기사 메일전송
North Korean hackers' computers hacked, revealing evidence of infiltration into Korean government and companies.
  • Yonhap News
  • August 13, 2025 at 10:13 AM
기사수정
  • Another group of hackers claims to have infiltrated North Korean computers, reports a specialized magazine.


North Korean IT personnel disguised with false identities (PG)North Korean IT personnel disguised with false identities. Yonhap News


Amid reports that North Korea is seeking to acquire foreign currency, including cryptocurrency, through hacking, a claim has emerged that hackers have infiltrated the computer of a North Korean hacker.


According to IT publication TechCrunch on the 12th (local time), two hackers, known by the names 'Saber' and 'cyb0rg', have infiltrated the computer of a North Korean hacker and published the details in the latest issue of the cybersecurity electronic magazine 'Phrack'.


In their article, the hackers stated that they infiltrated the work computer used by a hacker referred to as 'Kim'.


TechCrunch reported, "This incident is a nearly unprecedented look into the internal activities of 'Kimsuky'," adding, "While security researchers and companies have primarily analyzed data breach incidents, these two hackers directly hacked into the computer of an organization member."


The computer contained a virtual machine (VM) and a virtual private server (VPS), and 'Kim' was identified as belonging to 'Kimsuky', a hacker group under the North Korean Reconnaissance General Bureau.


'Kimsuky' is a well-known advanced persistent threat (APT) group operating within the North Korean government, focusing on targets of interest to government agencies in various countries, including South Korea, and North Korean intelligence agencies.


Like other hacking organizations, it also carries out cybercrime operations and is known to steal and launder cryptocurrency to fund North Korea's nuclear weapons program.


The two hackers wrote, "This incident offers a glimpse into how openly 'Kimsuky' collaborates with Chinese government hackers and shares their tools and techniques."


They also claimed to have discovered evidence that 'Kimsuky' had hacked into South Korean government networks and several companies. Specific names of the agencies and companies were not disclosed.


Furthermore, they reported finding various data, including email addresses, hacking tools used by 'Kimsuky', internal manuals, and passwords.


The two hackers explained that they were able to identify 'Kim' as a North Korean hacker due to clues and traces such as file configurations and domains previously known to belong to 'Kimsuky'.


They also added that 'Kim' strictly adhered to working hours, showing a pattern of connecting around 9 a.m. and disconnecting around 5 p.m. daily, based on Pyongyang time.


Yonhap News 


What do you think of this article?
recommend
0
great
0
moved
0
정기구독배너
Go to Mobile Site