INSIDE THE MACHINE
What twenty-two months inside North Korean command infrastructure reveals about how the operation actually runs — and what it does next
Bottom line
For twenty-two months, a Greek security researcher lived inside the command infrastructure of a North Korean cyber operation and watched it work. Vangelis Stykas — CTO and co-founder of Kumio — gained access in roughly October 2024 and held it, apparently uninterrupted, until he presented what he found at Black Hat USA on 6 August 2026. The headline numbers have been everywhere since: about five terabytes of data, visibility into the operators’ own Slack and Discord channels, their source code and keys, and enough victim material to map 1,640 affected companies across 57 countries, of which he assessed 700 to 800 held severe exposure.
Those numbers are the least interesting part of the disclosure, and two of them are routinely misread. This assessment is about the operation behind them.
The single most important thing the intrusion revealed is not how much the operators took. It is what they left. Sitting inside root-level access to a children’s hospital holding the health records of millions of Americans, and to another firm holding criminal records, the operators took the crypto and ignored the rest. That is not restraint and it is not an oversight. It is the clearest possible statement of what this operation is for, and it reframes every other finding.
Our assessment is that this is a high-throughput, revenue-driven crypto-theft production line, run by an organisation with real capability at its core objective and conspicuously little discipline everywhere else — the same organisation, at the end of the money trail, that funds North Korea’s munitions programme and its material support to Russia. It coordinates over commercial platforms from outside North Korea. It has been penetrated by at least three separate researchers, which tells you it has almost no capacity to protect itself. And it is sitting on a reservoir of severe, unused access to hundreds of organisations with nothing to steal financially — a dormant espionage capability that a single tasking decision in Pyongyang could switch on.
The rest of this report shows how we reach those judgments from what was actually disclosed, marks clearly where we are inferring, and — because we had a prior draft and this version corrects it — is candid about one judgment we got wrong before the full research corpus was in front of us.
Key judgments
Each judgment carries two ratings, kept separate on purpose. Confidence describes how good the evidence is. Likelihood describes how probable the outcome is. Collapsing the two — which most reporting does — hides exactly the information a reader needs.
KJ-1 The operation is crypto-selective to the point of leaving espionage-grade access untouched
An operation that walks past millions of health records to grab a crypto wallet is telling you precisely what it is measured on. Everything else observable about it follows: indiscriminate delivery, rapid re-tooling, reuse of the same lure for over three years, and a monetisation focus so narrow that valuable non-financial access is left on the floor. We assess with high confidence that yield in convertible cryptocurrency is the operation’s governing metric and that other data is, to these operators, noise.
So what: your exposure to this specific operation depends heavily on whether you hold anything it can convert to currency. If you do — wallets, keys, exchange access, custody tooling — assume fast, focused theft. If you do not, the near-term theft risk is genuinely lower than the headlines imply. But do not exhale yet, because the access itself does not evaporate just because they did not use it. See KJ-2.
KJ-2 Hundreds of organisations hold a dormant DPRK espionage capability that has simply not been switched on
This is the sharpest strategic-warning finding in the disclosure, and it is corroborated from inside the industry. Marcus Hutchins of Expel, tracking the same actor, put it plainly: the crypto teams stick to crypto, but they maintain persistent corporate access, and an espionage team could piggyback on it at any time — all it would take is one person being handed the access. The separation between what this operation does today and what the North Korean state could direct it to do tomorrow is a management choice, not a technical barrier.
We assess it is likely the access stays dormant in the near term, because activating it cuts against the revenue focus and risks the crypto operation’s tempo. But the judgment that matters is the conditional one: the interval between “dormant foothold” and “active intelligence collection at a hospital, a bank, or a judicial council” is a single instruction, and nothing in the operation’s structure would slow that instruction down.
So what: an organisation with no crypto exposure that appears in this dataset is not safe; it is holding a loaded position that has not yet been fired. The correct response is not relief that they took nothing — it is to treat the access as live and remediate it as though espionage had already begun, because the warning time on that switch is effectively zero.
KJ-3 This is a throughput business with almost no operational discipline
Default malware user-agents that make traffic trivially identifiable. A hardcoded archive password of “2024.” Base64 slicing passed off as obfuscation. Malware published unobfuscated to public registries. Infrastructure reused across months. Fake developer accounts with a single stale repository. And, most tellingly, self-infection sustained at a scale and duration that let an outsider pivot into the core and stay for nearly two years. This is not what a disciplined offensive programme looks like. It is what an organisation looks like when throughput is the only thing measured and hygiene is nobody’s job.
So what: this adversary will not go quiet after being exposed. A unit under a revenue quota re-tools and continues; it does not stand down to lick its wounds. Any hardening plan premised on a post-disclosure lull is planning for a pause that is not coming.
