Researcher traces North Korean hacking operation to 1640 companies across 57 countries via Black Hat disclosure, Coinbase Uniswap Boston Childrens Hospital named
Researcher Vangelis Stykas spent 22 months inside a North Korean hacking group's own systems and traced it to 1,640 breached companies in 57 countries, 700 to 800 with serious intrusions. Coinbase, Uniswap Labs and Boston Children's Hospital are among the named targets.
A Greek cybersecurity researcher has pulled back the curtain on one of the largest North Korean hacking operations documented to date. Vangelis Stykas, chief technology officer at the firm Kumio, spent 22 months inside a North Korean hacking group's own command and control infrastructure after the hackers infected their own workstations with their own malware, giving him access to their Slack and Discord channels and roughly 5 terabytes of stolen data. Stykas, who presented his findings at the Black Hat security conference, traced the group's activity to 1,640 companies across 57 countries, with 700 to 800 of those experiencing intrusions he described as seriously damaging. Named victims include Coinbase, Uniswap Labs, Boston Children's Hospital and the smartphone maker Oppo, though Boston Children's Hospital disputes that its own systems were breached and says the issue traced back to a former contractor's personal device. The group's primary infiltration method, tracked by Microsoft since 2022 under the name Contagious Interview, lures software developers and contractors with fake job offers, then asks them to download a coding test that secretly installs malware. The hackers have focused mainly on stealing cryptocurrency and gaining root-level server access rather than broader espionage. The scale of the exposure shows how thoroughly North Korea's state-linked hacking groups have infiltrated software supply chains through routine hiring processes, a vector that is far harder for companies to screen against than a traditional phishing email.