A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide

← Back to the feed

A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide

Wired · 2 hours ago

A Greek cybersecurity researcher, Vangelis Stykas, has spent nearly two years covertly inside systems used by North Korean state hackers, uncovering evidence that their operations have compromised 1,640 companies across 57 countries. Stykas, CTO of cybersecurity firm Kumio, is presenting his findings at the Black Hat security conference in Las Vegas, warning that the scale of infiltration via targeted employees and contractors is far greater than previously understood. The disclosure highlights how North Korea's hacking units, which fund the regime's weapons programmes partly through stolen data and cryptocurrency, have achieved deep, damaging access to a wide range of global organisations.

Of the affected companies, Stykas estimates 700 to 800 suffered "really damaging" intrusions, including root access to servers and AWS accounts, and in crypto firms, access to keys and blockchain systems. He gained his access via the hackers' own command-and-control servers, in some cases exploiting the fact the hackers had infected themselves with their own malware, giving him visibility into their Slack and Discord communications and around five terabytes of data. He is publicly naming roughly a dozen organisations that handled disclosure well, including Boston Children's Hospital, AEON Smart Technology, Oppo, Coinbase, Uniswap Labs, Italy's Supreme Judicial Council, a Al Rajhi Bank subsidiary, and Belgium's Digitaal Vlaanderen, several of which have confirmed remediation efforts.

  • Researcher infiltrated North Korean hacker systems for nearly two years
  • Found 1,640 companies in 57 countries impacted, 700-800 severely
  • Named a dozen firms including Coinbase, Oppo and Boston Children's Hospital

Asia Cybersecurity Technology World

Read the full article at the source →