KJ-4 The programme has essentially no capacity to protect itself, and it has now been penetrated at least three times
The asymmetry is total: this operation surveils its victims obsessively — keylogging, screenshots, clipboard capture — and appears to monitor itself not at all. More damning still, victim remediation was under way by at least March 2026, as organisations were pulled off the board one by one following responsible disclosure, and the operators reportedly still did not notice their own infrastructure had been compromised. An organisation that cannot detect its own victims disappearing has no counterintelligence function in any meaningful sense.
So what: this operation is penetrable and will very likely be penetrated again, both because the weakness is structural and because Stykas has just shown the research community it can be done. For CTI teams that is a collection opportunity. For everyone else it is a reason to build the internal process for handling a researcher notification now, because more are coming.
KJ-5 The operators work from permissive commercial environments, dispersed outside North Korea
Domestic North Korean networks are too restricted and monitored to run persistent commercial workspaces from. The tooling choice corroborates the well-documented picture of DPRK cyber and IT-worker personnel deployed across more than forty countries, concentrated in China and Russia, under the Reconnaissance General Bureau — but corroborates it from a new angle: not defector testimony or seized laptops, but the operators’ own unforced preference for convenience over security, the same trade visible everywhere else in their tradecraft.
So what: there is a disruption surface here that is neither military nor diplomatic. Commercial platform-abuse teams can act where domain takedowns cannot, and they have. Expect that pressure to grow — and expect the operators to migrate toward self-hosted or decentralised coordination in response, which costs them the tempo they optimise for. They have already shown the appetite: their payload delivery moved onto public blockchains (Section 3).
KJ-6 The contractor multiplier is now known to both sides
Twenty-two months of accumulated take, showing which compromises yielded one set of credentials and which yielded thirty, is a feedback loop sitting on their own infrastructure. An operation this data-driven has almost certainly noticed that consultants, managed-service engineers, and prolific open-source maintainers are worth many times an in-house hire. We assess it is likely targeting has already begun tilting toward them, and that the shift becomes measurable in incident-response reporting over the next two to three quarters as a rising share of victims who were contractors rather than employees. The early signal is already faintly visible: of the organisations named publicly, both Coinbase and Boston Children’s located their exposure on a contractor or personal device rather than inside their own environment.
So what: the organisations most exposed can see it least, because a contractor’s other clients are invisible to them by construction. Ask every engineering supplier how many concurrent clients each assigned engineer serves and what access they hold at each. Most have never been asked. The answer is a direct input to your blast-radius model and, for many readers, the most alarming number they will collect this year.
KJ-7 Intrusion and IT-worker fraud share a services layer, not a command
We assess it is very likely they share infrastructure and services and unlikely they run as a single command. The evidence supports a common support apparatus — the same people building fake companies, laundering identities, and moving money for both — rather than merged tasking. The distinction is legal as much as analytical (Section 7), and collapsing the two causes organisations to prepare for the wrong incident and to leave counsel out of a response where sanctions exposure required them in the room.
KJ-8 The research and threat-intelligence community is squarely in the target set
An operation already probing CTI platforms, now comprehensively humiliated by two researchers who lived inside its infrastructure, has both motive and demonstrated inclination to hit the research community harder. Researchers are also, conveniently, developers — the exact population this campaign is built to compromise, requiring no adaptation of the tooling. Their organisations hold unusually attractive material: customer telemetry, unpublished research, and victim-notification lists.
So what: if you work in threat intelligence, security research, or incident response, you are in the target population twice over. Treat your own analysts’ endpoints as the highest-risk population you run, not the most trusted, and do not assume technical sophistication confers immunity to a well-built recruitment lure.
KJ-9 The money terminates at North Korea’s weapons apparatus and its support to Russia
The end of this money trail is not abstract. Revenue pools upward through team collectors into centrally held leadership accounts and feeds sanctioned entities, weapons manufacturing, and procurement — and, per the same reporting, North Korea’s material support to Russia, measured in tens of thousands of containers of ammunition and thousands of troops. A compromised developer credential is the front end of a chain that terminates in artillery.
So what: for boards and executives, this is the framing that makes the threat legible. This is not fraud in the abstract; paying a DPRK-linked worker or losing a wallet to this operation is, at the far end, a contribution to a munitions programme — which is also why the sanctions exposure in Section 7 is strict and unforgiving of good intentions.
KJ-10 The defensible number is 175, not 1,640
The 175-plus figure describes organisations where stolen credentials were verified as still live — the strongest standard in the set. The 1,640 figure describes organisations identified through analysis of attacker infrastructure, which is inference from artifact presence and depends entirely on an unpublished definition of “impacted.” And the 1,500 figure that sits between them is not a measure of the operation at all: by the source’s own reconciliation it is the number of hosts Stykas personally triaged. Anyone repeating “1,640 companies breached” is making a claim the public evidence does not support, and anyone treating the 1,500 as the operators’ processing rate — as we ourselves did in the prior draft — is misreading the researcher’s workload as the adversary’s.
2. What the access actually was
Before drawing conclusions from a dataset it is worth being precise about what the dataset is, and this one is unusual in ways that cut in both directions.
