기사 메일전송
[Exclusive] Analysis of Kimsuky Counter-Hacking Report: "Grounds for Compulsory Investigation Established"
  • Kim Young
  • August 18, 2025 at 4:56 PM
기사수정
  • Traces of North Korea-China collaboration, and even attempts to access the vote counting system
  • NEC Refutes “No Signs of Intrusion”… Report Contains Specific Records
  • National security breached, yet only finger-pointing continues… Public distrust grows

이번 기사는 미국 라스베이거스에서 열린 DEF CON 33 해킹대회에서 공개된 ‘APT Down: The North Korea Files’ 역해킹 보고서를 중심으로, 대한민국 핵심 기관이 실제로 어떤 방식으로 침투당했는지를 검증한 것입니다. 특히 중앙선거관리위원회 내부망과 투개표 시스템 접근 시도가 구체적으로 기록된 점은 ‘사이버 공격 흔적이 없다’는 선관위의 기존 입장을 정면으로 뒤집습니다. 본지는 정치적 공방을 넘어, 국가 안보와 선거 신뢰성 차원에서 철저한 검증과 책임 규명이 필요하다는 점에서 이 문제를 집중 조명합니다. <편집자 주>

The 'Kimsuky Counter-Hacking Report' revealed at DEF CON 33 in Las Vegas. The presentation highlighted evidence of hacking attempts on the National Election Commission (NEC). Composite by Hanmi Ilbo.

The South Korean National Election Commission (NEC) has been dealt a direct blow following the leak of internal documents belonging to the North Korean hacking group 'Kimsuky' at an international hacking conference.


The report specifically documented attempts to breach the NEC’s internal network and manipulate its voting and ballot-counting systems. These findings directly contradict the NEC’s repeated claims that there were "no traces of infiltration."


The data revealed a wide-ranging compromise, including the mass theft of digital certificates from the Ministry of the Interior and Safety and the Ministry of Unification, source code from the Ministry of Foreign Affairs' Kebi mail server, records of infiltration into the Ministry of National Defense and the Defense Counterintelligence Command, and the leakage of account and authentication keys from the Supreme Prosecutors' Office. Notably, explicit attempts to access the NEC's voting and ballot-counting systems were identified.


The leaked malware contained hardcoded passwords such as ‘Min2jAcgXeDsdL’, and a new type of binary was discovered that had not even been registered on VirusTotal.


Cybersecurity experts have pointed out that "with this level of evidence, the NEC must at least provide an explanation regarding the facts."


In August 2025, at DEF CON 33, the world’s largest hacking conference held in Las Vegas, the release of 'APT Down: The North Korea Files' shook the international security community and the political sphere alike.


The files, totaling 8.9GB of internal data, were obtained by U.S. hackers who infiltrated the workstations and VPS servers belonging to members of the North Korean state-sponsored hacking group 'Kimsuky' and were released to the world.


While the documents exposed the full extent of North Korea's cyber operations, the part that particularly shocked South Korea was the records concerning the National Election Commission (NEC). Contrary to the NEC's stance maintained for years that there were "no signs of cyber infiltration," these materials contained detailed records of access logs, attempts to breach voting and counting systems, and the mass theft of digital certificates.


Log Records Concentrated Just Before the General Election


According to the analyzed data, concentrated and repetitive attempts to access the NEC’s internal network were detected in March 2024, just weeks before the 22nd general election. Log records were found simultaneously on NEC servers in the metropolitan areas of Seoul, Gyeonggi, and Incheon, indicating that the regional election commission networks were compromised at the same time.


Even more concerning is the fact that the mass theft of digital certificates from the Ministry of the Interior and Safety and the Ministry of Unification coincided with this period. Given the overlap between the log records and the timing of the certificate leaks, there is a strong possibility that this was not merely "probing" but an active attempt to target the election management system itself.


The Severity of Digital Certificate Theft


Digital certificates are not just simple login credentials. They can be exploited as keys for critical actions, such as accessing NEC voting and counting servers, falsifying electronic data, and illegally accessing voter registration records. Given the interconnected nature of the authentication systems between government agencies, the fact that a certificate leaked from one ministry could provide direct access to NEC systems represents a severe security vulnerability.


Experts warn, "The infiltration of the NEC is not an isolated hacking incident but a state-level operation to neutralize the authentication foundation of the entire government," adding, "Particularly because it occurred just before the general election, the possibility of result manipulation cannot be ruled out."


Suspicions of North Korea-China Collaborative Hacking


The internal Kimsuky documents revealed a regular work pattern, with activity primarily occurring between 9:00 AM and 5:00 PM Pyongyang time. This is evidence that North Korean hackers operate in a structured, systematic manner, much like military personnel or public officials.


Furthermore, records of Chinese IP addresses and collaboration channels appeared throughout the data. Some logs even contained records of Korean-to-Chinese translations via Google Translate. This strongly suggests that North Korea and China may have been effectively involved in joint operations related to the election, going beyond simple technical exchanges.


