North Korean Hackers Breach 1,640 Firms Across 57 Countries

North Korean Hackers Breached 1,640 Companies Across 57 Countries: Research

Last Updated:
North Korean Hacker Addresses Trading on Hyperliquid, Resulting in $700K Loss
Google News

Get our latest news first. Add us as your Preferred Source on Google and tap "Star" to prioritize our updates.

North Korean cyber operators have expanded their global reach after compromising 1,640 organizations across 57 countries through fake software developer recruitment campaigns. Cybersecurity researchers found that attackers consistently targeted cryptocurrency firms while exploiting weak contractor security practices. 

The findings suggest that many organizations unknowingly exposed critical infrastructure because contractors retained broad access across multiple corporate environments. Consequently, a single successful compromise often created opportunities for attackers to penetrate several businesses at once and steal valuable digital assets.

Researchers Reveal Massive Crypto-Focused Operation

Kumio Chief Technology Officer Vangelis Stykas spent 22 months monitoring infrastructure linked to North Korean hacking groups. His investigation uncovered severe breaches affecting roughly 700 to 800 organizations. 

Attackers reportedly obtained administrator privileges, cloud infrastructure permissions, and cryptocurrency wallet credentials. Besides targeting blockchain companies, hackers infiltrated healthcare, finance, government, and technology organizations. However, investigators found that cryptocurrency theft remained the primary objective throughout the campaign.

Contractor Access Increased Security Risks

Researchers determined that fake job interviews served as the attackers’ preferred entry method. Victims downloaded disguised coding assessment software that secretly installed malware on their systems. Moreover, many contractors possessed credentials for numerous organizations, dramatically increasing the impact of each compromise. 

Security experts warn that companies should strengthen contractor oversight, limit privileged access, and continuously monitor credentials. Hence, stronger identity controls and faster incident response remain essential against increasingly sophisticated state-backed cyber threats.

Related: MyTrade Founder Fined After Guilty Plea in Crypto Wash Trading Scheme

Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.