Stykas obtained access to the North Korean command-and-control infrastructure around October 2024 and held it for roughly twenty-two months, up to his Black Hat presentation in August 2026. The enabling failure, as reported, was operator self-infection: the people running the campaign had their own systems compromised by the same commodity stealers they deploy against victims, which opened a channel from those operator workstations back into the shared infrastructure. From there he reportedly had visibility into the operators’ Slack and Discord coordination, their source code and developer keys, infrastructure artifacts, and roughly five terabytes of victim data staged on the C2.
Three properties make this analytically valuable in a way ordinary threat research is not.
It is longitudinal. Twenty-two months is long enough to see behaviour change over time. Most threat intelligence is a photograph — a sample detonated, an infrastructure cluster enumerated. This is closer to time-lapse, which is what permits judgments about tempo and about how the operation responds to pressure.
It is internal. Visibility into the operators’ own coordination is categorically different from visibility into their malware. Malware tells you what an operation built. Internal channels tell you how it decides and what it measures. Even unpublished, the existence of that material changes the confidence with which the operating model can be reasoned about.
It is unreproducible. And here the value is bounded. The access method is deliberately undisclosed, which is defensible but means no third party can audit the collection or assess how representative it was. The corpus is described but not published, and for victim-privacy and legal reasons almost certainly never will be. The slide deck, whitepaper, and indicator package were all still unreleased as of this writing.
The evidentiary limit, stated plainly
Evidence obtained through unauthorised access to adversary infrastructure sits in unresolved legal territory in most jurisdictions. That does not make it useless — it makes it a lead rather than a finding. An organisation contacted by this kind of research should treat it as a high-priority trigger for its own investigation and base every disclosure on its own telemetry, not on the researcher’s claim. Several organisations named here did exactly that and found the exposure narrower than a breach.
One caution belongs on the record. It is conceivable that a sophisticated adversary aware of a researcher’s presence could shape what remained visible. We assess this as unlikely and toward the lower bound: the disclosure produced actionable notifications that multiple organisations independently confirmed and remediated, which is expensive and counterproductive for a deception. But twenty-two months is long enough that the question is not frivolous, and an assessment that never asked it would be incomplete.
3. The self-infection tell — and the pattern around it
If you read one section of this assessment, read this one. That the operators infected themselves has been reported almost everywhere as an irony — the hackers got hacked, a satisfying coda. Read as evidence rather than as a joke, it is the second most informative thing in the disclosure, and reading it correctly depends on seeing that it does not stand alone.
Start with what self-infection requires to be true. BeaverTail, InvisibleFerret, OtterCookie and their relatives are indiscriminate collectors — browser credential stores, wallet extensions, SSH keys, environment files, clipboard, screenshots. They do not distinguish a victim’s machine from a builder’s. For operators to have infected themselves, they were running or testing their own payloads in an environment that also held operational material and reached the same infrastructure they used to run the campaign. That is a segmentation failure, and segmentation between a malware development environment and an operational one is not an advanced practice — it is the first thing any competent offensive team builds, precisely because the consequence of skipping it is what happened here.
What turns this from an anecdote into a judgment is that it is not isolated. The research base documents a consistent pattern of the same trade — convenience over security — across the operation’s tradecraft:
• Self-infection with the operators’ own commodity stealers, sustained long enough for an outsider to pivot into the core and stay nearly two years.
• A default malware user-agent — python-requests/2.25.1 in InvisibleFerret — that makes the traffic trivially identifiable to any defender who looks.
• A hardcoded default archive password of “2024” for the ZIP and 7z files used to stage stolen data.
• C2 addresses “obfuscated” with sliced Base64, which is encoding, not obfuscation, and defeats nobody.
• Malware published unobfuscated to public package registries on multiple documented occasions.
• Infrastructure and C2 domains reused across months of operations rather than rotated per campaign.
• Fake developer accounts with a single stale repository and no update history — identifiable as inauthentic at a glance.
The delivery record corroborates the same reading from a different direction. Since late 2022 the operation has cycled through malicious repositories, then package-registry seeding at a scale of hundreds of packages per wave, then trojanised video-conferencing installers, then ClickFix paste-the-command lures, then IDE task-configuration abuse, then payload fragments concealed in SVG project assets. That is roughly six substantive delivery re-tools in thirty-two months — and across all of them the initial-access concept never changed once: persuade a developer to run our code during a hiring process. This is an organisation that iterates hard on the mechanism and not at all on the model, because the model works and iteration on the mechanism is what you do when your infrastructure keeps getting burned. It is not the profile of an operation trying to stay hidden. One optimising for stealth reduces volume and invests in not being seen; this one seeds hundreds of packages into registries that vendors actively hunt and generates thousands of near-identical personas.
We assess it is very likely detection is priced in as a cost of doing business rather than treated as failure. The operation appears to have concluded — correctly, on the evidence — that it can lose infrastructure continuously and still hit its numbers, because the supply of developers willing to run a coding assessment is effectively unlimited and standing up new infrastructure costs almost nothing.
