Not all breaches were equal. Stykas estimated that 700 to 800 of those victims suffered what he described as "really damaging" intrusions . In those severe cases, attackers gained:
Stykas publicly named roughly a dozen organizations that handled the disclosure process well or had already independently discovered the breach . Among them:
The campaign was broad-based, hitting technology firms, financial institutions, healthcare providers, and government bodies across dozens of countries .
The primary initial-access method was a social engineering campaign Stykas identified as "Contagious Interview" . North Korean hackers posed as corporate recruiters on professional networks like LinkedIn. They targeted software developers with enticing job offers and, during sham interviews, tricked victims into downloading malware-laced coding tests, PDFs, or other files .
Once a single contractor or employee's device was compromised, the attackers pivoted into the corporate network. In some cases, North Korean IT workers also infiltrated companies directly through fraudulent remote employment .
Stykas gained access not through a sophisticated intrusion but because the North Korean hackers accidentally infected their own workstations with their own malware . This operational security failure gave Stykas a foothold into their command-and-control servers. From there, he accessed their internal Slack and Discord channels, combed through stolen data, and extracted developer keys, source code, and internal communications .
He spent 22 months quietly monitoring their operations without being detected .
At Black Hat, Stykas disclosed :
Stykas's findings underscore a critical vulnerability in modern corporate security: the reliance on remote contractors and the hiring process itself as an attack surface. They also highlight how state-backed hacking groups can conceal a staggering number of breaches — far more than previously known — for years.
The fact that an individual researcher could infiltrate and monitor a nation-state's hacking apparatus for nearly two years also suggests significant operational security gaps within North Korean cyber units .