North Korean hackers hit 1,640 firms as AI tools widen their reach

- A security researcher revealed that North Korean state hackers have infiltrated 1,640 companies across 57 countries, gaining root-level access to hundreds of them.Â
- Hackers target software developers with lucrative fake job offers, using rigged coding tests to install malware on contractor laptopsÂ
- North Korean operators are heavily utilizing commercial AI tools to automate and meticulously plan high-stakes heists.Â
A security researcher who spent nearly two years quietly monitoring North Korean hacking operations dropped a bombshell at the Black Hat conference in Las Vegas.
At the conference, he revealed that state-sponsored hackers have successfully breached 1,640 companies across 57 countries, with several hundred among them suffering severe compromises.
Root access to servers, AWS accounts and crypto keys
Vangelis Stykas, the CTO of cybersecurity firm Kumio, gained access after the hackers accidentally infected their own systems with malware. This blunder allowed Stykas to slip inside their command-and-control servers, access their Slack and Discord channels, and comb through roughly five terabytes of data.
According to Stykas, the level of access varied, but the worst breaches gave hackers total control, including root access to cloud servers, AWS accounts, and even master cryptographic keys for blockchain companies.Â
He also publicly named several affected organizations that handled his disclosure well, including Coinbase, Uniswap Labs, and Boston Children’s Hospital.
Coinbase stated that the contractor Stykas flagged was investigated and fired within 30 days without exposing customer data, while Boston Children’s Hospital clarified that the incident involved a former contractor’s personal device rather than core hospital systems.
Some pushed back on the findings.
North Korean hackers’ bait: Fake job offers
The scam itself was surprisingly simple: they lure software developers with lucrative fake job offers and trick them into running a coding test that installs malware.
The real danger lies in freelance culture.Â
Because independent developers often manage multiple corporate clients at once, a single infected laptop can act as a master key for dozens of companies.Â
Stykas noted finding individual contractors who inadvertently handed over access to as many as 30 businesses at once, mirroring broader federal investigations into North Korean remote-worker schemes that stole billions in crypto.
How commercial AI assists novice hackers
The reason a country with a notoriously isolated internet infrastructure can pull this off at scale is majorly thanks to commercial artificial intelligence. In April, WIRED discovered a North Korean group called HexagonalRodent that was using standard AI tools from companies like OpenAI, Anima, and Cursor to automate everything from writing malware code to building convincing fake recruiter websites.
Obvious clues, like English-language comments and emojis embedded deep within the malware code, point directly to AI generation.Â
Experts also note that AI is effectively leveling the playing field, allowing less-skilled operators to execute complex, multi-stage cyberattacks. Separate investigations by Google’s threat team also revealed North Korean hackers UNC2970 using tools like Gemini to research targets and map out high-paying job roles in defense and tech.
Two heists took over 76% of April’s stolen crypto
Beyond sheer volume, the level of precision these attacks are now carrying is starting to concern analysts. According to blockchain intelligence firm TRM Labs, North Korean groups are responsible for about 76% of all stolen crypto in April, totaling up to roughly $577 million extracted from just two massive exploits.
Most experts now suspect that advanced AI tools play a major role in the meticulous social engineering required to pull off these high-stakes heists, pushing North Korea’s total estimated crypto theft past $6 billion since 2017.
If you're reading this, you’re already ahead. Stay there with our newsletter.
FAQs
Who is Vangelis Stykas?
He is the chief technology officer at cybersecurity firm Kumio and a Greece-based researcher who, according to WIRED, spent about 22 months with access to North Korean hacking servers before presenting his findings at Black Hat in Las Vegas.
How do North Korean hackers break into companies?
They lure software developers with fake, high-paying job offers, then ask the target to run a coding "test" that secretly installs malware, a technique Microsoft has tracked as Contagious Interview since at least 2022.
How much cryptocurrency did North Korea steal in 2026?
TRM Labs found North Korean groups took roughly $577 million through April 2026, about 76% of all crypto hack losses that year, mostly from the $285 million Drift Protocol and $292 million KelpDAO attacks, bringing cumulative theft since 2017 above $6 billion.
Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Hannah Collymore
Hannah is a writer and editor with nearly a decade of blog writing and event reporting experience in the crypto space. At Cryptopolitan, Hannah contributes to the news page, reporting and analyzing the latest developments in DeFi, RWA, crypto regulation, AI and frontier tech industries. She graduated from Arcadia university with a degree in Business Administration.
















