
Over 22 months, Greek cybersecurity specialist Vangelis Stikas found signs of intrusions by North Korea-linked hackers into the systems of 1,640 organizations across 57 countries, WIRED reported.
He estimated that in 700–800 cases the attacks led to serious infrastructure compromise. Among the potentially affected organizations, Stikas named Coinbase, Uniswap Labs, Boston Children’s Hospital, Japan’s AEON Smart Technology, Chinese smartphone maker Oppo, Italy’s Supreme Council of the Judiciary, a unit of Saudi Arabia’s Al Rajhi Bank, and the Flemish government body Digitaal Vlaanderen.
Most cases have not been independently confirmed. Some of the named entities confirmed isolated incidents; however, Coinbase and Boston Children’s Hospital said they found no intrusions into their internal systems.
Researcher gained access to hackers’ servers
Stikas is the chief technology officer and co-founder of Kumio. He said he gained access to several command-and-control servers used to manage infected devices and collect stolen information.
The researcher did not disclose the method of entry for security reasons. He said that in some cases the hackers infected their own workstations with malware they created. This allegedly allowed Stikas to access their Slack and Discord channels.
He said he examined about 5 TB of data. He identified potential victims by developer keys, source code, cloud account credentials and other digital traces. Stikas then notified organizations about possible compromises.
“This is access to companies, root access to servers and AWS. For crypto companies, this means keys and access to blockchain infrastructure. The level of access is incredible,” Stikas said.
Only some organizations confirmed incidents
Japan’s computer incident response team confirmed Stikas’s findings regarding AEON Smart Technology to the publication. Specialists helped the company address the effects of the attack.
The government of Flanders also said that on March 3, 2026 it received a notification from the Centre for Cybersecurity Belgium after the researcher’s outreach. The affected workstation was isolated, and potentially exposed credentials and access keys were revoked and replaced.
According to Boston Children’s Hospital, the incident involved a personal device of a former independent contractor, not the hospital’s infrastructure. A review found no unauthorized access to internal systems. Data related to the episode, representatives said, were already publicly available.
Coinbase confirmed that at the end of 2025 it engaged a short-term U.S. contractor for engineering work. The exchange’s systems detected anomalous technical activity and limited his access, and within 30 days of the start of work the platform ended the engagement. Later, Stikas provided the company with information about his possible connection to a broader North Korean operation.
The exchange found no evidence that the specialist was in North Korea or linked to the country’s government. A small amount of code ended up in his private repository, but Coinbase called the materials insignificant and unrelated to customer data.
Uniswap Labs, Oppo and several other named organizations did not respond to WIRED’s request.
Attacks began with fake job interviews
In most of the cases studied, the attackers used fake job offers, posing as recruiters for cryptocurrency and AI companies. During interviews, the victim was asked to clone and run an NPM package hosted on GitHub, GitLab or Bitbucket. After the code executed, a backdoor was downloaded to the device.
In newer attacks, the hackers began using Visual Studio Code workflows. When opening a downloaded project, the editor prompts the user to trust the author; after approval, a configuration file can automatically download and run malicious code.
Microsoft has tracked such activity since at least December 2022. The company determined that the tools collect API tokens, cloud credentials, signing keys, wallet materials and password manager files. Some versions take screenshots, read the clipboard and execute remote commands.
According to Stikas, the risk increased with contractors who had access to the infrastructure of multiple clients. In one case, the infected device belonged to a specialist who worked with about 30 organizations.
Cryptocurrencies — the main target
The researcher said the attackers obtained access to large volumes of confidential information but were primarily looking for crypto wallets and related keys.
Expel threat analyst Marcus Hutchins told WIRED that he observed similar campaigns with equally long lists of potential victims. He said a focus on digital assets does not rule out further use of access for espionage or theft of other data.
“Give one person access to a system and they can do almost anything,” Hutchins said.
In March, the U.S. Treasury’s Office of Foreign Assets Control imposed sanctions on six individuals and two companies for facilitating schemes involving North Korean IT workers. According to the agency, in 2024 such operations brought North Korean authorities nearly $800 million.
In June, researchers from Cisco Talos reported a new trojan, PylangGhost. North Korean hackers distributed it through fake interviews for crypto specialists.
Earlier, the Ketman project identified 100 alleged North Korean IT operators who worked in digital asset-focused companies under false identities. Later, the country’s Foreign Ministry called allegations of involvement in cryptocurrency theft “absurd slander.”
