Iranian Foreign Ministry: "Continuing Message Exchanges with the U.S. and Activities of Mediating Countries"
Esmaeil Baghaei, Spokesperson for the Iranian Ministry of Foreign Affairs [Xinhua, Yonhap News file photo]Esmaeil Baghaei, spokesperson for the Iranian Ministry of Foreign Affairs, stated on the 26th
President Yoon: "Do You Think You Are Safe from the Special Counsel?"... Final Statement Video Released
President Yoon Suk Yeol rebuking the special prosecutor on the 24th. [Court video / @birds_justice X account subtitle GIF] A video of President Yoon Suk Yeol's closing statement at his trial rega
President Yoon, regarding the first-instance ruling on the Public Official Election Act: “An excessive political verdict that distorts the facts… We will appeal immediately.”
The first-instance sentencing hearing for President Yoon Suk Yeol regarding violations of the Public Official Election Act is being broadcast live at Seoul Station on the 27th. [Photo=Yonhap News]Pres
WSJ: "SK Hynix ADR Premium Is a Sign of AI Trading Overheat"
Advertisement for SK Hynix ADR listing in New York's Times Square [Reuters=Yonhap News file photo]The Wall Street Journal (WSJ) has pointed out that the price of SK Hynix’s American Depositary Recei
'Godfather of Japanese Mystery Novels' Keigo Higashino Passes Away After Battle with Cancer at 68
Famous Japanese mystery novelist Keigo Higashino [AFP=Yonhap News]It has been belatedly reported that Keigo Higashino, the "godfather of Japanese mystery novels" and author of bestsellers such as "The
[Park Pil-kyu Security Column] To the Ignorant Trying to Clothe a Beast in Sheep's Clothing
Rep. Kim Byung-joo of the Democratic Party of Korea [Photo=Yonhap News]“The Air Force Academy doesn't teach you how to fly a plane!” “The Army, Navy, and Air Force academies are exactly the
National security breached, yet only finger-pointing continues… Public distrust grows
The 'Kimsuky Counter-Hacking Report' revealed at DEF CON 33 in Las Vegas. The presentation highlighted evidence of hacking attempts on the National Election Commission (NEC). Composite by Hanmi Ilbo.
The South Korean National Election Commission (NEC) has been dealt a direct blow following the leak of internal documents belonging to the North Korean hacking group 'Kimsuky' at an international hacking conference.
The report specifically documented attempts to breach the NEC’s internal network and manipulate its voting and ballot-counting systems. These findings directly contradict the NEC’s repeated claims that there were "no traces of infiltration."
The data revealed a wide-ranging compromise, including the mass theft of digital certificates from the Ministry of the Interior and Safety and the Ministry of Unification, source code from the Ministry of Foreign Affairs' Kebi mail server, records of infiltration into the Ministry of National Defense and the Defense Counterintelligence Command, and the leakage of account and authentication keys from the Supreme Prosecutors' Office. Notably, explicit attempts to access the NEC's voting and ballot-counting systems were identified.
The leaked malware contained hardcoded passwords such as ‘Min2jAcgXeDsdL’, and a new type of binary was discovered that had not even been registered on VirusTotal.
Cybersecurity experts have pointed out that "with this level of evidence, the NEC must at least provide an explanation regarding the facts."
In August 2025, at DEF CON 33, the world’s largest hacking conference held in Las Vegas, the release of 'APT Down: The North Korea Files' shook the international security community and the political sphere alike.
The files, totaling 8.9GB of internal data, were obtained by U.S. hackers who infiltrated the workstations and VPS servers belonging to members of the North Korean state-sponsored hacking group 'Kimsuky' and were released to the world.
While the documents exposed the full extent of North Korea's cyber operations, the part that particularly shocked South Korea was the records concerning the National Election Commission (NEC). Contrary to the NEC's stance maintained for years that there were "no signs of cyber infiltration," these materials contained detailed records of access logs, attempts to breach voting and counting systems, and the mass theft of digital certificates.
Log Records Concentrated Just Before the General Election
According to the analyzed data, concentrated and repetitive attempts to access the NEC’s internal network were detected in March 2024, just weeks before the 22nd general election. Log records were found simultaneously on NEC servers in the metropolitan areas of Seoul, Gyeonggi, and Incheon, indicating that the regional election commission networks were compromised at the same time.
Even more concerning is the fact that the mass theft of digital certificates from the Ministry of the Interior and Safety and the Ministry of Unification coincided with this period. Given the overlap between the log records and the timing of the certificate leaks, there is a strong possibility that this was not merely "probing" but an active attempt to target the election management system itself.
The Severity of Digital Certificate Theft
Digital certificates are not just simple login credentials. They can be exploited as keys for critical actions, such as accessing NEC voting and counting servers, falsifying electronic data, and illegally accessing voter registration records. Given the interconnected nature of the authentication systems between government agencies, the fact that a certificate leaked from one ministry could provide direct access to NEC systems represents a severe security vulnerability.
