Quick Take
  • A Greek security researcher reportedly spent 22 months inside North Korean hacking servers.
  • He came out with a victim list of 1,640 organizations in 57 countries.
  • Vangelis Stykas is chief technology officer at security firm Kumio.
  • He presented the findings this week at Black Hat in Las Vegas.

What Happened

A Greek security researcher reportedly spent 22 months inside North Korean hacking servers. He came out with a victim list of 1,640 organizations in 57 countries.

In some cases he landed on their personal computers. The hackers had infected those machines themselves.

This one counted them from the attackers’ own files. Of the 1,640 organizations, Stykas rates 700 to 800 as seriously breached.

A Job Offer Was the Only Exploit They Needed

“By embedding targeted malware delivery directly into interview tools, coding exercises, and assessment workflows developers inherently trust, threat actors exploit the trust job seekers place in the hiring process,” read an excerpt in a March security blog from Microsoft security blog.

The backdoors then hunt a short shopping list. Microsoft names API tokens, cloud credentials, signing keys, crypto wallets, and password manager files.

Market Context

Vangelis Stykas is chief technology officer at security firm Kumio. He presented the findings this week at Black Hat in Las Vegas.

How the Hunters Became the Hunted

Why It Matters

Stykas turned the usual order around. He worked his way into the command-and-control servers the crews use to run their malware.

Then he simply stayed. For nearly two years he watched them work and logged each new victim as it appeared.

Details

He pulled roughly five terabytes of data. It held developer keys, private source code, and the crews’ own Slack and Discord messages.

That access is why the count is firm. Most threat reports estimate victims from the outside.

Follow us on X to get the latest news as it happens

In those cases the crews held root access to servers, Amazon Web Services (AWS) root permissions, or cryptocurrency wallet keys.

No software flaw opened these doors. A job offer did.

Developers were approached with senior roles and strong pay. They were then asked to run a take-home coding test. The test installed malware.

Palo Alto Networks researchers named the pattern Contagious Interview back in November 2023. Five security firms have since tracked the same crew under six different labels.

Microsoft published its own breakdown in March 2026. It traced the chain to fake code packages hosted on GitHub, GitLab, and Bitbucket.

Opening one in Visual Studio Code triggers a trust prompt. Approve it, and the editor runs the attackers’ code for them.

Hiring is a repeat weak point. Consensys caught a hidden North Korean developer on its own team, a month into work on MetaMask code.

One Contractor, Thirty Front Doors

The lure is cheap. The reach is not.

Stykas found contractors carrying live credentials for as many as 30 companies. A single infected laptop became thirty ways in.

Boston Children’s Hospital shows the pattern. Stykas traced its exposure to a former contractor’s personal device.