North Korean hackers have breached hundreds of networks worldwide, according to new revelations from a security researcher. These findings shine a light on the extensive scale and persistence of North Korean cyber-espionage, with attacks impacting organisations across numerous sectors globally.
Researcher Uncovers North Korean Hacking Operations
Vangelis Stykas, a security professional, maintained covert access to servers controlled by North Korean hackers over a period of nearly two years. By monitoring these servers, he was able to observe the hackers’ activities in real time and collect evidence of their methods and targets. The operation began in 2021 and continued through early 2023, providing an unprecedented window into the inner workings of a state-backed threat group.
The focus keyword North Korean hackers appears early in the report, underlining the international significance of this campaign. Stykas’s research reveals that these hackers were not just targeting one or two organisations, but had gained access to hundreds of networks across multiple continents. The affected entities span a wide range of industries, although detailed victim information remains confidential to protect those organisations.
How the Intrusions Unfolded: Methods and Targets
The North Korean hackers employed a variety of techniques to achieve their intrusions. According to the research, the attackers leveraged spear-phishing campaigns, malicious document attachments, and exploits against unpatched software vulnerabilities. Once inside a network, they established persistent access, enabling ongoing surveillance and data exfiltration.
Key details from Stykas’s findings include:
- Access to over 600 internal organisational networks was detected during the research period.
- Victims included financial institutions, manufacturing firms, government agencies, and technology companies.
- Evidence suggested both data theft and attempts to move laterally within compromised environments.
- The attackers used custom tools and legitimate system administration utilities to evade detection.
- Command and control servers were rotated regularly, complicating efforts to block or track activity.
Stykas’s monitoring provided insights into the day-to-day operations of the threat actors. He observed scripts used to automate credential theft, network reconnaissance, and the extraction of sensitive files. In some cases, the hackers appeared to be searching for financial information or proprietary business data, aligning with previous North Korean cybercrime campaigns.
Timeline and Ongoing Exploitation
The campaign observed by Stykas began in early 2021, with activity continuing well into 2023. Throughout this period, the attackers demonstrated persistence and adaptability, updating their tools and techniques as needed. At no point during these two years did the North Korean group appear to lose access to its key infrastructure, indicating strong operational security on their part.
The research shows that hundreds of organisations remained compromised for extended periods, sometimes months at a time. The attackers’ infrastructure included multiple compromised servers, some of which acted as relays to further obscure their real locations. Stykas’s ongoing access allowed him to see live command inputs and file transfers, giving a detailed picture of the group’s priorities and capabilities.
While some of the compromised organisations eventually detected and removed the intruders, many networks remained vulnerable throughout the monitoring period. The scale of the breaches suggests that the group was operating with significant resources and a clear mandate to obtain valuable data from outside North Korea’s borders.
Why This Matters: Implications for Organisations Worldwide
The discovery that North Korean hackers have breached hundreds of global networks highlights the persistent and far-reaching threat posed by state-backed cyber actors. This campaign demonstrates that organisations of all sizes and sectors are potential targets, regardless of geographic location. The use of advanced intrusion techniques and the ability to maintain long-term access underscores the need for constant vigilance and rapid response to suspicious activity.
The evidence provided by Stykas’s research is a rare and detailed look into North Korea’s cyber-espionage capabilities. It serves as a timely reminder for organisations to regularly assess their security posture and remain alert to the evolving tactics of sophisticated threat groups.
What Organisations Should Do Now
While the technical indicators from this research have not been publicly disclosed, organisations should take immediate steps to:
- Review user activity logs for signs of unauthorised access or unusual behaviour.
- Patch critical software vulnerabilities as soon as updates become available.
- Educate staff on targeted phishing and social engineering threats linked to state actors.
It is also advisable to monitor threat intelligence feeds for updates related to North Korean cyber activity, as further details may emerge from ongoing investigations.
Originally reported by wired.com.





