A security researcher has spent nearly two years inside the digital infrastructure of North Korean state-backed hackers, uncovering evidence of intrusions into hundreds of systems across the globe.
Vangelis Stykas, a cybersecurity professional, maintained access to servers controlled by North Korean threat actors since 2023, according to a report published by Wired on Thursday. His work has revealed the scale and scope of a coordinated hacking operation that has penetrated networks in multiple countries.
Inside the Operation
Stykas gained access to command and control servers used by the North Korean hacking group, allowing him to monitor their activities and analyse the targets they had compromised. The servers contained logs and data showing successful intrusions into corporate networks, government systems, and other sensitive infrastructure.
The researcher did not disclose specific victim organisations or countries, citing ongoing law enforcement investigations and the sensitivity of the information. However, he confirmed that the number of compromised systems runs into the hundreds.
North Korean state-sponsored hacking groups have been linked to some of the most significant cybercrimes in recent years, including the 2014 Sony Pictures breach, the WannaCry ransomware attack in 2017, and numerous cryptocurrency thefts totalling billions of dollars.
The findings suggest that North Korean cyber operations are more extensive than previously understood by the public. While governments and cybersecurity firms have tracked these groups for years, Stykas’ direct access to their infrastructure provided a rare inside view of their operational tempo and success rate.
Stykas shared his findings with law enforcement agencies and cybersecurity companies to help identify and notify victims. Many of the compromised organisations were reportedly unaware they had been breached.
The researcher’s work highlights a persistent challenge in global cybersecurity: organisations often lack the visibility to detect sophisticated intrusions, particularly those conducted by well-resourced state actors.
North Korean Cyber Strategy
North Korea’s cyber operations are widely believed to serve two primary purposes: espionage and revenue generation. The isolated nation has faced international sanctions for decades, limiting its access to traditional financial systems.
Cryptocurrency theft has become a major revenue stream for the regime. According to blockchain analytics firm Chainalysis, North Korean hackers stole approximately $1.7 billion in cryptocurrency in 2022 alone, with the funds reportedly used to finance weapons programmes and government operations.
The United Nations Security Council has documented North Korea’s use of stolen cryptocurrency to evade sanctions and fund its nuclear and ballistic missile programmes.
Attribution and Response
Stykas did not name the specific North Korean hacking group whose servers he accessed. Multiple threat groups operate under the direction of North Korea’s Reconnaissance General Bureau, including the Lazarus Group, APT38, and the Kimsuky group.
The US government has sanctioned North Korean hackers and issued indictments against individuals linked to these operations, though arrests remain unlikely given the lack of extradition agreements with North Korea.
Cybersecurity experts say the research underscores the need for improved threat intelligence sharing and enhanced network monitoring, particularly for organisations that may be targeted for financial gain or strategic intelligence.
Stykas’ extended access to the hacking infrastructure represents an unusual intelligence coup in the cybersecurity community, where such sustained infiltration of adversary systems is rare and typically conducted by government agencies rather than independent researchers.

