A Security Pro Hacked North Korean Hackers. He Found Theyâd Breached Hundreds of Networks Worldwide
For years, North Koreaâs stealthy hackers and scam IT workers have infiltrated companies, stealing corporate secrets and plundering billions in cryptocurrency to help fund the
For years, North Koreaâs stealthy hackers and scam IT workers have infiltrated companies, stealing corporate secrets and plundering billions in cryptocurrency to help fund the totalitarian regime and its weapons programs. Now, a security researcher who has spent almost two years inside the systems belonging to a group of those North Korean hackers is raising the alarm on just how effective and far reaching the targeting of individual employees and contractors has been in breaching organizations across the globe. Since Greece-based cybersecurity researcher Vangelis Stykas gained access to North Korean systems 22 months ago, he says, he has found evidence that 1,640 companies across 57 countries have been impacted by the countryâs hacking operations. Among these, Stykas will detail at the Black Hat security conference in Las Vegas today, around 700 to 800 of the impacted organizations have had âreally damagingâ intrusions. âItâs company access, itâs root access to servers, itâs root access to AWS,â the researcher tells WIRED, referring to Amazon Web Services and the term ârootâ to mean the highest level of permissions in a computer system.
âFor crypto companies, itâs keys, itâs blockchain accessâitâs ridiculous access.â Stykas, the CTO at cybersecurity firm Kumio, says he accessed multiple command-and-control servers used by the hackers, though he asked WIRED not to reveal the details of how he gained that access due to the sensitivity of that information. In some cases, he notes, the hackers appeared to have infected themselves with their own malwareâwhich, as a result, gave him access to the hackersâ workstations, too. âI have access to their Slack, I have access to their Discord, I have access to a lot of stuff,â Stykas says, adding he has seen around 5 terabytes of data in total. As he probed those systems over months, Stykas identified potential victimsâby analyzing developer keys, source code, and moreâand says he has disclosed the incidents to those impacted. As part of his talk at Black Hat, Stykas is publicly naming around a dozen of the impacted companiesâthese are, he says, largely the ones that handled the disclosures well and/or fixed possible compromises. The researcher says these include the Boston Childrenâs Hospital (which held a vast Covid-19 database of Americansâ personal health data), the large Japanese tech firm AEON Smart Technology, Chinese phone manufacturer Oppo, cryptocurrency firms Coinbase and Uniswap Labs, Italyâs Supreme Judicial Council, a subsidiary of Saudi Arabian bank Al Rajhi Bank, and Digitaal Vlaanderen, part of the Flemish Government in Belgium.