What this means for the next twelve months
The standard post-disclosure expectation does not apply. When a well-resourced espionage service is exposed it typically goes quiet, re-tools deliberately, and returns with better tradecraft — a pattern driven by an organisation that values its access and can afford to pause. This operation is not that. Because Stykas’s access reportedly ran right up to the presentation, the operators most likely learned of the intrusion from the public disclosure itself rather than months earlier, which means their infrastructure rotation is being triggered now, in the weeks around this report, not last quarter. We assess it is very likely they rotate comprehensively, make modest and uneven improvements to operator hygiene, and continue at or near current tempo. There is no lull to plan around.
4. The funnel, read correctly
This is the section this report gets most wrong if it is not careful, and the section our prior draft did get wrong. The numbers everyone quoted are layers of one funnel with different evidentiary standards, and reading the ratios between them as if they described the operation’s internal workflow is a trap we walked into and are now walking back.
The layers, with what each actually measures: around 96,000 developer workstations reached through malicious packages — a distribution figure, every developer who executed a package, not a compromise count. More than 1,500 hosts triaged in detail — and this is the critical correction, because by the source’s own reconciliation that is the number Stykas personally analysed, a measure of one researcher’s workload, not the operators’ throughput. Over 175 organisations where stolen credentials were verified as still live — the strongest standard in the set. Ninety-nine organisations contacted through coordinated disclosure. And, at the widest ring, 1,640 companies across 57 countries inferred from analysis of the attacker infrastructure, of which 700 to 800 were assessed as holding severe access.
The correction, and why it matters
Our earlier draft read the drop from 96,000 to 1,500 as evidence of a human bottleneck inside the operation — a queue of stolen credentials waiting for an operator, and therefore a lag between compromise and exploitation that defenders could exploit.
That inference does not survive the source. The 1,500 is the researcher’s triage sample. It says nothing about how fast the operators process what they steal, and building a defensive recommendation on it would have been building on sand. We are retracting it, and replacing it with something the evidence does support.
What the funnel does support: ruthless selectivity
The reliable signal in these numbers is not a processing rate. It is the shape of what gets acted on versus what gets left. The operators reached tens of thousands of machines and verified live credentials at 175-plus organisations, and inside the severe-access subset they consistently took cryptocurrency material and ignored everything else — including, at named victims, health records on millions of people and Americans’ criminal records. The narrowing of the funnel is therefore not primarily a capacity story. It is a selection story: this operation collects broadly and exploits narrowly, along a single axis of monetisable value.
That distinction changes the defensive conclusion in a way that matters. For an organisation holding convertible crypto value, the operation is fast and focused, and the old advice holds in its sharpest form: assume theft is immediate and rotate everything reachable from a compromised developer endpoint within the hour, because there is no queue protecting you. For an organisation holding no crypto value, the picture is different and more uncomfortable: the operators may well have taken nothing, not because you were defended but because you had nothing they wanted — while leaving in place the severe access that KJ-2 identifies as a dormant espionage capability. The absence of theft is not the absence of compromise.
Severity is potential, not proof
The 700 to 800 severe-access figure describes what the operators could have done — root on servers, cloud control, crypto keys. The selectivity finding tells us directly that they did not do it everywhere; at the non-crypto victims they demonstrably did not act on the access at all. For defenders this means an organisation appearing in the dataset should investigate urgently but must not read the notification as proof of exploitation. For analysts it means the figure is an inventory of opportunity — a statement about reach, not about damage — and conflating the two inflates the assessment in a way the eventual whitepaper will not support.
5. The organisation behind the operation
Attribution reporting usually stops at the cluster name. What a defender actually needs is a sense of what kind of organisation is on the other end, because that determines what it does next, what it responds to, and what it cannot easily change. The research base now supports a more concrete picture than inference alone would.
Who runs it
The apparatus behind these operations sits under North Korea’s Reconnaissance General Bureau, with the IT-worker revenue machinery reported under Department 53 and its front companies — Korea Osong Shipping, Chonsurim Trading — and its recruitment pipeline drawing from elite institutions including Kim Chaek University of Technology and the University of Sciences in Pyongsong. South Korea’s intelligence service assessed the total DPRK cyber workforce at around 8,400 in 2024, up from 6,800 two years earlier, with tens of thousands more deployed as IT workers across more than forty countries. This is not a small cell. It is an industrial programme with recruitment, training, deployment, and revenue-collection functions.
It coordinates on commercial platforms, which places its people
Slack and Discord are not the tools of a team inside North Korea’s restricted domestic network. The choice corroborates the dispersal picture above from a new angle — the operators’ own unforced tooling preference rather than defector testimony or seized hardware — and it tells you something about priorities. Those platforms are convenient, and they are also logged, subpoena-reachable, and subject to abuse-team action. Choosing them over self-hosted alternatives is the same convenience-over-security trade visible in the self-infection failure and the six OPSEC lapses beside it. We assess with moderate-to-high confidence this is a consistent organisational property rather than scattered mistakes.
