A researcher observed North Korean hackers from the inside for two years. What did he learn?

cryptonews.ruPubblicato 2026-08-09Pubblicato ultima volta 2026-08-09

Introduzione

Greek cybersecurity researcher Vangelis Stykas spent nearly 22 months infiltrating the infrastructure of a North Korean-linked hacker group, revealing his findings at Black Hat USA 2026. He accessed the group's internal systems after the operators infected their own workstations with the same malware used against targets. His access yielded data on 1,640 targeted companies across 57 countries, with 700-800 suffering serious breaches, including Coinbase and Uniswap Labs. This period coincided with record crypto thefts by North Korean actors, who stole an estimated $643 million in the first half of 2026—about 66% of global losses from hacks and exploits. Two major April attacks on Drift Protocol and KelpDAO accounted for most of these funds. Cumulative thefts since 2017 are estimated at over $6.75 billion, with proceeds funding weapons programs and sanctions evasion. The group's tactics have shifted towards sophisticated social engineering, such as posing as recruiters to trick developers into installing malware, rather than attacking blockchain protocols directly. Despite their advanced capabilities, the incident where operators infected their own machines highlights lapses in their operational security, creating vulnerabilities that researchers or rival intelligence agencies could exploit.

Greek cybersecurity specialist Vangelis Stykas, CTO of the company Kumio, observed the work of a DPRK-linked hacking group from inside its own infrastructure for almost 22 months. He reported this on August 6-7 at the Black Hat USA 2026 conference.

Stykas discovered data on 1,640 companies in 57 countries that were on the group's target list or had already been affected by it. Of these, about 700–800 organizations suffered serious intrusions — the attackers gained root access to servers, AWS infrastructure, and in the case of crypto companies — also to wallet keys. Among the publicly named victims:

  • Coinbase
  • Uniswap Labs
  • Boston Children's Hospital
  • Oppo
  • AEON Smart Technology

The researcher gained access to the hackers' communications and servers largely by chance: the group's operators infected their own workstations with the same malware used to attack victims. This opened the way for Stykas to their C2 servers, Slack and Discord accounts, and about 5 TB of internal data.

Record losses in the first half of the year

Stykas's surveillance coincided with the publication of data on the record scale of North Korean crypto-hacking. According to a TRM Labs report from July 1, 2026, in the first half of the year, DPRK-linked hackers stole about $643 million in cryptocurrency — roughly 66% of the total amount stolen globally in hacks and exploits during that period. The industry's total losses for the half-year amounted to $972 million across 207 recorded incidents.

Almost all of North Korea's haul came from two major attacks in April 2026 — on Drift Protocol (about $285 million) and on KelpDAO (about $292 million). At the same time, TRM Labs emphasizes: these figures only account for direct hacks and exploits. In addition to these, the DPRK obtains cryptocurrency through phishing, social engineering, fraudulent schemes and scams, as well as by having its IT specialists employed under false identities in Western companies.

Analytical platforms estimate the cumulative volume of cryptocurrency stolen by North Korean hackers since 2017 at approximately $6.75 billion as of the end of 2025 — taking into account 2026 operations, this sum has grown even larger.

Tactical shift: betting on people, not on code

The main attack method is increasingly becoming social engineering against company employees, rather than hacking the protocol itself. Hackers linked to the Lazarus group and related structures pretend to be recruiters, offer developers high-paying remote work, and send a "test task". Once the victim downloads and runs the file on their work computer, malware is installed on the device, opening access to corporate infrastructure, keys, servers, and wallets — after which the funds are withdrawn. This scenario was used, in particular, in the multi-month campaign against Drift Protocol and in Operation Contagious Interview.

The combination of TRM Labs data and Stykas's findings shows that over recent years, North Korean operators have built an infrastructure covering hundreds of companies worldwide — from crypto exchanges and DeFi protocols to electronics manufacturers and medical institutions. The main blow, however, is not against technical vulnerabilities in blockchains, but against employees' trust in seemingly legitimate job offers.

AI Opinion

From the perspective of macroeconomic connections, Stykas's investigation appears as part of a broader picture. The stolen crypto-assets do not settle in the hackers' private accounts — the U.S. State Department confirmed back in January 2026 that proceeds from such operations are systematically directed towards weapons programs and circumventing UN sanctions. A technical aspect left out of the article is the resilience of the Lazarus infrastructure itself: the infection of the operators' own workstations with the same malware indicates a lack of internal cyber hygiene even within an advanced group. This creates a window of vulnerability that the researcher exploited, but which competing intelligence could theoretically also exploit. The question remains open: for how long will such "accidental" slip-ups remain the only way to peer inside the North Korean hacking machine?

end-content

Domande pertinenti

QHow did the Greek cybersecurity researcher Vangelis Stykas gain access to the North Korean hackers' internal infrastructure?

AHe gained access largely by chance. The operators of the hacking group infected their own workstations with the same malware they used to attack victims. This opened a path for Stykas to their C2 servers, Slack and Discord accounts, and approximately 5 TB of internal data.

QAccording to the TRM Labs report cited in the article, what was the estimated value of cryptocurrency stolen by North Korean-linked hackers in the first half of 2026?

AAccording to the TRM Labs report from July 1, 2026, North Korean-linked hackers stole about $643 million in cryptocurrency in the first half of 2026.

QWhat is the primary attack method increasingly used by North Korean-linked hackers, as described in the article?

AThe primary method is increasingly social engineering attacks against company employees, rather than hacking the protocol itself. Hackers pose as recruiters offering high-paying remote jobs and send 'test tasks' containing malware.

QWhich two major attacks in April 2026 accounted for nearly all of North Korea's cryptocurrency theft in the first half of 2026?

