Greek cybersecurity specialist Vangelis Stykas, CTO of the company Kumio, observed the work of a DPRK-linked hacking group from inside its own infrastructure for almost 22 months. He reported this on August 6-7 at the Black Hat USA 2026 conference.
Stykas discovered data on 1,640 companies in 57 countries that were on the group's target list or had already been affected by it. Of these, about 700–800 organizations suffered serious intrusions — the attackers gained root access to servers, AWS infrastructure, and in the case of crypto companies — also to wallet keys. Among the publicly named victims:
- Coinbase
- Uniswap Labs
- Boston Children's Hospital
- Oppo
- AEON Smart Technology
The researcher gained access to the hackers' communications and servers largely by chance: the group's operators infected their own workstations with the same malware used to attack victims. This opened the way for Stykas to their C2 servers, Slack and Discord accounts, and about 5 TB of internal data.
Record losses in the first half of the year
Stykas's surveillance coincided with the publication of data on the record scale of North Korean crypto-hacking. According to a TRM Labs report from July 1, 2026, in the first half of the year, DPRK-linked hackers stole about $643 million in cryptocurrency — roughly 66% of the total amount stolen globally in hacks and exploits during that period. The industry's total losses for the half-year amounted to $972 million across 207 recorded incidents.
Almost all of North Korea's haul came from two major attacks in April 2026 — on Drift Protocol (about $285 million) and on KelpDAO (about $292 million). At the same time, TRM Labs emphasizes: these figures only account for direct hacks and exploits. In addition to these, the DPRK obtains cryptocurrency through phishing, social engineering, fraudulent schemes and scams, as well as by having its IT specialists employed under false identities in Western companies.
Analytical platforms estimate the cumulative volume of cryptocurrency stolen by North Korean hackers since 2017 at approximately $6.75 billion as of the end of 2025 — taking into account 2026 operations, this sum has grown even larger.
Tactical shift: betting on people, not on code
The main attack method is increasingly becoming social engineering against company employees, rather than hacking the protocol itself. Hackers linked to the Lazarus group and related structures pretend to be recruiters, offer developers high-paying remote work, and send a "test task". Once the victim downloads and runs the file on their work computer, malware is installed on the device, opening access to corporate infrastructure, keys, servers, and wallets — after which the funds are withdrawn. This scenario was used, in particular, in the multi-month campaign against Drift Protocol and in Operation Contagious Interview.
The combination of TRM Labs data and Stykas's findings shows that over recent years, North Korean operators have built an infrastructure covering hundreds of companies worldwide — from crypto exchanges and DeFi protocols to electronics manufacturers and medical institutions. The main blow, however, is not against technical vulnerabilities in blockchains, but against employees' trust in seemingly legitimate job offers.
AI Opinion
From the perspective of macroeconomic connections, Stykas's investigation appears as part of a broader picture. The stolen crypto-assets do not settle in the hackers' private accounts — the U.S. State Department confirmed back in January 2026 that proceeds from such operations are systematically directed towards weapons programs and circumventing UN sanctions. A technical aspect left out of the article is the resilience of the Lazarus infrastructure itself: the infection of the operators' own workstations with the same malware indicates a lack of internal cyber hygiene even within an advanced group. This creates a window of vulnerability that the researcher exploited, but which competing intelligence could theoretically also exploit. The question remains open: for how long will such "accidental" slip-ups remain the only way to peer inside the North Korean hacking machine?
end-content




