Cybersecurity researchers say North Korean operators compromised 1,640 organizations across 57 countries through fake software developer recruitment campaigns, with cryptocurrency firms repeatedly in the crosshairs.

The activity was tracked over 22 months by Kumio Chief Technology Officer Vangelis Stykas, whose investigation tied the operation to infrastructure used by North Korean hacking groups. The findings point to a broad campaign that also reached healthcare, finance, government, and technology organizations, while crypto theft remained the main apparent objective.

A long-running campaign with wide reach

According to the research, the attackers used a global social-engineering effort built around bogus hiring processes for software developers. The campaign is said to have affected organizations in 57 countries, showing how far the operation spread beyond any single sector or region.

Stykas said his direct investigation uncovered severe breaches at roughly 700 to 800 organizations. The larger figure of 1,640 organizations reflects the broader scope researchers attributed to the campaign. Throughout that activity, cryptocurrency businesses were described as a consistent target.

Fake coding tests used as the entry point

Researchers found that sham job interviews were the preferred way in. Prospective victims were asked to download coding assessment tools that appeared legitimate but in fact installed malware.

Once inside, the operators reportedly stole high-value access, including administrator privileges, cloud infrastructure permissions, and cryptocurrency wallet credentials. That level of access could allow attackers to move beyond an initial infected machine and into core business systems and digital asset storage.

Contractors amplified the damage

A key weakness identified in the research was the role of contractors with broad access across multiple companies. In many cases, those workers retained credentials for numerous corporate environments, which meant a single compromise could open paths into several organizations at once.

Researchers said this practice significantly increased the scale of the breaches. In effect, one infected contractor system could expose critical infrastructure across different employers or clients, creating opportunities to steal data, permissions, and digital assets from multiple businesses.

Crypto remained the central target

Although the campaign also reached sectors such as healthcare, finance, government, and technology, investigators said the effort consistently centered on cryptocurrency theft. The combination of wallet credential theft and access to cloud and administrator systems suggests crypto companies remained especially attractive targets.

The report did not frame every intrusion as identical, but it presented a clear pattern: state-backed operators used recruitment lures to obtain privileged access, then leveraged that access toward digital asset theft wherever possible.

What researchers say comes next

The research points to contractor security and identity controls as immediate pressure points for organizations reviewing their defenses. Security experts cited in the findings said companies should tighten oversight of contractors, reduce privileged access, and continuously monitor credentials for misuse.

They also said faster incident response is increasingly important as state-backed cyber operations become more sophisticated. Based on the investigation, the next confirmed step for affected organizations is to review contractor permissions and watch for signs of compromise linked to developer hiring workflows and downloaded coding-test software.

Source: Coin Edition