Oppo, Boston Children's Hospital, and Italy's Supreme Judicial Council, disclosed at Black Hat in Las Vegas.
A Greece-based security researcher walked into Black Hat in Las Vegas this week and said the quiet part out loud: for 22 months he has been sitting inside the infrastructure North Korean operators use to run their intrusions, watching them work. Vangelis Stykas, CTO at cybersecurity firm Kumio, told Wired he counted 1,640 impacted companies across 57 countries, with 700 to 800 of them suffering what he called 'really damaging' intrusions.
The mechanism, as Stykas describes it, is the one the industry has been staring at for the last couple of years. The operators approach software developers with fake, high-paying job offers, then send a coding test that secretly installs malware and hands them the developer's credentials. From there, in Stykas's own words to Wired, it is 'company access, it's root access to servers, it's root access to AWS.' For crypto firms, he added, it's 'keys, it's blockchain access, it's ridiculous access.'
The list of publicly named victims is what makes the scope point land. At Black Hat, Stykas identified around a dozen organizations, including Coinbase, Uniswap Labs, Oppo, Boston Children's Hospital, and Italy's Supreme Judicial Council, largely the ones he says handled the disclosure well or fixed the compromises. Android Authority picked up the Oppo detail in particular, but the through-line is that this is not a crypto-only story anymore. It stretches into consumer hardware, pediatric healthcare, and a European judicial body.
The honest caveat is that almost all of this rests on one researcher's disclosure and one conference talk. Stykas asked Wired not to reveal exactly how he got into the command-and-control servers, and the deep artifacts, the roughly 5 terabytes of stolen data and the attackers' Slack and Discord logs, are described but not published. Take the specifics as reported, not settled. What the reporting also does not give you is a per-victim breakdown of what was actually stolen, how many of those 700 to 800 severe intrusions are still live, or how many of the 1,640 counted companies have even been told.
The forward-looking piece for anyone running a developer-heavy company is that the recruiting funnel is now indistinguishable from the intrusion funnel. If your engineers are running take-home coding tests from strangers on work laptops, or on personal machines that then touch corporate cloud, that is the exposure this talk is really about. The teams that come out of this best will treat candidate code as untrusted input, the same way they treat email attachments.
Shared on Bluesky by 1 AI expert
Originally reported by wired.com
Read the original article →Original headline: Wired: Greek Researcher Hacked North Korean Hackers, Finds 1,640 Companies Across 57 Countries Breached in 22 Months