Over a span of 22 months, Greek cybersecurity expert Vangelis Stikas has uncovered signs of North Korean hackers infiltrating the systems of 1,640 organizations across 57 countries, as reported by WIRED.
Stikas estimates that in 700 to 800 instances, these attacks led to serious compromises of infrastructure. He identified several potentially affected entities, including Coinbase, Uniswap Labs, Boston Children’s Hospital, Japan's AEON Smart Technology, Chinese smartphone manufacturer Oppo, the Italian Supreme Council of the Judiciary, Saudi Arabia's Al Rajhi Bank, and the Flemish government agency Digitaal Vlaanderen.
Most of these incidents have not been independently verified. Some of the mentioned organizations have confirmed isolated incidents, but both Coinbase and Boston Children’s Hospital reported no breaches of their internal systems.
Researcher Accessed Hackers' Servers
Stikas, who is the Chief Technology Officer and co-founder of Kumio, disclosed that he gained access to several command-and-control servers used by the hackers for managing infected devices and collecting stolen information.
He did not reveal the method of his infiltration for security reasons. He noted that in some cases, the hackers compromised their own workstations with malware they developed, which allegedly allowed Stikas to access their channels on Slack and Discord.
According to Stikas, he analyzed about 5 TB of data. He identified potential victims based on discovered developer keys, source code, cloud credentials, and other digital traces. Subsequently, he informed the organizations about the possible compromises.
“This is access to companies, root access to servers and AWS. For crypto companies, it means keys and access to blockchain infrastructure. The level of access is incredible,” Stikas stated.
Organizations Only Confirmed Some Episodes
The Japanese Computer Security Incident Response Team validated Stikas's findings regarding AEON Smart Technology and assisted the company in mitigating the attack's aftermath.
The Flemish government reported that on March 3, 2026, it received a notification from the Belgian Cybersecurity Centre following Stikas's alert. The affected workstation was isolated, and potentially exposed credentials and access keys were revoked and replaced.
Boston Children’s Hospital claimed that the incident involved a personal device of a former independent contractor, not the hospital's infrastructure. Their investigation found no unauthorized access to internal systems, stating that the related data was already publicly available.
Coinbase confirmed that it had hired a short-term contractor from the U.S. for engineering work at the end of 2025. The exchange detected anomalous technical activity in its systems and restricted the contractor's access, terminating the relationship within 30 days. Later, Stikas provided information suggesting a possible link between the contractor and a broader North Korean operation.
Coinbase found no evidence that the contractor was in North Korea or connected to the government. A small amount of code was found in his private repository, but Coinbase deemed it insignificant and unrelated to client data.
Uniswap Labs, Oppo, and several other organizations mentioned did not respond to WIRED's inquiries.
Attacks Started with Fake Interviews
In most of the cases examined, the attackers used fake job offers. They posed as recruiters from cryptocurrency and AI companies. During the interviews, the victims were asked to clone and run an NPM package hosted on GitHub, GitLab, or Bitbucket, which would install a backdoor on their devices.
In newer attacks, hackers have begun using Visual Studio Code workflows. When opening a downloaded project, the editor prompts to trust its author, and upon acceptance, a configuration file can automatically download and execute malicious code.
Microsoft has been tracking such activities since at least December 2022. The corporation found that the tools being used collect API tokens, cloud credentials, signing keys, cryptocurrency wallet materials, and password manager files. Some versions even take screenshots, read the clipboard, and execute remote commands.
Stikas noted that the risk was heightened by contractors who had access to the infrastructure of multiple clients. In one instance, an infected device belonged to a specialist working with approximately 30 organizations.
Cryptocurrencies Are the Main Target
The researcher asserted that the hackers gained access to massive amounts of sensitive information but primarily sought cryptocurrency wallets and associated keys.
Marcus Hutchins, a threat analyst at Expel, told WIRED that he has observed similar campaigns with equally extensive lists of potential victims. He indicated that the focus on digital assets does not preclude the possibility of using the access for espionage or theft of other data.
“It only takes giving access to one person, and they can do practically anything within the system,” Hutchins noted.
In March, the U.S. Treasury's Office of Foreign Assets Control imposed sanctions on six individuals and two companies for facilitating schemes involving North Korean IT workers. According to the agency, such operations netted the North Korean regime nearly $800 million in 2024.
In June, researchers from Cisco Talos reported a new trojan named PylangGhost, which North Korean hackers were spreading through fake interviews targeting cryptocurrency specialists.
Earlier, the Ketman project identified 100 suspected North Korean IT operators working in digital asset-focused companies under false identities. Subsequently, the North Korean Foreign Ministry dismissed the allegations of involvement in cryptocurrency theft as "absurd slander."
