A researcher observed North Korean hackers from the inside for two years. What did he learn?

cryptonews.ruОпубліковано о 2026-08-09Востаннє оновлено о 2026-08-09

Анотація

Greek cybersecurity researcher Vangelis Stykas spent nearly 22 months infiltrating the infrastructure of a North Korean-linked hacker group, revealing his findings at Black Hat USA 2026. He accessed the group's internal systems after the operators infected their own workstations with the same malware used against targets. His access yielded data on 1,640 targeted companies across 57 countries, with 700-800 suffering serious breaches, including Coinbase and Uniswap Labs. This period coincided with record crypto thefts by North Korean actors, who stole an estimated $643 million in the first half of 2026—about 66% of global losses from hacks and exploits. Two major April attacks on Drift Protocol and KelpDAO accounted for most of these funds. Cumulative thefts since 2017 are estimated at over $6.75 billion, with proceeds funding weapons programs and sanctions evasion. The group's tactics have shifted towards sophisticated social engineering, such as posing as recruiters to trick developers into installing malware, rather than attacking blockchain protocols directly. Despite their advanced capabilities, the incident where operators infected their own machines highlights lapses in their operational security, creating vulnerabilities that researchers or rival intelligence agencies could exploit.

Greek cybersecurity specialist Vangelis Stykas, CTO of the company Kumio, observed the work of a DPRK-linked hacking group from inside its own infrastructure for almost 22 months. He reported this on August 6-7 at the Black Hat USA 2026 conference.

Stykas discovered data on 1,640 companies in 57 countries that were on the group's target list or had already been affected by it. Of these, about 700–800 organizations suffered serious intrusions — the attackers gained root access to servers, AWS infrastructure, and in the case of crypto companies — also to wallet keys. Among the publicly named victims:

  • Coinbase
  • Uniswap Labs
  • Boston Children's Hospital
  • Oppo
  • AEON Smart Technology

The researcher gained access to the hackers' communications and servers largely by chance: the group's operators infected their own workstations with the same malware used to attack victims. This opened the way for Stykas to their C2 servers, Slack and Discord accounts, and about 5 TB of internal data.

Record losses in the first half of the year

Stykas's surveillance coincided with the publication of data on the record scale of North Korean crypto-hacking. According to a TRM Labs report from July 1, 2026, in the first half of the year, DPRK-linked hackers stole about $643 million in cryptocurrency — roughly 66% of the total amount stolen globally in hacks and exploits during that period. The industry's total losses for the half-year amounted to $972 million across 207 recorded incidents.

Almost all of North Korea's haul came from two major attacks in April 2026 — on Drift Protocol (about $285 million) and on KelpDAO (about $292 million). At the same time, TRM Labs emphasizes: these figures only account for direct hacks and exploits. In addition to these, the DPRK obtains cryptocurrency through phishing, social engineering, fraudulent schemes and scams, as well as by having its IT specialists employed under false identities in Western companies.

Analytical platforms estimate the cumulative volume of cryptocurrency stolen by North Korean hackers since 2017 at approximately $6.75 billion as of the end of 2025 — taking into account 2026 operations, this sum has grown even larger.

Tactical shift: betting on people, not on code

The main attack method is increasingly becoming social engineering against company employees, rather than hacking the protocol itself. Hackers linked to the Lazarus group and related structures pretend to be recruiters, offer developers high-paying remote work, and send a "test task". Once the victim downloads and runs the file on their work computer, malware is installed on the device, opening access to corporate infrastructure, keys, servers, and wallets — after which the funds are withdrawn. This scenario was used, in particular, in the multi-month campaign against Drift Protocol and in Operation Contagious Interview.

The combination of TRM Labs data and Stykas's findings shows that over recent years, North Korean operators have built an infrastructure covering hundreds of companies worldwide — from crypto exchanges and DeFi protocols to electronics manufacturers and medical institutions. The main blow, however, is not against technical vulnerabilities in blockchains, but against employees' trust in seemingly legitimate job offers.

AI Opinion

From the perspective of macroeconomic connections, Stykas's investigation appears as part of a broader picture. The stolen crypto-assets do not settle in the hackers' private accounts — the U.S. State Department confirmed back in January 2026 that proceeds from such operations are systematically directed towards weapons programs and circumventing UN sanctions. A technical aspect left out of the article is the resilience of the Lazarus infrastructure itself: the infection of the operators' own workstations with the same malware indicates a lack of internal cyber hygiene even within an advanced group. This creates a window of vulnerability that the researcher exploited, but which competing intelligence could theoretically also exploit. The question remains open: for how long will such "accidental" slip-ups remain the only way to peer inside the North Korean hacking machine?

end-content

Пов'язані питання

QHow did the Greek cybersecurity researcher Vangelis Stykas gain access to the North Korean hackers' internal infrastructure?

AHe gained access largely by chance. The operators of the hacking group infected their own workstations with the same malware they used to attack victims. This opened a path for Stykas to their C2 servers, Slack and Discord accounts, and approximately 5 TB of internal data.

QAccording to the TRM Labs report cited in the article, what was the estimated value of cryptocurrency stolen by North Korean-linked hackers in the first half of 2026?

AAccording to the TRM Labs report from July 1, 2026, North Korean-linked hackers stole about $643 million in cryptocurrency in the first half of 2026.