AThe two major attacks were on Drift Protocol (about $285 million) and on KelpDAO (about $292 million).

QWhat does the article suggest about the ultimate use of the cryptocurrency stolen by North Korean hackers?

AThe article states, citing the U.S. State Department, that the proceeds from these operations are systematically directed towards weapons programs and circumventing UN sanctions.

Letture associate

AMD acquires Taalas: hardware AI manages without scarce HBM memory

AMD has agreed to acquire Toronto-based startup Taalas, which tackles a key bottleneck in AI inference: the constant need to transfer model weights from memory to the processor for each generated token. Taalas's chips eliminate this operation by permanently embedding the model weights into the transistors themselves. This data transfer is what currently limits inference speed and has made high-bandwidth memory (HBM) a scarce commodity. Taalas's first test chip, fabricated on TSMC's 6nm process, reportedly generated tokens for Meta's Llama 3.1 8B model at speeds 48 times faster than comparable Nvidia GPUs. Its architecture features a mask ROM section for fixed weights and SRAM for adaptable components. However, this design comes with a significant trade-off: each chip is permanently dedicated to a single model. Switching models requires a partial redesign and fabrication, a process taking about two months. While the acquisition is seen as part of AMD's rivalry with Nvidia in inference, its broader implication lies in challenging the assumption of a permanent HBM memory shortage. The AI memory market is currently booming, with HBM supply sold out through 2026. Yet, Taalas's technology demonstrates that the memory bottleneck is an engineering challenge, not an absolute physical constraint. This aligns with industry-wide efforts from companies like Nvidia (through model compression) and memory makers like Samsung and SK hynix (developing new packaging and storage technologies) to reduce dependency on scarce HBM. AMD's move suggests that the current high prices for memory, driven by AI demand, may not be sustainable. It highlights a growing engineering push against the premise of perpetual memory scarcity, reminding investors that memory has historically been a cyclical business.

cryptonews.ru49 min fa

AMD acquires Taalas: hardware AI manages without scarce HBM memory

cryptonews.ru49 min fa

Vance says US-Iran conflict remains in 'midgame', US military 'seeks exit', Iran sets 'six conditions for reopening the strait'

U.S. Vice President Vance described the U.S.-Iran conflict as being in the "mid-game," stating the U.S. is utilizing diplomatic, economic, and military tools, with a focus on increasing oil and gas shipments through the Strait of Hormuz. Meanwhile, U.S. Chairman of the Joint Chiefs of Staff Gen. Dan Caine is reportedly seeking an "exit" privately, expressing concerns that airstrikes alone are insufficient to achieve objectives and that further escalation carries significant risks. He highlighted critical ammunition shortages for key missile defense systems. In response, Iran’s Supreme National Security Council Secretary, Zolgadr, presented six conditions for reopening the Strait of Hormuz: a U.S. pledge never to threaten Iran, an end to aggression against Iran and its allies, withdrawal of forces from the region, war reparations, lifting of all sanctions, and the unconditional unfreezing of Iranian assets. These demands, seen as a high bar set by hardliners, contrast with more pragmatic requests made in backchannel talks, which focus on lifting the blockade, restoring oil sanctions waivers, and accessing frozen funds. While Iran and Oman are close to a technical agreement on a temporary shipping lane, Iran clarified this does not equate to a full reopening of the strait, which remains contingent on U.S. meeting its conditions. Attacks on commercial vessels in the area continue, with recent incidents attributed to Iran. Despite pauses in military action and expressions of openness to talks from both sides, negotiations are currently stalled over Iran's economic demands and U.S. insistence on freedom of navigation.

marsbit1 h fa

Vance says US-Iran conflict remains in 'midgame', US military 'seeks exit', Iran sets 'six conditions for reopening the strait'

marsbit1 h fa

$20k Signing Fee + $30k Monthly Salary: The Story Behind Pump.fun Poaching FOMO's Corner

The meme market has become increasingly fragmented, with a significant divide between overseas and Chinese users in terms of ecosystem and trading tools. Recently, a piece of gossip spread within overseas meme communities: Pump.fun, the largest token launch platform, is allegedly offering lucrative incentives to poach users from its competitor FOMO. According to a leaked agreement, eligible users are reportedly offered a one-time $20,000 signing bonus plus a $30,000 monthly salary to migrate their funds and trading activity exclusively to Pump.fun, close their FOMO accounts, and meet specific trading volume requirements. This aggressive move highlights FOMO's rapid rise. Launched just over a year ago, FOMO has secured $94 million in funding and, crucially, its revenue over the past 30 days has surpassed that of Uniswap and Phantom. Its market share in trading bots has even overtaken GMGN to become the leader. FOMO's success is attributed to its "social-first" product design, featuring a profit leaderboard and a feed tracking top traders' activities—effectively creating "trading celebrities" that users follow. In response, Pump.fun has recently upgraded its app to replicate these social features, shifting its homepage focus to trader activity feeds. The platform's founder has actively welcomed prominent meme traders. This competition underscores a major shift in the overseas meme market: the battleground has moved from launch tools and liquidity to a fight for attention and influence. The market is now dominated by a "网红带货模式" (influencer-driven model), where platforms compete to sign the most influential trading Key Opinion Leaders (KOLs), who have become the new carriers of market consensus. While this mirrors early competition in livestreaming platforms, it signals a potential risk for the meme space: losing the organic, community-driven vitality that originally fueled its growth, as competition centers increasingly on a concentrated group of trading influencers.

marsbit2 h fa

$20k Signing Fee + $30k Monthly Salary: The Story Behind Pump.fun Poaching FOMO's Corner

marsbit2 h fa

Trading

Spot
活动图片