Stykas publicly named roughly a dozen organizations that handled the disclosure process well or had already independently discovered the breach . Among them:
The campaign was broad-based, hitting technology firms, financial institutions, healthcare providers, and government bodies across dozens of countries .
The primary initial-access method was a social engineering campaign Stykas identified as "Contagious Interview" . North Korean hackers posed as corporate recruiters on professional networks like LinkedIn. They targeted software developers with enticing job offers and, during sham interviews, tricked victims into downloading malware-laced coding tests, PDFs, or other files
.
Once a single contractor or employee's device was compromised, the attackers pivoted into the corporate network. In some cases, North Korean IT workers also infiltrated companies directly through fraudulent remote employment .
Stykas gained access not through a sophisticated intrusion but because the North Korean hackers accidentally infected their own workstations with their own malware . This operational security failure gave Stykas a foothold into their command-and-control servers. From there, he accessed their internal Slack and Discord channels, combed through stolen data, and extracted developer keys, source code, and internal communications
.
Stykas's findings underscore a critical vulnerability in modern corporate security: the reliance on remote contractors and the hiring process itself as an attack surface. They also highlight how state-backed hacking groups can conceal a staggering number of breaches — far more than previously known — for years.