A Greece-based cybersecurity researcher, Vangelis Stykas, has revealed that North Korean state-linked hackers breached 1,640 companies across 57 countries, after he spent 22 months infiltrating the attackers' own systems and found they had unwittingly infected themselves with their own malware.
That self-infection gave Stykas access to the hackers' workstations, Slack and Discord communications, and roughly 5 terabytes of stolen data, which he used to map the scope of the campaign. He presented the findings at the Black Hat security conference in Las Vegas, describing a breach operation significantly larger than previously documented.
Crypto firms among the confirmed victims
Stykas identified Coinbase and Uniswap Labs among the affected organizations, alongside Boston Children's Hospital and Chinese smartphone maker OPPO. Of the 1,640 companies impacted, between 700 and 800 suffered what Stykas characterized as "really damaging" intrusions, with attackers gaining what he described as full company access — "root access to servers, it's root access to AWS."
Related: Active Bitcoin Addresses Hit 18-Month High as Coldcard Exploit Drives Mass Wallet Migration
The fake-job-interview playbook
The attackers' primary entry method relied on fake software developer job interviews, tricking targets — often engineers with access to sensitive infrastructure — into installing malware disguised as technical assessments or coding tools. That tactic has become one of North Korea's signature approaches to targeting crypto and tech firms specifically, since engineering hires at those companies frequently hold direct access to hot wallets, private keys, or production systems that traditional corporate breaches rarely reach.
The revelation adds a rare inside view to a threat that crypto security firms have warned about for years but have struggled to quantify with this level of specificity, given how deliberately North Korean operators cover their tracks after high-value intrusions.