▲ Hacking (File Photo)
It has been revealed that a North Korean hacking group that has been stealing cryptocurrency and confidential information from companies worldwide was instead hacked by a security researcher.
Vangelis Stykas, Chief Technology Officer (CTO) of the US security firm Qumio, has secured 5 terabytes (TB) of hacking data from a North Korean hacking organization's server over the past 22 months, US tech media outlet Wired reported on August 6 (local time).
While Stykas did not disclose the specific method used to infiltrate the organization's server, he explained that some North Korean hackers became infected with malicious code, allowing access to their work PCs and messenger conversations on platforms like Slack and Discord.
Analyzing the data obtained in this manner, he discovered that this North Korean hacking group targeted 1,640 companies across 57 countries.
Cases of severe damage alone, such as the theft of root administrator privileges or cryptocurrency keys, reached 700 to 800 locations.
The core crime pattern of the North Korean hackers was identified as a recruitment-disguised approach known as a "Contagious Interview."
This method involves approaching developers with the bait of high salaries and tricking them into downloading a program under the guise of a "coding test" to implant malicious code—a tactic popularized and frequently used by affiliates of the Lazarus Group under North Korea's Reconnaissance General Bureau.
In particular, if an outsourced contractor receiving work from multiple companies gets infected with malicious code, the scale of the damage can expand accordingly.
Stykas explained, "There were cases where outsourced contractors with access privileges to up to 30 companies were hacked."
He stated that the targets included an agency under the Government of Flanders in Belgium, cryptocurrency firm Coinbase, Chinese smartphone manufacturer Oppo, Japanese technology firm AEON Smart Technology, and Boston Children's Hospital in the US.
While these institutions took measures such as replacing access credentials or terminating contracts, some denied the damage or refuted that there was evidence linking the incidents to North Korea.
※ Please note: This article was translated by AI and may contain errors.
Video News
Video News
Video News
Video News
Video News