QWhat is the primary attack method increasingly used by North Korean-linked hackers, as described in the article?

AThe primary method is increasingly social engineering attacks against company employees, rather than hacking the protocol itself. Hackers pose as recruiters offering high-paying remote jobs and send 'test tasks' containing malware.

QWhich two major attacks in April 2026 accounted for nearly all of North Korea's cryptocurrency theft in the first half of 2026?

AThe two major attacks were on Drift Protocol (about $285 million) and on KelpDAO (about $292 million).

QWhat does the article suggest about the ultimate use of the cryptocurrency stolen by North Korean hackers?

AThe article states, citing the U.S. State Department, that the proceeds from these operations are systematically directed towards weapons programs and circumventing UN sanctions.

Пов'язані матеріали

Analog Chip Giants TI and ADI Are Stepping Up

Analog chip giants Texas Instruments (TI) and Analog Devices (ADI) have both reported strong quarterly results, signaling an industry recovery. TI's Q2 2026 revenue reached $5.463 billion, a 23% year-over-year (YoY) increase. ADI's Q3 FY2026 revenue hit $4.022 billion, up 40% YoY, marking a new quarterly record. Both companies benefited from rising demand in industrial and data center markets, though their growth paths differed. TI experienced broad-based strength across its segments. Industrial revenue (33% of total) grew approximately 30% YoY, while data center revenue (9%) doubled. The automotive segment (33%) also showed a strong rebound, attributed to demand from China's EV/hybrid market and low inventory levels at automakers. ADI's growth was led by its industrial (49% of revenue, +53% YoY) and communications (16%, +84% YoY) segments, with data center products constituting 80% of the latter. Management highlighted a significant "AI exposure," with data center and ATE-related businesses now accounting for 20% of total revenue. Key differences emerged in their strategies and supply chain dynamics. ADI attributed a larger portion of its growth to AI infrastructure demand and has built "strategic inventory" to a record high of ~$1.93 billion to support future growth, despite channel inventory being below target levels. Its product lead times have extended to up to six months, and price increases are contributing to margin expansion. TI's inventory remained high at $4.6 billion but saw improved turnover. The company emphasized that its growth is primarily volume-driven, with minimal contribution from recent price hikes. TI maintains a competitive lead time below 13 weeks and expressed confidence in its capacity sufficiency for the next three years. In summary, both companies are riding a recovery wave fueled by industrial and AI/data center demand. TI's approach leverages its broad market presence and prepared capacity, while ADI is more focused on AI-driven growth and strategic inventory buildup. Their differing paths highlight the evolving structure of demand within the analog semiconductor market's rebound.

marsbit17 хв тому

Analog Chip Giants TI and ADI Are Stepping Up

marsbit17 хв тому

Bernstein Research Report Analysis: Circle Benefits from USDC Expansion Cycle, Maintains Outperform Rating with $140 Price Target

Bernstein Report Analysis: Circle Benefits from USDC Expansion Cycle, Maintains Outperform Rating with $140 Target Stablecoin markets are reversing. After nearly six months of stagnation and decline, the supply of USDC suddenly increased by $1.7 billion in the final week of August. Circle's stock price has rebounded 42% from its slump driven by concerns over OUSD competition. On August 24, Bernstein published a report stating this is not a temporary technical rebound. Four key factors are driving a new stablecoin expansion cycle: the macro interest rate environment, expansion of the on-chain capital market, proliferation of stablecoin payments, and the emerging use of AI agent payments. Circle, as the largest compliant stablecoin issuer, is positioned to benefit significantly. Bernstein maintains its "Outperform" rating for Circle with a $140 price target, implying a 59% upside from the current price. The recovery in USDC supply validates the macro logic. The US Treasury's long-end bond buyback plan is reshaping the macro narrative for stablecoins, with stablecoins absorbing incremental short-term Treasury supply. Both Bitcoin and stablecoins benefit from this macro shift. AI agent payments represent a new growth frontier. Stablecoin payments are extending from "person-to-person" to "machine-to-machine." Bernstein highlights the x402 payment protocol, designed for AI agents to autonomously hold wallets, discover services, and make instant micropayments using USDC. While current volumes are small, this signals stablecoins' evolution towards becoming a native currency for the digital economy. USDC accounts for over 99% of x402 transaction volume. Circle benefits from two structural trends. First, the expansion of the on-chain capital market: its ARC blockchain, with validators like BlackRock and DTCC, supports asset tokenization. USDC has also been used as collateral for regulated derivatives. Second, the continued adoption of stablecoin payments: USDC's share of adjusted transaction volume has risen from ~40% in 2025 to over 60% year-to-date in 2026. Bernstein's $140 valuation is based on a long-term discounted cash flow model, corresponding to ~23x 2028 adjusted EBITDA. Key risks include digital asset volatility, increased competition, and Circle's reliance on interest income for 99% of its revenue. The stablecoin expansion is a structural story, and Circle sits at the confluence of these driving trends.

marsbit29 хв тому

Bernstein Research Report Analysis: Circle Benefits from USDC Expansion Cycle, Maintains Outperform Rating with $140 Price Target

marsbit29 хв тому

Торгівля

Спот
活动图片