/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

A researcher with access to North Korean hackers' servers says their operations have impacted 1,640 companies across 57 countries over the past 22 months

For nearly two years, researcher Vangelis Stykas has maintained access to North Korean hackers' servers.

Wired

Context & Ripple Effects

The reported footprint adds operational visibility to a campaign history previously characterized as extensive and revenue-focused in coverage of North Korea's expanding hacking apparatus. It also follows researchers’ identification of a long-running backdoor at a Russian rocket-design bureau, showing activity that extended beyond financially motivated targeting.

Stykas’ nearly two years of server access matters because it turns a broad attribution narrative into a cross-company, cross-country exposure record.

First-order effects

  • Companies included in the reported footprint have a concrete lead for incident-response teams to correlate their systems, accounts, and vendors with the observed infrastructure.
  • Vangelis Stykas’ access provides defenders and investigators with a longer-lived view of the operators’ activity than a single disclosed intrusion.

Second-order effects

  • Security teams at organizations outside the named set face pressure to review shared infrastructure and supplier connections, since the reported operations crossed 57 countries.
  • The breadth of the reported activity strengthens demand for threat intelligence that links individual incidents to a sustained North Korean operational network rather than treating them as isolated breaches.

Third-order effects

  • If server-side visibility continues to expose similarly broad targeting, cyber defense will increasingly center on limiting the blast radius of compromised access and infrastructure rather than solely blocking known malware.
  • The combined record of revenue-oriented operations and the Russian bureau backdoor points to a persistent state-linked cyber apparatus able to pursue different target types, complicating one-size-fits-all defensive priorities.

The trend: North Korean cyber operations are being understood less as discrete attacks and more as durable, globally distributed infrastructure campaigns with mixed financial and intelligence objectives.

Discussion

  • @dell Dell Cameron on bluesky
    NEW: “They're here, they're hacking us nonstop.  At the end of the day, everyone's getting hacked.”  Vangelis Stykas had access to a North Korean command-and-control server for 22 months: 1,640 companies across 57 countries.  —  More from Black Hat, by @mattburgess1.bsky.social &…
  • @agreenberg Andy Greenberg on bluesky
    At Black Hat, security researcher Vangelis Stykas reveals what he found by lurking inside North Korean hackers' infrastructure for nearly two years: They got footholds inside 1,640 networks, by his count.  About half of those intrusions were serious breaches. www.wired.com/story/…
  • r/craftofintelligence r on reddit
    A Security Pro Hacked North Korean Hackers.  He Found They'd Breached Hundreds of Networks Worldwide
  • r/pwnhub r on reddit
    A Security Pro Hacked North Korean Hackers.  He Found They'd Breached Hundreds of Networks Worldwide
  • @wired @wired on x
    For nearly two years, researcher Vangelis Stykas has maintained access to North Korean hackers' servers. His work shows they pulled off intrusions in a shocking number of systems across the globe. https://www.wired.com/...
  • r/blackhat r on reddit
    A Security Pro Hacked North Korean Hackers.  He Found They'd Breached Hundreds of Networks Worldwide