Security researcher accesses North Korean hacker servers, uncovers global network breaches
Researcher Vangelis Stykas has spent almost two years with continuous access to servers operated by North Korean hacking groups, allowing him to observe their activities in real time. During this period, Stykas documented a series of coordinated intrusions that targeted a wide array of institutions, including financial services, telecommunications providers, and government agencies across multiple continents. The data collected from the compromised servers revealed that the attackers employed sophisticated malware, credential‑stealing tools, and lateral‑movement techniques to infiltrate networks and exfiltrate sensitive information.
The findings underscore the extensive reach of the North Korean cyber apparatus, which appears to have leveraged compromised infrastructure to conduct operations on a scale larger than previously reported. By maintaining a foothold within the attackers’ own command‑and‑control environment, Stykas was able to map the groups’ operational patterns, identify recurring targets, and confirm that the intrusions were part of a sustained campaign rather than isolated incidents. The research highlights the ongoing threat posed by state‑sponsored cyber actors and the importance of international cooperation in detecting and mitigating such widespread digital incursions.