DPRK State-Sponsored Campaign: Reverse-Infection Uncovers 1,640 Global Breaches
A counter-intrusion operation led by researcher Stykas has successfully exposed a massive North Korean state-sponsored campaign targeting 1,640 organizations across 57 countries. By exploiting vulnerabilities in the attackers' own infrastructure, the researcher achieved a reverse-infection, gaining access to Command and Control (C2) logs and internal datasets. The campaign primarily utilized social engineering through the deployment of fraudulent IT workers to gain initial access to corporate environments. Once inside, the actors deployed specialized scripts designed to harvest cryptocurrency private keys. This intelligence revelation provides critical visibility into the DPRK's methodology, victimology, and identity-spoofing frameworks used to bypass traditional perimeter defenses.