기사 메일전송
[Hot Issue] KimSuki Backdoor Hacking, NEC's Lies Exposed... GPKI Breached, National Computer Network Collapse
  • Kim Young
  • August 16, 2025 at 3:09 AM
기사수정
  • DEF CON 33·‘APT Down’ featured in Phrack — First glimpse inside North Korean cyber organization
  • The National Election Commission, Ministry of the Interior and Safety, Ministry of Foreign Affairs, and Ministry of National Defense are suspected of being infiltrated... Did they not know or did they conceal it? Controversy is inevitable.

  • GPKI breached, personal information from e-government services like Government 24 leaked to North Korea… International community calls it an “unprecedented incident.”
2025년 8월, 세계 최대 해킹대회 DEF CON 33과 해킹 전문 매거진 Phrack을 통해 북한 해킹조직 ‘킴수키(Kimsuky)’의 내부 자료가 처음 공개됐다. 8.9GB에 달하는 이 자료는 대한민국 핵심 정부기관의 침투 피해 정황을 담고 있으며, 특히 선관위 해킹은 그간의 부인·축소 해명을 뒤집는 증거로 은폐 가능성까지 제기된다. GPKI 인증체계 탈취는 정부 행정서비스를 이용하는 전 국민의 개인정보가 북한으로 넘어갔을 가능성을 시사한다. 외교·국방망까지 뚫린 이번 사건은 국가 시스템 무결성 붕괴라는 총체적 위기로, 전면적 진상 규명이 시급하다. <편집자 주>

DEF CON 33 Announcement Poster. Homepage capture

August 11, 2025, Las Vegas, USA. Hundreds of security experts and hackers gathered at the DEF CON 33 presentation hall. The stage screen displayed the title ‘APT Down: The North Korea Files,’ and individuals with the nicknames ‘Saber’ and ‘cyb0rg’ appeared. They declared that they had hacked into the Linux workstation and VPS (Virtual Private Server) of hackers belonging to the North Korean state-sponsored hacking group ‘Kimsuky’ and exfiltrated 8.9GB of internal data.


Amidst murmurs from the audience, the two hackers revealed an analytical document published in the latest hacking magazine, Phrack Issue 72. It contained the following passage:


“They fill the pockets of the powerful through cyber warfare and maintain oppression. We expose their dark deeds to the world.”


On August 14th, the obtained data was distributed globally through the international whistleblower platform DDoSecrets. At that moment, not only the reality of North Korea's cyber operations but also concrete infiltration damage to major South Korean government agencies was revealed.


Cover of the legendary hacking magazine Phrack. Homepage capture

Evidence of Hacking into Key South Korean Institutions


The leaked data included: hacking into high-ranking officials' emails at regional offices of the National Election Commission (NEC) in April 2021, attempts to access the vote counting and tabulation system, mass theft of public certificates from the Ministry of the Interior and Safety and the Ministry of Unification, the entire source code of the Ministry of Foreign Affairs' webmail (Kebi) server, infiltration records of the Defense Counterintelligence Command (DCC), and leakage of accounts and authentication keys from the Supreme Prosecutors' Office.


It also contained malware source code, hardcoded passwords (Min2jAcgXeDsdL), new malicious binaries not yet present on VirusTotal, and data related to cryptocurrency hacking and money laundering. The data also showed regular work patterns from 9 AM to 5 PM Pyongyang time and traces of collaboration with Chinese hackers.


NEC Hacking — Potential Cover-up


Until now, the NEC has repeatedly maintained the position that there were “no signs of cyber intrusion.” However, the latest data specifically records access paths into the NEC's internal network and attempts to infiltrate the vote counting and tabulation system.


If the NEC was aware of these facts and concealed them, it would constitute an act of undermining the constitutional order, going beyond mere security lapses. This situation calls for a thorough investigation into the suspected cover-up by the NEC, along with a state audit into allegations of election fraud.


