Iranian Foreign Ministry: "Continuing Message Exchanges with the U.S. and Activities of Mediating Countries"
Esmaeil Baghaei, Spokesperson for the Iranian Ministry of Foreign Affairs [Xinhua, Yonhap News file photo]Esmaeil Baghaei, spokesperson for the Iranian Ministry of Foreign Affairs, stated on the 26th
President Yoon: "Do You Think You Are Safe from the Special Counsel?"... Final Statement Video Released
President Yoon Suk Yeol rebuking the special prosecutor on the 24th. [Court video / @birds_justice X account subtitle GIF] A video of President Yoon Suk Yeol's closing statement at his trial rega
President Yoon, regarding the first-instance ruling on the Public Official Election Act: “An excessive political verdict that distorts the facts… We will appeal immediately.”
The first-instance sentencing hearing for President Yoon Suk Yeol regarding violations of the Public Official Election Act is being broadcast live at Seoul Station on the 27th. [Photo=Yonhap News]Pres
WSJ: "SK Hynix ADR Premium Is a Sign of AI Trading Overheat"
Advertisement for SK Hynix ADR listing in New York's Times Square [Reuters=Yonhap News file photo]The Wall Street Journal (WSJ) has pointed out that the price of SK Hynix’s American Depositary Recei
'Godfather of Japanese Mystery Novels' Keigo Higashino Passes Away After Battle with Cancer at 68
Famous Japanese mystery novelist Keigo Higashino [AFP=Yonhap News]It has been belatedly reported that Keigo Higashino, the "godfather of Japanese mystery novels" and author of bestsellers such as "The
[Park Pil-kyu Security Column] To the Ignorant Trying to Clothe a Beast in Sheep's Clothing
Rep. Kim Byung-joo of the Democratic Party of Korea [Photo=Yonhap News]“The Air Force Academy doesn't teach you how to fly a plane!” “The Army, Navy, and Air Force academies are exactly the
A 'HACKED' warning sign superimposed over a view of the Ministry of Foreign Affairs building in Jongno-gu, Seoul. Internal documents from the North Korean hacking group 'Kimsuky,' unveiled at DEF CON 33, contained evidence of a leak of the Ministry of Foreign Affairs' Kebi mail system source code. (Composite by Hanmi Ilbo)
With the release of internal data from the North Korean hacking group 'Kimsuky' at an international hacking conference, the core of South Korean democracy—its election management system—has been thrust into the spotlight.
The data contained specific details regarding access logs for the National Election Commission (NEC) servers, infiltration attempts into voting and counting systems, and the mass theft of GPKI certificates.
However, the traces left just before the 2024 general election were not limited to the NEC.
According to the 'APT Down' report revealed at DEF CON 33, approximately 8.9GB of internal data from Kimsuky was leaked, including the entire source code for the Ministry of Foreign Affairs' Kebi mail platform. This was not a mere email breach, but the exposure of the blueprints for the diplomatic communication network itself. In essence, the negotiations, confidential reports, and foreign strategies of diplomats could have been monitored or manipulated at any time.
Even more shocking were the phishing attempt logs targeting spo.go.kr (the portal for the Ministry of Justice and the Prosecution Service) and mofa.go.kr (the domain for the Ministry of Foreign Affairs). These attacks were concentrated during Pyongyang’s working hours (9:00 AM to 5:00 PM KST) and a significant number originated from Chinese IP addresses. Notably, internal data confirmed that key institutions, including the Defense Counterintelligence Command (DCC), had been long-term targets of the hackers.
Furthermore, the theft of account and authentication keys from the Supreme Prosecutors' Office was confirmed. Authentication keys act as digital signatures proving one is a "legitimate user" within the prosecution’s internal system. The loss of these keys meant that hackers could pose as insiders to access materials or execute commands—a incident that fundamentally shook the foundation of trust in the prosecution.
The Ministry of the Interior and Safety was no exception. The Government Public Key Infrastructure (GPKI) and Gov.kr (Government 24) have long been considered "ticking time bombs" by the international security community. Their outdated encryption algorithms and centralized structure were fatal vulnerabilities, and actual infiltration attempts by hackers have now been confirmed in the logs. Sensitive personal data, such as resident registration, taxes, and family records, were left potentially exposed without defense.
“In early 2024 … The threat actor had thousands of these files on his workstation.
The threat actor developed a Java program to crack the passwords protecting the keys and certificates.” Excerpt from original text (from GPKI Stolen Certificates)
The report presented at the DEF CON venue emphasized the following:
“This dataset includes spear-phishing campaigns conducted by Kimsuky, command-and-control (C2) infrastructure, and internal design documents. This demonstrates that North Korean cyber operations have moved beyond simple intrusion to target the operational structure of administrative systems themselves.”
International media outlets offered similar analyses. TechCrunch described it as “a rare, if not unprecedented, internal disclosure that reveals how North Korean and Chinese hackers share tools and techniques.”
Security researchers diagnosed the leak as “a warning that the South Korean government must redesign its entire system architecture for security.”
However, the South Korean government’s response was quite the opposite. The National Intelligence Service and KISA stated, “We were aware of the situation and responded accordingly, and no traces of significant information leaks were found.” Their continued insistence that “no confirmed damage has occurred,” even after the DEF CON presentation, stands in stark contrast to the FBI’s immediate launch of an investigation following the 2016 DNC server hacking incident in the United States.
Key Summary
Leak of Ministry of Foreign Affairs Kebi Mail Source Code: Entire diplomatic network blueprints are in the hands of hackers.
Theft of Supreme Prosecutors' Office Authentication Keys: Collapse of the legitimacy of the prosecution’s systems.
Access logs for spo.go.kr and mofa.go.kr: Attacks concentrated during Pyongyang hours, originating from Chinese IPs → Evidence of North Korea-China cooperation.
Targeting the Defense Counterintelligence Command (DCC): Exposure of threats even to core defense and intelligence agencies.
Vulnerabilities in GPKI and Gov.kr: Risks of total exposure of public administrative data.
Government Response: Maintaining a posture of downplaying or denying any damage.
Coming Up Next
Part 2 will cover the circumstances under which the media and civil society became targets. We will focus on the targeted phishing campaign dubbed ‘Operation Covert Stalker,’ malware disguised under the names of news organizations, and the silence of the South Korean media.
#DEFCON33 #APTDown #Kimsuky #MofaKebi #SupremeProsecutorsOffice #GovernmentPortalPhishing #DefenseCounterintelligenceCommand #CyberSecurity #MinistryOfTheInteriorAndSafety #HanmiIlboSpecialReport
Kim Young More by this author