Skip to content
Vulnerability ResearchCVEendpoint-securitycredential-theft

22 months inside North Korea's attack infrastructure

3 min read
Share

22 months inside North Korea's attack infrastructure

The disclosure

A security researcher based in Greece presented findings at Black Hat USA 2026 from an unprecedented access period: 22 months inside multiple North Korean command-and-control systems. The material, approximately 5 TB, included access to attacker workstations, Slack channels, Discord servers, and operational records covering DPRK cyber activity across multiple campaigns.

The disclosure links 1,640 organizations across 57 countries to DPRK operations. Between 700 and 800 of those organizations experienced confirmed serious intrusions, defined as root access to servers or full access to AWS environments.

Why the scale matters

Public reporting on DPRK cyber operations has historically focused on high-profile incidents: cryptocurrency exchange thefts, defense contractor breaches, financial system targeting in Southeast Asia. That framing creates a mental model of North Korean hackers as specialized and targeted. The Black Hat data revises that model. 1,640 victim organizations across 57 countries is not a targeted operation against a specific sector. It describes a broad, persistent, systematic effort to establish access across global enterprise infrastructure, maintain it quietly, and exploit it opportunistically.

The 57-country distribution also contradicts a common assumption that DPRK cyber operations primarily target the US, South Korea, and Japan. The actual victim distribution is substantially more global.

What the C2 access revealed

The researcher's 22-month observation period captured DPRK operators conducting their work using Slack and Discord. This creates both an intelligence opportunity and an operational security observation: DPRK actor groups are not running fully air-gapped, custom communication infrastructure. They use commodity tools that leave persistent, searchable records.

Implications for defenders

The victim list revision means organizations that have dismissed North Korean threat actor relevance based on sector or geography should revisit that assessment. The data suggests DPRK-affiliated groups are maintaining persistent access in organizations across a wide range of industries.

Root-level access and AWS environment compromise indicate that DPRK operations are not limited to credential harvesting or data exfiltration. The access profile described is consistent with pre-positioned capability for long-term persistence and potential destructive action.

For threat intelligence teams: cross-reference your environments against the IOC sets that will emerge from the Black Hat disclosure over the coming weeks. Organizations that believe they may be among the 1,640 should contact their national CERT and monitor threat intelligence feeds.

What comes next

The DPRK cyber operation arc is expanding. CVE-2026-68820, the WinSock kernel rootkit used in Operation Dream Job, adds kernel-level persistence capability to the picture. The 22-month C2 access disclosure adds scale. Together they describe a threat actor that is more capable, more broadly deployed, and harder to detect than most current defensive postures assume.

Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if your organization needs to evaluate North Korean threat actor exposure in your environment.

Related articles