GPKI Theft — The Heart of e-Administration Breached


GPKI (Government Public Key Infrastructure) is the authentication backbone for all e-administration services, including Government24, tax, real estate registration, and passport issuance. Hackers mass-stole public certificates and passwords, and created wordlists with deciphered passwords such as ‘unikorea123.’


This implies that the possibility of all citizen administrative information falling into North Korean hands is high. Experts point out that the possibility of personal information, including account details, being compromised cannot be ruled out.


Infiltration of Diplomacy and Defense Networks


The leakage of the entire source code for the Ministry of Foreign Affairs' webmail server threatens diplomatic secrets and embassy communications. Infiltration records of the Defense Counterintelligence Command suggest access to military intelligence networks, and the leakage of authentication keys from the Supreme Prosecutors' Office indicates the potential exposure of investigative secrets.


This is a shocking incident that reveals the grim reality that the government was unaware that diplomatic and military secrets, as well as investigative secrets, were being passed to the North.


International Reactions


The U.S. security media outlet TechCrunch described it as “the world’s first comprehensive disclosure of a nation-state hacking group’s inner workings.” TechRepublic mentioned the possibility of collaboration with Chinese hackers.


U.S. cybersecurity experts pointed out, “If South Korea’s core government authentication systems were compromised, this is not just data leakage but a collapse of the trust foundation of its e-government. Information sharing with allies and redesigning authentication systems are necessary.”


In March 2024, Japan's National center of Incident readiness and Strategy for Cybersecurity (JPCERT/CC) confirmed a phishing-based cyberattack by the Kimsuky group targeting Japan and issued an official alert. Japan is also heightening its vigilance regarding similar attack methods to those indicated in the leaked data.


Globally, demands are increasing for expanded cyber sanctions against North Korea and strengthened trilateral cooperation among South Korea, the U.S., and Japan.


There are also claims that the recent appointment of retired Colonel John Mills, who has extensive experience in cybersecurity, as the Deputy Assistant Secretary of State for Cyber, Digital, and Emerging Technologies by the U.S. State Department may be related to this.


Crisis of National System Integrity


This incident reveals a comprehensive crisis, with the collapse of election trust due to NEC hacking, the collapse of e-administration trust due to GPKI theft, and the collapse of national security due to diplomatic and military infiltration, all exposed simultaneously.


Without a thorough investigation and state audit to uncover the truth, South Korea could permanently lose the fairness of future elections and the trust in its administration and security.



#KimsukyHacking #DEFCON33 #Phrack #NECHacking #GPKIExtortion #NationalSecurityCrisis #CyberWarfare #InternationalResponse #CoverUpAllegations #NationalInfrastructureCollapse


관련기사
What do you think of this article?
recommend
0
great
0
moved
0

This article has 5comments.

  • Profile
    guest2025-08-19 15:43:08

    대한민국 언론이 보도를 안하니 우리가 공유해 널리 널리 알리자고요!

  • Profile
    guest2025-08-16 21:49:51

    '국민의 알 권리'를 노래 부르듯이 지저귀는 것들이 꼭 알아야 되는 진실에 대해서는 입 꾹 닫고 눈 꽉 감으니, 그들을 일컬어 기레기라 부른다.

  • Profile
    guest2025-08-16 14:25:06

    우리나라는 무대응 으로 합의를 했냐 ㅋㅋ 기렉 들이 ㅋㅋ 언론의 역할을 하는 언론이 없어 ㅋㅋㅂㅅㄷ 인가

  • Profile
    guest2025-08-16 06:53:57

    이런기사가 방송에 보도가 안되니 국민들에 반이 부정선거를 음모론으로 알고있지

  • Profile
    guest2025-08-16 06:09:06

    부정채용특검하고 부정선거 수사하라 노태악은 사퇴하고 선관위는 해체가답이다...
    이제는 행동으로 보일때 모두 광화문광장으로 나가자...

정기구독배너
Go to Mobile Site