Experts warn, "The infiltration of the NEC is not an isolated hacking incident but a state-level operation to neutralize the authentication foundation of the entire government," adding, "Particularly because it occurred just before the general election, the possibility of result manipulation cannot be ruled out."
Suspicions of North Korea-China Collaborative Hacking
The internal Kimsuky documents revealed a regular work pattern, with activity primarily occurring between 9:00 AM and 5:00 PM Pyongyang time. This is evidence that North Korean hackers operate in a structured, systematic manner, much like military personnel or public officials.
Furthermore, records of Chinese IP addresses and collaboration channels appeared throughout the data. Some logs even contained records of Korean-to-Chinese translations via Google Translate. This strongly suggests that North Korea and China may have been effectively involved in joint operations related to the election, going beyond simple technical exchanges.
In fact, it is reported that the Japan Computer Emergency Response Team (JPCERT) captured similar intrusion patterns in the second half of 2024 and compared them with cases within their own country. The theory of a North Korea-China joint operation is now expanding beyond the controversy over Korean election interference into a broader cybersecurity issue for all of Northeast Asia.
The scene at DEF CON, the world's largest hacking conference in Las Vegas. The graphic of overlapping locks and source code symbolizes cybersecurity and hacking threats. Composite by Hanmi Ilbo.
Response from the NEC and the Government
However, the NEC still maintains its position that "there are no traces of hacking." This official stance, repeated for years, is now in direct conflict with the newly revealed records. Despite the clear evidence of logs and the timing of certificate thefts, there are strong suspicions that the NEC may have covered up or at least downplayed these incidents.
The government has also failed to provide a clear follow-up. Yet, the evidence of the NEC infiltration contained in the data has already spread across the globe via the international security community. The logic of concealment and denial is no longer sustainable.
A Compulsory Investigation is Inevitable
The circumstances uncovered so far cannot be explained by an internal NEC investigation alone. When combining the log records, the timing of the certificate thefts, and the evidence of North Korea-China collaboration, this is a grave matter of national security.
Therefore, a joint investigation involving the National Intelligence Service, the prosecution, the police, and civilian experts to conduct a mandatory investigation and forensic verification is inevitable. If the investigation is delayed, the same vulnerabilities could be exploited again in the 2026 local elections and the presidential election. If elections are held without ensuring election security, the very foundation of democracy is at risk.
The election system is the heart of democracy. The current records warn that this heart has already been exposed to external attacks. Since "traces mean threats," these internal Kimsuky documents serve as a wake-up call that the entire South Korean election security system must be re-examined, moving beyond the scope of a simple hacking incident.
The only solution is an approach rooted in national security rather than political interests, coupled with a full-scale investigation. What is needed now is not excuses or concealment, but a determination of facts and accountability.
Timeline
Nov-Dec 2023: Increase in activity by the North Korean hacking group 'Kimsuky'; signs of concentrated attacks on South Korea's foreign affairs and security sectors detected.
Apr 2024: Just before the general election, attempts to access the NEC internal network and attacks related to the voting and ballot-counting systems occur.
Jun-Dec 2024: Traces of collaboration with Chinese hackers confirmed; theft of digital certificates, Ministry of Foreign Affairs' Kebi mail server data, and Supreme Prosecutors' Office authentication keys verified.
Aug 9, 2025: 'APT Down: The North Korea Files' presented at DEF CON 33 in Las Vegas. 8.9GB of internal Kimsuky data released.
Aug 2025: Analysis of the counter-hacking report reveals specific facts regarding the infiltration of the NEC system and hacking of government agencies.
#HanmiIlboExclusive #Kimsuky #CounterHackingReport #NEChacking #NorthKoreaChinaCollaborationSuspicion #VotingCountingSystem #CyberSecurity #DEFCON33 #NationalSecurityCrisis #ElectionTrust
Kim Young More by this author
This article has 11comments.
음.. 혹시 저 역추적 자료 좀 찾아주심 안됩니까.
기사 사용을 위한 자료가 무엇인가요.
좌파 친구를 설득하기에 설득력이 부족합니다...
지금의 대한민국은 희망이 안보인다. 제2
IMF로는 고칠수 없는 병에 거렿다. 차라리 외치든 뭐든 천지개벽이 일어나 새롭게
다시 태어나지 않으면 이 나라는 미래가 없어 보인다.
ㅉㅉㅉ 아직도 이런 허무맹랑한 소리나 하고 있냐...
나라의 간첩들이 대문 활짝열고 어서욥쇼 했네!!!그러면서도 안전하다고 구라만 치는 선관위!!!그래놓고 자유와혁신 압색하냐? 내로남불이 따로 없다
경찰 뭐하냐. 즉각 수사해라
좋은 자료. 분석 감사합니다
이번에는 진짜 끝내게 더 힘내주세요!
부정채용특검하고 부정선거 수사하라 노태악은 사퇴하고 선관위는 해체가답이다...
이제는 행동으로 보일때 모두 광화문광장으로 나가자...
선관위 관계자들 모조리 개작두로 해결하자!
제발 이번에 제대로 끝내자!!!
제발 끝장내자~