It is measured on output, and the measurement shapes everything
The scale of the revenue objective is now well established. U.S. Treasury assessed the IT-worker scheme alone at close to $800 million in 2024. Blockchain analytics firms put total DPRK cryptocurrency theft since 2017 above six billion dollars, with a single year — 2025 — accounting for roughly two billion. Almost every observable characteristic of Contagious Interview follows from managing to numbers of that size: wide indiscriminate delivery, rapid re-tooling after each burn, reuse of a working lure for over three years, weak internal discipline, and the ruthless crypto-selectivity that leaves espionage-grade access untouched. Organisations built this way respond to pressure on output, not to pressure on exposure. Attribution, indicator publication, and infrastructure takedown impose costs this operation has already shown it absorbs. What bites is anything that reduces yield per compromise.
6. Following the money to the munitions programme
The strategic weight of this threat is easiest to underestimate from inside a security team, where it reads as credential theft and fraud. Following the money changes the register entirely, and the research base now allows that trail to be drawn with unusual specificity.
In April 2026 the on-chain investigator ZachXBT obtained data from an internal DPRK payment platform — a Discord-style remittance system where operatives report earnings to handlers. The leak comprised 390 accounts, chat logs, and transaction data, secured, in a detail that belongs in Section 3, by the password “123456.” The platform’s structure is a money-laundering topology in miniature: individual contributions in the low thousands of dollars, team collectors remitting tens to over a hundred thousand at a time on behalf of multiple workers, and value pooling upward into centrally held leadership accounts. Payments referenced an “RB wallet” — Korea Ryonbong General Corporation, an OFAC-designated entity under North Korea’s Munitions Industry Department.
For an intelligence consumer, this reframes the risk calculus. The exposure is not merely financial or reputational. Money moving to this apparatus moves to a designated munitions entity, which is why the sanctions posture in Section 7 is strict and why “we were deceived” is not a defence to the underlying violation. It also sharpens the stakes of the dormant-access finding in KJ-2: the same organisation that funds a weapons programme is sitting on unused root access to hospitals, banks, and a judicial council, one tasking decision away from using it.
7. The contractor discovery
The finding that a single compromised contractor carried credentials for as many as thirty companies has been reported as a victimology detail. We think that framing misses it, and that this is the most consequential operational lesson in the disclosure — for the operators as much as for defenders.
Consider it from their side. The campaign has run since at least late 2022, and the take from every compromise lands on their infrastructure and accumulates. Twenty-two months of that data — enough that a researcher mapped 1,640 organisations from it — necessarily contains the signal that some endpoints yield one set of corporate credentials and others yield thirty. That is a feedback loop in their own dataset. Any operation managed against output, with access to a signal that strong, will optimise against it. The only real questions are whether they have noticed and whether they have restructured targeting yet.
If the shift is happening it should produce observable changes, and naming them in advance is what makes the judgment falsifiable. Expect recruiter personas increasingly aimed at consultancies, managed-service providers, and independent contractors rather than in-house engineers; lures tailored to freelance platforms; rising interest in prolific open-source maintainers, whose endpoints bridge unusually many trust domains; and, in incident-response reporting specifically, a growing share of cases where the compromised individual was not an employee of the affected organisation. That last indicator is already faintly visible: of the organisations named publicly, both Coinbase and Boston Children’s Hospital located their exposure on a contractor or personal device rather than in their own environment.
Why this is structurally hard to defend
The asymmetry is the problem. A contractor’s other clients are invisible to you by construction. You can harden your environment comprehensively and still inherit a compromise from an engineer whose exposure happened entirely outside your visibility, on a device you do not own, through an interview for a fourth company you have never heard of. Vendor-risk programmes assess the supplier as an entity — its certifications and policies — and essentially never ask the question that matters most here.
The question is: how many concurrent clients does each engineer assigned to us serve, and what access do they hold at each? Most contracting firms have never been asked, many will not know, and the ones that do know are often reluctant to say. All three responses are informative, and collecting the answers across your supplier base is probably the highest-value internal intelligence any reader of this report can gather this quarter.
8. Convergence with the IT-worker programme
Contagious Interview and DPRK remote IT-worker fraud attack the same trust surface from opposite directions — a fake employer weaponising the interview on one side, a fake or laundered candidate weaponising the employment relationship on the other. The convergence is real but frequently overstated in a specific and unhelpful way: reporting that treats them as one operation under unified command outruns the evidence. What the evidence supports is a shared services layer.
What appears to be shared
Persona generation is the clearest case, and it has industrialised. Both campaigns depend on manufactured identities at scale, and the tradecraft has advanced from cartoon avatars in 2022, through faces photoshopped onto stock bodies, to AI-generated imagery and, by 2026, real-time AI deepfake video used to defeat live interview screening. That last step prompted an eleven-nation coordinated alert on 31 July 2026 — five days before the Black Hat talk — and it directly counter-evolves the one control most companies had added, the live video interview. Front companies are the second shared element, the same corporate shells hosting malicious recruiting and employing laundered workers. Facilitator networks are the third — the people providing addresses, laptop farms, and financial accounts — and the layer law enforcement has hit hardest, with 137 laptops seized across 21 premises in June 2025 alone. Money movement is the fourth, the laundering apparatus traced in Section 6.
