Researcher links North Korean hacks to 1,640 organizations in 57 countries

Researcher links North Korean hacks to 1,640 organizations in 57 countries

Stykas said fake coding tests used in the "Contagious Interview" campaign delivered malware that exposed root and AWS access, private keys and cloud credentials, with attackers prioritizing wallets and other blockchain infrastructure.

UNI

Fact Check
All specific claim elements are confirmed by WIRED's primary reporting: Vangelis Stykas linking North Korean hacks to 1,640 organizations across 57 countries, the 'Contagious Interview' campaign using fake coding tests, gaining root and AWS access, and prioritizing cryptocurrency wallets, private keys, and blockchain infrastructure. Crypto Briefing and MLQ.ai independently corroborate the same figures and mechanisms. The numbers and details are consistent across all sources with no conflicting evidence.
    Reference123
Summary

North Korean operatives posing as recruiters used fake job interviews and coding tests to compromise about 1,640 organizations across 57 countries in a campaign dubbed "Contagious Interview," with Vangelis Stykas saying at Black Hat Las Vegas in August 2026 that he spent 22 months inside multiple command-and-control servers and collected about 5 terabytes of attacker data. He said 700 to 800 victims suffered severe breaches that gave the crews server root access, AWS root permissions or cryptocurrency wallet keys, and that contractors sometimes carried live credentials for as many as 30 companies. Palo Alto Networks first named the tactic in November 2023, while Microsoft said in March 2026 that fake code packages on GitHub, GitLab and Bitbucket could trigger malicious code execution through a Visual Studio Code trust prompt; the attackers then hunted API tokens, cloud credentials, signing keys, private keys, crypto wallets and password manager files. Stykas said the crews prioritized wallets and blockchain access over other reachable records, warned organizations including Coinbase and Uniswap Labs, and traced one Boston Children's Hospital exposure to a former contractor's personal device, a characterization the hospital disputed after saying it revoked credentials within hours and found no evidence its systems were accessed. The findings add to a broader picture of DPRK-linked crypto theft, which CrowdStrike said reached $2.02 billion in 2025, up 51% from a year earlier, while TRM Labs said April's $285 million Drift Protocol theft involved in-person contact and that Pyongyang-linked thefts have exceeded $6 billion since 2017.

Terms & Concepts
  • Contagious Interview: A social-engineering campaign that disguises malware as coding tests during fake recruitment processes.
  • root access: Administrator-level control over a server or device, allowing an intruder to change files, settings and permissions.
  • private keys: Secret cryptographic credentials used to control blockchain assets and authorize transactions.