North Korean cyber operators have successfully compromised 1,640 organizations across 57 countries, according to a cybersecurity researcher who spent nearly two years secretly infiltrating the hackers’ own infrastructure, uncovering one of the most extensive pictures yet of Pyongyang’s global cyber operations. The findings were presented by Vangelis Stykas, a Greece-based cybersecurity researcher and founder of Atropos.ai, who said he gained access to command-and-control systems used by North Korean hacking groups and collected approximately 5 terabytes of internal data over a 22-month period. His investigation revealed evidence that 1,640 companies had been breached, with an estimated 700 to 800 organizations suffering what he described as “really damaging” intrusions involving administrator-level access to servers, cloud infrastructure and cryptocurrency wallets.
The compromised organizations span 57 countries and include businesses across the technology, healthcare, finance, telecommunications and cryptocurrency sectors. According to Stykas, North Korean operators frequently obtained access by targeting software developers through fraudulent recruitment campaigns known as “Contagious Interview”, where victims were lured into fake job interviews and tricked into running malware disguised as coding assignments. Several high-profile organizations—including Coinbase, Uniswap Labs, Boston Children’s Hospital, Oppo and AEON Smart Technology—were either directly affected or exposed through contractors whose compromised devices provided attackers with access to corporate environments.
Developers Become the Primary Attack Vector
Rather than exploiting corporate networks directly, North Korean groups increasingly target individual developers. The investigation found that many victims were freelance engineers or contractors who held privileged access to multiple organizations simultaneously. Once malware infected a developer’s workstation, attackers could leverage those credentials to pivot into several companies, dramatically amplifying the scale of each compromise. Researchers said many of the intrusions resulted in root-level access to production servers, cloud infrastructure and source code repositories. In cryptocurrency-related companies, attackers also sought access to private keys, hot wallets and blockchain infrastructure, consistent with North Korea’s long-running strategy of using cybercrime to generate revenue for the regime.
The campaign forms part of a broader pattern documented by governments and private cybersecurity firms. North Korean cyber units have increasingly combined malware operations with fraudulent remote employment schemes, fake identities and software supply-chain attacks to infiltrate Western organizations. US authorities estimate that these operations generate hundreds of millions of dollars annually for Pyongyang while also supporting espionage objectives.
Scale Highlights Growing Supply-Chain Risk
The newly disclosed figures suggest North Korea’s cyber campaign has become considerably broader than previously understood. While cryptocurrency theft remains a primary objective, Stykas warned that many compromised organizations may still contain persistent backdoors capable of supporting future espionage or ransomware operations. The researcher noted that some victims remained unaware they had been breached until informed during his investigation.
The findings also underscore the growing cybersecurity risks associated with globally distributed software development teams. As companies increasingly rely on remote employees and third-party contractors, attackers have shifted toward compromising trusted individuals rather than attempting to breach heavily defended corporate networks directly. Cybersecurity experts recommend strengthening developer security through hardware-backed authentication, privileged access controls, continuous endpoint monitoring and enhanced verification of recruitment processes, particularly for engineering roles targeted by fake job campaigns.
For governments and enterprises alike, the investigation illustrates the expanding sophistication of North Korea’s cyber capabilities. Rather than isolated cryptocurrency thefts, the evidence points to a coordinated global operation capable of infiltrating hundreds of organizations simultaneously through trusted software developers, reinforcing concerns that cyber operations have become one of the regime’s most effective tools for generating revenue and gathering intelligence.