In fact, it is reported that the Japan Computer Emergency Response Team (JPCERT) captured similar intrusion patterns in the second half of 2024 and compared them with cases within their own country. The theory of a North Korea-China joint operation is now expanding beyond the controversy over Korean election interference into a broader cybersecurity issue for all of Northeast Asia.


The scene at DEF CON, the world's largest hacking conference in Las Vegas. The graphic of overlapping locks and source code symbolizes cybersecurity and hacking threats. Composite by Hanmi Ilbo.

Response from the NEC and the Government


However, the NEC still maintains its position that "there are no traces of hacking." This official stance, repeated for years, is now in direct conflict with the newly revealed records. Despite the clear evidence of logs and the timing of certificate thefts, there are strong suspicions that the NEC may have covered up or at least downplayed these incidents.


The government has also failed to provide a clear follow-up. Yet, the evidence of the NEC infiltration contained in the data has already spread across the globe via the international security community. The logic of concealment and denial is no longer sustainable.


A Compulsory Investigation is Inevitable


The circumstances uncovered so far cannot be explained by an internal NEC investigation alone. When combining the log records, the timing of the certificate thefts, and the evidence of North Korea-China collaboration, this is a grave matter of national security.


Therefore, a joint investigation involving the National Intelligence Service, the prosecution, the police, and civilian experts to conduct a mandatory investigation and forensic verification is inevitable. If the investigation is delayed, the same vulnerabilities could be exploited again in the 2026 local elections and the presidential election. If elections are held without ensuring election security, the very foundation of democracy is at risk.


The election system is the heart of democracy. The current records warn that this heart has already been exposed to external attacks. Since "traces mean threats," these internal Kimsuky documents serve as a wake-up call that the entire South Korean election security system must be re-examined, moving beyond the scope of a simple hacking incident.


The only solution is an approach rooted in national security rather than political interests, coupled with a full-scale investigation. What is needed now is not excuses or concealment, but a determination of facts and accountability.


Timeline


Nov-Dec 2023: Increase in activity by the North Korean hacking group 'Kimsuky'; signs of concentrated attacks on South Korea's foreign affairs and security sectors detected.

Apr 2024: Just before the general election, attempts to access the NEC internal network and attacks related to the voting and ballot-counting systems occur.

Jun-Dec 2024: Traces of collaboration with Chinese hackers confirmed; theft of digital certificates, Ministry of Foreign Affairs' Kebi mail server data, and Supreme Prosecutors' Office authentication keys verified.

Aug 9, 2025: 'APT Down: The North Korea Files' presented at DEF CON 33 in Las Vegas. 8.9GB of internal Kimsuky data released.

Aug 2025: Analysis of the counter-hacking report reveals specific facts regarding the infiltration of the NEC system and hacking of government agencies.



#HanmiIlboExclusive #Kimsuky #CounterHackingReport #NEChacking #NorthKoreaChinaCollaborationSuspicion #VotingCountingSystem #CyberSecurity #DEFCON33 #NationalSecurityCrisis #ElectionTrust



관련기사
What do you think of this article?
recommend
0
great
0
moved
0

This article has 11comments.

  • Profile
    masin5562025-11-07 12:55:42

    음.. 혹시 저 역추적 자료 좀 찾아주심 안됩니까.
    기사 사용을 위한 자료가 무엇인가요.

    좌파 친구를 설득하기에 설득력이 부족합니다...

  • Profile
    guest2025-08-24 17:11:31

    지금의 대한민국은 희망이 안보인다. 제2
    IMF로는 고칠수 없는 병에 거렿다. 차라리 외치든 뭐든 천지개벽이 일어나 새롭게
    다시 태어나지 않으면 이 나라는 미래가 없어 보인다.

  • Profile
    guest2025-08-20 19:54:18

    ㅉㅉㅉ 아직도 이런 허무맹랑한 소리나 하고 있냐...

  • Profile
    guest2025-08-20 19:35:57

    나라의 간첩들이 대문 활짝열고 어서욥쇼 했네!!!그러면서도 안전하다고 구라만 치는 선관위!!!그래놓고 자유와혁신 압색하냐? 내로남불이 따로 없다

  • Profile
    guest2025-08-20 18:51:46

    경찰 뭐하냐. 즉각 수사해라

  • Profile
    guest2025-08-19 11:23:44

    좋은 자료. 분석 감사합니다

  • Profile
    sealinner2025-08-19 11:17:17

    이번에는 진짜 끝내게 더 힘내주세요!

  • Profile
    guest2025-08-19 06:18:56

    부정채용특검하고 부정선거 수사하라 노태악은 사퇴하고 선관위는 해체가답이다...
    이제는 행동으로 보일때 모두 광화문광장으로 나가자...

  • Profile
    hsh_97632025-08-18 22:32:27

    선관위 관계자들 모조리  개작두로 해결하자!

  • Profile
    guest2025-08-18 18:43:49

    제발 이번에 제대로 끝내자!!!

  • Profile
    kingyc712025-08-18 17:30:43

    제발 끝장내자~

정기구독배너
Go to Mobile Site