Impacted entities include global technology firms like Oppo, major cryptocurrency platforms such as Coinbase and Uniswap Labs, and sensitive public institutions including Boston Children’s Hospital.
The breaches are significant because they provided state-sponsored actors with root access—the highest level of system permissions—to private servers and cloud computing environments like Amazon Web Services (AWS).
While the hackers gained entry to systems containing sensitive personal health data and criminal records, their primary objective was the theft of cryptocurrency and blockchain keys.
According to the source, these stolen funds are used to finance the North Korean regime and its weapons programs.
The hackers primarily infiltrate organizations through a tactic called "Contagious Interview," where they lure software developers with lucrative fake job offers.
Targets are tricked into downloading malware disguised as coding tests, which then compromises their workstations and steals developer keys or source code.
This method is especially dangerous when used against external contractors who manage systems for multiple clients, as a single successful infection can grant the hackers a foothold in dozens of corporate networks simultaneously.