North Korean Hackers Compromise 1,600 Organizations in 57 Countries
Cybersecurity researcher Vangelis Stykas, who infiltrated the infrastructure of a North Korean state‑sponsored hacking group, disclosed that the actors have breached 1,640 companies across 57 nations. Between 700 and 800 of those intrusions were classified as “really damaging,” giving the attackers root‑level access to servers, cloud platforms and cryptocurrency wallets.
The campaign relied on fake remote‑job offers that lured developers into installing malicious code during interview tests, a technique previously documented by Microsoft as “Contagious Interview.” Victims include high‑profile firms such as Coinbase, Uniswap Labs, the Japanese tech firm AEON Smart Technology, Chinese smartphone maker Oppo, and Boston Children’s Hospital, among others. Stykas will detail the findings at the Black Hat conference in Las Vegas, publicly naming a dozen organizations that have responded to the disclosures.
The operation underscores a growing threat to the global tech and financial sectors, where stolen credentials can be used to exfiltrate data, hijack blockchain assets and launch further attacks.
Entities: AEON Smart Technology · Coinbase · North Korean hackers · Oppo · Vangelis Stykas