What appears not to be shared
Tasking, tooling, and tradecraft look distinct. The IT-worker programme requires patience, sustained employment performance, and the ability to pass prolonged human scrutiny; Contagious Interview requires volume and none of that. Different skill profiles, different management problems, and observable behaviour consistent with separate teams drawing on common support. There are documented moments where the two touch — the February 2025 Bybit theft of roughly $1.5 billion reportedly saw both a crypto-heist actor and a Contagious Interview cluster targeting the same exchange — but co-targeting is not unified command, and the cleaner reading is a shared apparatus rather than a merged operation.
Why the distinction matters beyond taxonomy
It matters legally. Sanctions exposure attaches to dealings with designated entities and to DPRK-linked employment. An organisation that suffered a Contagious Interview compromise is a victim. An organisation that has been paying a DPRK IT worker for six months may be a victim and simultaneously a party with an affirmative compliance obligation, because sanctions liability under U.S. programmes is generally strict — deception is not a defence to the underlying violation. Collapsing the two threats into one narrative causes organisations to prepare for the wrong incident, and specifically to leave counsel out of a response where counsel needed to be in the room before the first containment action.
For defenders the operational consequence of convergence is narrower than the headlines but more important: the two threats are almost always owned by different functions — security owns the malware, HR owns the hiring — and the identity-assurance problem sitting between them is owned by nobody. That gap is why organisations heavily invested in one path are often wholly unprepared for the other.
9. What happens next
This section is estimative. Each forecast carries a likelihood and is written to be falsifiable — if we are wrong it should be checkable from public reporting within the stated window rather than argued about afterwards.
Now, and over the coming weeks: infrastructure rotation, near-certainly
Because the researcher’s access reportedly ran up to the presentation, the operators most likely learned of the intrusion from the disclosure itself. That places the rotation now, in the weeks around this report, rather than months in the past. Every domain, IP, package name, front company, and persona associated with the exposed corpus should be treated as burned as of early August 2026. The practical consequence is that every published indicator list from this campaign is a retrospective hunting resource, not a forward control — and a meaningful fraction sits on shared cloud platforms whose hostnames get reassigned to legitimate services, so blocking on them carries real collateral risk.
Within months: partial hygiene improvement, unevenly applied
We assess it is likely the operators separate development and testing from operational environments, at least for the individuals directly implicated, because public humiliation creates internal accountability pressure that abstract policy does not. We assess it is unlikely the improvement is thorough or durable: the incentive structure that produced seven documented OPSEC failures has not changed, and discipline that costs tempo erodes fastest once the embarrassment fades. Expect visible tightening over roughly two quarters, then gradual regression.
Within months: migration off commercial coordination platforms — leaning likely
Our prior draft rated this a coin flip. The corpus tilts it toward likely, for one reason: these operators have already demonstrated both the appetite and the capability for takedown-resistant infrastructure. Their payload delivery moved onto public blockchains through the EtherHiding technique — read-only smart-contract calls that leave no transaction record and cannot be seized by any conventional means. An operation that has put its payloads beyond takedown has shown it will move its coordination too once Slack and Discord prove to be a liability, as they now spectacularly have. The countervailing force is the same convenience logic visible everywhere else in their tradecraft, which is why we stop at likely rather than very likely. This remains the single most diagnostic indicator to watch: migration confirms the operation can learn an expensive lesson; continued commercial-platform use after this exposure would confirm the throughput-over-discipline model in the strongest possible terms.
Within two to three quarters: measurable tilt toward multi-tenant targets — likely
Developed in Section 7. The observable is a rising share of reported incidents in which the compromised individual was a contractor, consultant, managed-service engineer, or open-source maintainer rather than an employee. Expect it to surface first in incident-response reporting rather than malware analysis, because it is a targeting change, not a tooling change, and malware-centric research will not see it.
The judgment that should worry policymakers most: activation of dormant access
We assess it is likely the 700-to-800-organisation reservoir of severe, unused access stays dormant in the near term, because activating it cuts against the revenue focus. But this is the forecast with the shortest warning time and the highest consequence if wrong. The Hutchins observation is the crux: the crypto teams stick to crypto, but the access they build and abandon is available to an espionage team the moment the state decides to task it. There is no technical work required to make the switch — the footholds already exist — so the transition from “dormant” to “active intelligence collection at a hospital or a judicial council” could happen with effectively zero observable lead time. We cannot forecast a tasking decision in Pyongyang. We can say that the capability is loaded and that the only thing between it and use is intent.
