A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide
For nearly two years, security researcher Vangelis Stykas has maintained access to servers used by North Korean hackers. His access showed that those…
By Dillip Chowdary • Aug 06, 2026 • Source: Wired
For nearly two years, security researcher Vangelis Stykas has maintained access to servers used by North Korean hackers. His access showed that those operators had already broken into a large number of systems worldwide. Wired reports the work as evidence of broad, sustained intrusion activity rather than isolated hits.
Stykas did not stop at detecting one campaign. He stayed inside the attackers’ own infrastructure long enough to observe how they used those servers after successful compromises. That posture turns the usual defender view inside out: instead of chasing malware on victim machines, he watched the operators’ backend and what they pulled from networks they had already entered.
Advertisement
Tech Pulse Daily
Get tomorrow's pulse first
Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.
For engineers and builders, the finding is operational. If state-linked operators can hold footholds across hundreds of networks, perimeter alerts and one-off incident response are not enough. Teams need durable logging, outbound and lateral-movement detection, and the ability to assume long-lived adversary access rather than single-event breaches.
The market context is familiar but sharpened by scale. North Korean hacking groups are already treated as high-priority threats for theft, espionage, and supply-chain abuse. Stykas’s multi-year access to their servers shows those groups running active, multi-target operations at volume, not only opportunistic strikes against a few high-value brands.
What to watch next is whether defenders and vendors can turn this kind of offensive research into concrete detection of the same infrastructure patterns. The practical takeaway for security teams is to treat “hundreds of networks worldwide” as a capacity signal: prioritize identity, remote-access paths, and post-compromise telemetry, and assume that quiet, long-running access is part of the threat model, not an edge case.
Advertisement