Home / Blog / A Security Pro Hacked North Korean Hackers. He Found They’d…
Tech News

A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide

For nearly two years, security researcher Vangelis Stykas has maintained access to servers used by North Korean hackers. His access showed that those…

By Dillip Chowdary • Aug 06, 2026 • Source: Wired

A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide

For nearly two years, security researcher Vangelis Stykas has maintained access to servers used by North Korean hackers. His access showed that those operators had already broken into a large number of systems worldwide. Wired reports the work as evidence of broad, sustained intrusion activity rather than isolated hits.

Stykas did not stop at detecting one campaign. He stayed inside the attackers’ own infrastructure long enough to observe how they used those servers after successful compromises. That posture turns the usual defender view inside out: instead of chasing malware on victim machines, he watched the operators’ backend and what they pulled from networks they had already entered.

Advertisement

Tech Pulse Daily

Get tomorrow's pulse first

Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.

For engineers and builders, the finding is operational. If state-linked operators can hold footholds across hundreds of networks, perimeter alerts and one-off incident response are not enough. Teams need durable logging, outbound and lateral-movement detection, and the ability to assume long-lived adversary access rather than single-event breaches.

The market context is familiar but sharpened by scale. North Korean hacking groups are already treated as high-priority threats for theft, espionage, and supply-chain abuse. Stykas’s multi-year access to their servers shows those groups running active, multi-target operations at volume, not only opportunistic strikes against a few high-value brands.

What to watch next is whether defenders and vendors can turn this kind of offensive research into concrete detection of the same infrastructure patterns. The practical takeaway for security teams is to treat “hundreds of networks worldwide” as a capacity signal: prioritize identity, remote-access paths, and post-compromise telemetry, and assume that quiet, long-running access is part of the threat model, not an edge case.

Advertisement

🔎 More interesting news

5-min tech signal

Weekday briefing for engineers who skip the noise.

No spam · Unsubscribe anytime

Advertisement

✈️ CareerPilot

Your AI job-search copilot

Match your resume against live Ashby, Greenhouse & Lever openings — fit scores, job-specific resume optimization and email alerts.

Find matching jobs →

Free Tools

Browse all tools →