Via securityweek.com
North Korean hackers infiltrated 1,640 companies as crypto wallets emerged as key target: Report
Researcher Vangelis Stykas said 700 to 800 organizations suffered damaging intrusions after employees and contractors were targeted through fake developer job offers.
North Korean hackers gained access to systems connected to 1,640 companies across 57 countries, with cryptocurrency wallets and blockchain infrastructure among their primary targets, according to research presented at the Black Hat security conference and reported by Wired.
Cybersecurity researcher Vangelis Stykas said between 700 and 800 of the affected organizations suffered damaging intrusions that gave attackers extensive access to corporate servers, cloud infrastructure, developer credentials, and digital assets.
Stykas, chief technology officer at cybersecurity firm Kumio, spent 22 months accessing command and control systems used by the hackers. He reviewed approximately five terabytes of data after gaining visibility into infrastructure and communications platforms used by the group.
The researcher identified potential victims by examining developer credentials, source code, and other information stored inside the compromised systems. He said he contacted affected organizations and publicly identified around a dozen companies during his Black Hat presentation.
The organizations named by Stykas included crypto companies Coinbase and Uniswap Labs, Boston Children’s Hospital, Japanese technology company AEON Smart Technology, smartphone manufacturer Oppo, Italy’s Supreme Judicial Council, and a technology agency linked to the Flemish government.
Coinbase said it had investigated a contractor before receiving Stykas’ warning and found no evidence that the individual was based in North Korea or affiliated with its government.
The exchange said its security systems had identified risks suggesting that the contractor may have outsourced work to another person. Coinbase terminated the contractor within 30 days of onboarding and said no sensitive information or customer data was exposed.
Boston Children’s Hospital said the incident involved the personal device of a former independent contractor rather than its internal systems. The hospital said it disabled the remaining credentials and found no evidence that its systems had been accessed without authorization.
The Flemish government said an affected workstation was isolated after authorities received the researcher’s disclosure in March. Potentially exposed credentials were revoked and replaced, and the organization said the incident had been contained.
The hackers primarily approached software developers with fake employment opportunities offering high salaries. Targets were then instructed to download software or complete coding tests that installed malware on their devices.
The tactic is associated with the Contagious Interview campaign, which uses fake recruiters, technical interviews, malicious code repositories, and software downloads to compromise developers. Microsoft has documented North Korean groups using similar methods to steal credentials and gain access to company systems.
External contractors increased the potential reach of the attacks because individual developers sometimes held credentials for several organizations. Stykas said some compromised contractors had access to as many as 30 companies.
Although several affected organizations held sensitive corporate, government, or health information, Stykas said the hackers were largely focused on obtaining cryptocurrency wallet credentials and blockchain access.
The findings come as US authorities continue warning companies about North Korean remote technology workers who use false identities to secure employment and gain access to corporate networks.
The FBI said North Korean workers impersonate people from other countries to obtain remote positions and generate revenue for the government. US authorities have also linked these employment schemes to cryptocurrency theft and efforts to fund North Korea’s weapons programs.