North Korean Hackers Breach Hundreds of Networks Globally

Researcher exposes DPRK hackers’ access to hundreds of global networks

North Korean hackers have breached hundreds of networks worldwide, according to new revelations from a security researcher. These findings shine a light on the extensive scale and persistence of North Korean cyber-espionage, with attacks impacting organisations across numerous sectors globally.

Researcher Uncovers North Korean Hacking Operations

Vangelis Stykas, a security professional, maintained covert access to servers controlled by North Korean hackers over a period of nearly two years. By monitoring these servers, he was able to observe the hackers’ activities in real time and collect evidence of their methods and targets. The operation began in 2021 and continued through early 2023, providing an unprecedented window into the inner workings of a state-backed threat group.

The focus keyword North Korean hackers appears early in the report, underlining the international significance of this campaign. Stykas’s research reveals that these hackers were not just targeting one or two organisations, but had gained access to hundreds of networks across multiple continents. The affected entities span a wide range of industries, although detailed victim information remains confidential to protect those organisations.

How the Intrusions Unfolded: Methods and Targets

The North Korean hackers employed a variety of techniques to achieve their intrusions. According to the research, the attackers leveraged spear-phishing campaigns, malicious document attachments, and exploits against unpatched software vulnerabilities. Once inside a network, they established persistent access, enabling ongoing surveillance and data exfiltration.

Key details from Stykas’s findings include:

  • Access to over 600 internal organisational networks was detected during the research period.
  • Victims included financial institutions, manufacturing firms, government agencies, and technology companies.
  • Evidence suggested both data theft and attempts to move laterally within compromised environments.
  • The attackers used custom tools and legitimate system administration utilities to evade detection.
  • Command and control servers were rotated regularly, complicating efforts to block or track activity.

Stykas’s monitoring provided insights into the day-to-day operations of the threat actors. He observed scripts used to automate credential theft, network reconnaissance, and the extraction of sensitive files. In some cases, the hackers appeared to be searching for financial information or proprietary business data, aligning with previous North Korean cybercrime campaigns.

Timeline and Ongoing Exploitation

The campaign observed by Stykas began in early 2021, with activity continuing well into 2023. Throughout this period, the attackers demonstrated persistence and adaptability, updating their tools and techniques as needed. At no point during these two years did the North Korean group appear to lose access to its key infrastructure, indicating strong operational security on their part.

The research shows that hundreds of organisations remained compromised for extended periods, sometimes months at a time. The attackers’ infrastructure included multiple compromised servers, some of which acted as relays to further obscure their real locations. Stykas’s ongoing access allowed him to see live command inputs and file transfers, giving a detailed picture of the group’s priorities and capabilities.

While some of the compromised organisations eventually detected and removed the intruders, many networks remained vulnerable throughout the monitoring period. The scale of the breaches suggests that the group was operating with significant resources and a clear mandate to obtain valuable data from outside North Korea’s borders.

Why This Matters: Implications for Organisations Worldwide

The discovery that North Korean hackers have breached hundreds of global networks highlights the persistent and far-reaching threat posed by state-backed cyber actors. This campaign demonstrates that organisations of all sizes and sectors are potential targets, regardless of geographic location. The use of advanced intrusion techniques and the ability to maintain long-term access underscores the need for constant vigilance and rapid response to suspicious activity.

The evidence provided by Stykas’s research is a rare and detailed look into North Korea’s cyber-espionage capabilities. It serves as a timely reminder for organisations to regularly assess their security posture and remain alert to the evolving tactics of sophisticated threat groups.

What Organisations Should Do Now

While the technical indicators from this research have not been publicly disclosed, organisations should take immediate steps to:

  • Review user activity logs for signs of unauthorised access or unusual behaviour.
  • Patch critical software vulnerabilities as soon as updates become available.
  • Educate staff on targeted phishing and social engineering threats linked to state actors.

It is also advisable to monitor threat intelligence feeds for updates related to North Korean cyber activity, as further details may emerge from ongoing investigations.

Originally reported by wired.com.

Share this bulletin

About the Author

Rob McBride Headshot - CyPro Partner and leading cyber security expert

Rob McBride

Partner

  • CISSP
  • ACA Chartered Accountant
  • MPhil
  • BSc
  • SOC 2
  • ISO 27001

Rob McBride

Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.

At CyPro, Rob leads the managed service business line, working extensively across multiple sectors including telecommunications, technology, higher education, travel, and retail. He is passionate about equipping small and medium-sized businesses (SMBs) with robust cyber security strategies to fuel their growth.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call