I made the last minute decision to travel to Las Vegas and attend the Black Hat cybersecurity conference. I was looking forward to reuniting with a cast of characters I’d already encountered while producing my film, “The Only Human in the Room.” I didn’t exactly have a plan, but I was banking on this reporter’s lifelong trove of serendipity to guide me to an editorial pot of gold. I had 36 hours.
DTEX’s Michael “Barni” Barnhart delivered at the 27-hour mark, assembling a small alliance of intelligence-gathering peers who were also in town for the conference. We found an empty hotel ballroom, and started filming.
We quickly determined the conversational premise: North Korea is a massive, state-sanctioned criminal syndicate. As such, it was an early adopter of AI-technologies (all the more better to surveil you), from facial recognition to deepfakes. The rest of the world, especially traditional corporate security and law enforcement continually struggle to play catch-up against these seemingly sophisticated cyber operations. See Exhibit A, DTEX’ excellent report, Exposing DPRK’s Cyber Syndicate and Hidden IT Workforce.
But smaller, more decentralized “freelance” collectives are acting faster than bureaucratic institutions to disrupt DPRK operations. Barni’s group includes Nick Roy, the founder of the reputed North Korean intelligence website nkinternet.com. During our chat, he explained how effective he was in setting traps for scammers by posing as a college student on Telegram, getting recruited by DPRK operatives, and successfully turning the tables on them by harvesting their IP addresses and computer names.
Japan-based cybersecurity researcher “SttyK” is even closer to the front lines with his work, which is why he’s compelled to wear a Guy Fawkes mask to conceal his identity. He’s actually able to monitor what the North Korean IT operatives are saying to each other and doing, monitoring their Google Chrome histories and translation logs. It’s a remarkably mundane operation, leveraging free offerings from ChatGPT and Google Translate. SttyK presented to Black Hat this year as he did in 2025, which led last August to a Wired article detailing the incredible extent of his research. I’m a Wired subscriber, but if you’re not, I concocted this graphic summarizing what SttyK’s data leak revealed about how the North Koreans infiltrate tech companies.
And this week, Wired published another expose on North Korean espionage:
Since Greece-based cybersecurity researcher Vangelis Stykas gained access to North Korean systems 22 months ago, he says, he has found evidence that 1,640 companies across 57 countries have been impacted by the country’s hacking operations. Among these, Stykas will detail at the Black Hat security conference in Las Vegas today, around 700 to 800 of the impacted organizations have had “really damaging” intrusions.
Ultimately, the collegial humanity of Barni, Nick, and SttyK (he even explained the somewhat profane origins of his moniker) convinced me that their collective’s agility and intelligence-sharing are what has led to their success against a seemingly formidable foe.