Within twelve to eighteen months: further disclosures of this kind — likely
This follows from KJ-4 and is now better-grounded than a single case would allow. Three separate outsiders have already been inside three parts of this apparatus — Stykas in the C2, Expel in an internal workforce tracker, ZachXBT in the payment platform. An operation that porous, combined with the strong incentive Stykas has just created for others to attempt the same, makes at least one further significant counter-intrusion disclosure against DPRK infrastructure likely within eighteen months. That prospect deserves a caution: this kind of research sits in unresolved legal territory, and a wave of imitators with less judgment than Stykas appears to have exercised carries real risk — to the researchers, to victims whose data passes through more hands, and to the legitimacy of the disclosure model itself.
10. What to do about it
The defensive literature on this campaign is extensive and largely correct; we will not reproduce it. What follows is the short list that flows specifically from what the disclosure revealed about how the operation works.
Rotate first if you hold crypto value; hunt for dormant access if you do not
The selectivity finding splits the response. If you hold anything convertible — wallets, keys, exchange or custody access — assume theft is fast and focused, and pre-authorise mass revocation: someone needs standing authority to revoke every credential reachable from a developer endpoint on suspicion, without a change ticket, before the investigation concludes. Most organisations have not assigned that authority, so the decision gets escalated at exactly the moment speed matters. Assign it, name the person, rehearse it.
If you hold no crypto value, the risk is inverted and easy to misread. The operators may have taken nothing — and left severe access in place. Your task is not to breathe out; it is to hunt for the foothold on the assumption it is still there, and remediate it as though espionage had already begun. The absence of theft is the most dangerous false comfort in this entire threat.
Ask your suppliers the contractor question
From KJ-6 and Section 7. For every engineering supplier, ask how many concurrent clients each assigned engineer serves and what access they hold at each, then ask what device they use and who manages it. This is a contractual conversation, not a technical one, and it will be uncomfortable. It is also the only way to see an exposure structurally invisible from your side. Where the answers are unsatisfactory the remedies are conventional — dedicated managed devices for privileged contractors, per-engagement identities with automatic expiry, contractual audit rights — but you cannot apply any of them until you have asked.
Reduce yield rather than chasing indicators
From Section 5. This adversary absorbs infrastructure loss without difficulty and is managed against output, not exposure. Measures that reduce what a successful compromise is worth — short-lived credentials, just-in-time privilege, no standing secrets on endpoints, isolation of untrusted execution — impose costs it cannot absorb the same way, because they reduce yield across every victim at once rather than forcing a one-time rebuild. The single highest-leverage control remains isolating recruiter-supplied code from any environment holding secrets or privileged sessions; it intervenes before the loader runs and makes everything downstream unreachable, which no detection control can match.
If you ship software or hardware, trace the path to a signed artifact
Public reporting’s crypto focus causes non-crypto product companies to read themselves out of the target set. That is a mistake compounded by the dormant-access finding: even if this operation takes nothing from you today, the reachable path from a compromised engineer to a signed release remains, and a future tasking of that access is a product-integrity event affecting every downstream customer. The diagnostic is one question — from a developer laptop, how many independent human approvals and non-exportable key operations sit between a commit and a signed release reaching customers? Fewer than two is the finding, and it outranks everything else on this list.
Treat researcher notification as a lead, not a verdict
From Section 2 and KJ-10. If a researcher contacts you claiming to have found your credentials in adversary infrastructure, investigate urgently and treat it as high-priority — but do not declare a breach on the strength of it. Base every regulatory or customer disclosure on your own telemetry, preserve the notification in the incident record, and note that the lead came from research obtained through means you cannot audit. Several organisations named in this disclosure investigated and found the exposure sat on a contractor or personal device rather than in their environment. Those that had announced first would have had a difficult retraction to manage.
If you work in this industry, you are in the target set
From KJ-8. Threat-intelligence analysts, researchers, and incident responders are developers holding unusually sensitive material, and this campaign is purpose-built to compromise developers. Apply your own advice to your own analysts: their endpoints should be the most constrained population you run, not the most trusted.
11. Confidence, gaps, and what would change this assessment
This assessment rests on a narrow evidentiary base and readers are entitled to know how narrow. The scale figures and internal-visibility claims trace to one researcher, one presentation, and one piece of tier-one journalism reporting both, with the slide deck, whitepaper, and indicator package all unreleased and the access methodology deliberately withheld. The technical corpus around the campaign — malware behaviour, delivery evolution, infrastructure, the money trail — is broad and well-sourced across vendors and government, and it is what allows the operating-model judgments to be drawn with more confidence than the Stykas disclosure alone would support. The volume of derivative press restating the scale figures adds no corroboration and is excluded from every confidence rating here.
Everything about the internal character of the operation — the crypto-selectivity as a governing metric, the absent security function, the contractor optimisation — is analytic inference from observed artifacts. We believe the inferences are well grounded and have shown the reasoning so readers can disagree with specific steps. But they are our judgments, not the researcher’s findings, and this version has already demonstrated the cost of over-reading a ratio: the funnel-bottleneck judgment in our prior draft did not survive the source, and we have retracted it.
