North Korean Hackers Infiltrated 1,600+ Companies Globally via Fake Job Offers, Researcher Reveals
A cybersecurity researcher has uncovered a massive campaign by North Korean state-sponsored hackers, compromising over 1,600 companies across 57 countries. Leveraging sophisticated social engineering tactics, particularly fake job offers, these threat actors gained deep access to corporate networks, primarily targeting cryptocurrency assets but posing significant espionage risks.
For years, **North Korea's** clandestine cyber operations have been a persistent threat, with state-sponsored hackers and fraudulent IT workers siphoning billions in cryptocurrency and corporate secrets to bolster the regime's illicit funding and weapons programs. Now, a deep dive by a security researcher reveals the sheer scale and effectiveness of their targeting of individual employees and contractors in breaching organizations worldwide.
**Vangelis Stykas**, a Greece-based cybersecurity researcher and CTO at **Kumio**, has spent 22 months embedded within the systems of a North Korean hacking group. His investigation, detailed at the **Black Hat** security conference in Las Vegas, exposes evidence of 1,640 companies impacted across 57 countries. Of these, an estimated 700 to 800 organizations suffered "really damaging" intrusions.
"Itβs company access, itβs root access to servers, itβs root access to **AWS**," Stykas told WIRED, referring to **Amazon Web Services** and the highest level of system permissions. "For crypto companies, itβs keys, itβs blockchain accessβitβs ridiculous access."
### Unprecedented Access and Data Volume
Stykas gained access to multiple command-and-control servers used by the hackers. Intriguingly, in some instances, the hackers inadvertently infected their own workstations with their malware, providing Stykas with a direct window into their operations. "I have access to their **Slack**, I have access to their **Discord**, I have access to a lot of stuff," he stated, revealing he has observed approximately 5 terabytes of data.
Over months, Stykas meticulously identified potential victims by analyzing developer keys, source code, and other artifacts. He asserts that he has disclosed these incidents to the affected parties. At Black Hat, he publicly named a dozen organizations that handled disclosures effectively or remediated compromises.
Notable entities include **Boston Childrenβs Hospital** (which held a vast COVID-19 database), Japanese tech firm **AEON Smart Technology**, Chinese phone manufacturer **Oppo**, cryptocurrency giants **Coinbase** and **Uniswap Labs**, Italyβs **Supreme Judicial Council**, a subsidiary of Saudi Arabian bank **Al Rajhi Bank**, and **Digitaal Vlaanderen**, part of the Flemish Government in Belgium.
### Responses from Affected Organizations
**Japanβs Computer Emergency Response Team** confirmed Stykas's findings and collaborated with **AEON Smart Technology** on remediation. A spokesperson for the Flemish government confirmed notification and stated, "the affected workstation was isolated and the potentially exposed credentials and access were revoked and rotated. Based on our investigation, the incident has been contained and remediated."
**Boston Childrenβs Hospital** clarified that the incident involved a former independent contractor's personal device, not hospital systems, and that "no evidence of unauthorized access to Boston Children's systems" was found. They added that the "data at issue" was already publicly available.
**Coinbase** stated they investigated a contractor, found no evidence of affiliation with the **DPRK** (Democratic Peopleβs Republic of Korea) government, but identified "potential risks in their technology setup," suggesting third-party outsourcing. The contractor was terminated, and **Coinbase** asserted that "no sensitive information was compromised and no customer data was exposed."
### The 'Contagious Interview' Tactic
While many of the compromised companies held highly sensitive dataβincluding one U.S. firm with access to Americans' criminal recordsβthe hackers largely maintained a laser focus on cryptocurrency wallets, often ignoring other systems. This strategic prioritization, however, should not be a source of comfort, as experts warn.
Almost all of these intrusions stemmed from a well-documented tactic: luring software developers with fake job offers promising inflated salaries. Once a target engaged, they were prompted to download a seemingly innocuous program for a coding test, which silently installed malware. **Microsoft** has tracked this fake interview technique in a broader campaign known as **Contagious Interview** since at least 2022.
Stykas highlighted the amplified risk posed by external contractors. "I have seen a couple of contractors that had access to up to 30 companies," he explained, underscoring how a single compromised individual could significantly expand a breach's blast radius.
### North Korea's Evolving Cyber Threat
**Dtex**, a cybersecurity firm, published a report last year detailing the sprawling and fluid nature of North Korea's cyber operations. The regime reportedly employs several hundred skilled cyber operators, trained from a young age, alongside thousands of so-called "IT workers" who secure fraudulent remote employment to funnel earnings back to the sanctioned state. Both groups are reportedly subject to yearly earnings quotas.
**Marcus Hutchins**, a threat intelligence researcher at **Expel**, who has tracked similar campaigns, was unsurprised by the scope. He noted a similar focus on crypto theft but cautioned against complacency. "It seems like the teams tend to stick to their task of getting crypto wallets. But thereβs obviously the risk that if theyβre maintaining persistent access to a corporation, one of the espionage teams could then piggyback off that access," Hutchins warned. "All it would take is for one person to get given access to that system, and they could just go to town."
Stykas's ongoing efforts underscore a critical concern: the hundreds of companies that have not responded to his warnings, and the new victims added daily. "This started as a side project, and right now it's my full-time job," he said.
"Theyβre here, theyβre hacking us nonstop," Stykas concluded. "At the end of the day, everyone's getting hacked. How you treat you being hacked is what separates a good company from a bad company. And we have seen a lot of bad companies."