The four things that would most change this assessment
Release of the presentation materials. The deck or whitepaper would establish how “impacted” was defined and what evidentiary standard sits behind each funnel layer, allowing KJ-10 and Section 4 to be tested directly rather than argued. Highest-value collection item available.
Any confirmed activation of dormant access at a non-crypto victim. KJ-2 assesses the espionage capability as dormant. A single confirmed case of intelligence collection — rather than crypto theft — at a hospital, bank, or government body would move this from a conditional warning to an active pattern and would require rewriting the operation as something other than a pure revenue business.
Evidence that crypto-selectivity is loosening. KJ-1 rests on the operators consistently ignoring non-crypto data. Reporting that they have begun harvesting broadly — documents, IP, personal data — would indicate either a change in tasking or the arrival of a second objective on the same access, and would undercut the tidy revenue-business framing.
Whether the operators migrate off commercial coordination platforms. The most diagnostic single indicator over the next two quarters, and a direct test of whether this organisation can act on an expensive lesson. Their prior move onto blockchain payload delivery is why we now lean toward expecting it.
Where we may be wrong
The most likely failure mode remains over-reading a small number of vivid details — and we have already made that error once, with the funnel. The self-infection argument in Section 3 is now buttressed by six additional documented OPSEC failures, which makes the throughput-over-discipline reading more robust than a single anecdote would allow; but if the broader pattern turns out to reflect a few careless individuals rather than an organisational property, the judgments flowing from it soften. We hold KJ-3 at moderate-to-high, not high, for that reason.
The second and more serious risk is the inverse of our own framing. We have characterised this as a revenue business that leaves espionage access idle. It is possible the idle access is not idle by neglect but idle by design — held deliberately in reserve, the quiet capability preserved behind the noisy crypto theft that everyone was meant to see. We assess this as less likely than simple revenue focus, but “the loud part is the part you were meant to find” is a pattern with precedent in state operations, and the consequence if it is true is precisely the KJ-2 scenario arriving faster than expected. An assessment that dismissed it would be doing the reader a disservice.
Sources and grading
Sources are graded using the Admiralty System — a letter for reliability, a numeral for credibility. The grading is included because the base for this topic mixes original vendor and government research, a single-researcher disclosure, tier-one journalism, and a long tail of derivative aggregation that repeats the same claims without adding evidence. Volume of coverage is not corroboration.
Load-bearing sources
• WIRED (5 August 2026) — B2. Primary reporting of the Stykas disclosure. Reliable outlet; credibility bounded by the single-source nature of the underlying claim. Origin of the scale figures and the ignored-non-crypto-data finding.
• Shostack + Associates Black Hat preview (23 July 2026) and Black Hat briefings listing — B2. Talk abstract metrics and the funnel figures, including the reconciliation that the 1,500 hosts were the researcher’s own triage sample.
• Expel / Marcus Hutchins (April 2026) — B2. Independent tracking of the same actor, the dormant-espionage-access warning quoted in KJ-2, and a second confirmed penetration — an internal workforce-tracking panel.
• DTEX money-trail research and ZachXBT on-chain leak (April–July 2026) — B2 / C2. The internal payment platform, its laundering topology, and the Ryonbong / Munitions Industry Department linkage underpinning KJ-9 and Section 6.
• U.S. Treasury (12 March 2026), DOJ (30 June 2025), FBI (23 July 2025) — A1. The ~$800M revenue figure, laptop-farm actions, and facilitator tradecraft. Strongest-graded material in this assessment.
• MITRE ATT&CK G1052 (v19) and Microsoft (11 March 2026) — A2. Campaign baseline, activity from at least December 2022, and malware family relationships.
• Google Threat Intelligence Group (16 October 2025) — A2. EtherHiding and the JADESNOW blockchain-C2 downloader; the basis for the migration forecast in Section 9.
• SentinelOne Labs (4 September 2025) — B2. Actor reconnaissance of commercial threat-intelligence platforms; the independent basis for KJ-8.
• Eleven-nation joint alert (31 July 2026) — A1. Real-time AI deepfake video defeating live interview screening; Section 8.
• Cisco Talos, Unit 42, ESET, Elastic, Silent Push, Socket, Sekoia, Jamf, Datadog, Panther, NTT, Nisos, Sygnia — A2 to B2. The technical corpus establishing malware capability, the OPSEC-failure pattern, delivery evolution, infrastructure, and laptop-farm tradecraft across 2023–2026.
• Coinbase and Boston Children’s Hospital public statements — C2. Self-interested but on the record, and load-bearing for the contractor-layer and selectivity arguments.
Excluded from corroboration
Derivative technology and cryptocurrency press coverage of the disclosure — TechTimes, Crypto Briefing, BeInCrypto, AI Weekly, Android Authority, graded D3 to D4 — restates the WIRED reporting without independent evidence and is excluded from every confidence rating in this document. Community actor trackers and encyclopaedia entries were used only for navigation and are cited nowhere as evidence.















