기사 메일전송
[Analysis] Tracking the Reality of the Kimsuky Hacking Group… ① Ministry of the Interior and Safety, Ministry of Foreign Affairs, and Ministry of National Defense: The Gateway of Administration Compromised
  • Kim Young
  • August 20, 2025 at 8:20 PM
기사수정
  • Leak of Ministry of Foreign Affairs Kebi Mail Source Code
  • Theft of Supreme Prosecutors' Office Account and Authentication Key
  • Structural Loopholes in National Administrative Services
DEF CON 33(라스베이거스, 2025년 8월 초) 현장에서 공개된 ‘APT Down: The North Korea Files’ 보고서를 토대로, 이번 편에서는 대한민국 핵심 정부기관의 해킹 정황과 시스템 구조적 허점을 면밀히 분석합니다. 본문은 실제 발표 자료와 해외 보안 전문가 평가를 포함해 재구성한 내용입니다. <편집자 주>

A 'HACKED' warning sign superimposed over a view of the Ministry of Foreign Affairs building in Jongno-gu, Seoul. Internal documents from the North Korean hacking group 'Kimsuky,' unveiled at DEF CON 33, contained evidence of a leak of the Ministry of Foreign Affairs' Kebi mail system source code. (Composite by Hanmi Ilbo)

With the release of internal data from the North Korean hacking group 'Kimsuky' at an international hacking conference, the core of South Korean democracy—its election management system—has been thrust into the spotlight.

 

The data contained specific details regarding access logs for the National Election Commission (NEC) servers, infiltration attempts into voting and counting systems, and the mass theft of GPKI certificates.


However, the traces left just before the 2024 general election were not limited to the NEC.


According to the 'APT Down' report revealed at DEF CON 33, approximately 8.9GB of internal data from Kimsuky was leaked, including the entire source code for the Ministry of Foreign Affairs' Kebi mail platform. This was not a mere email breach, but the exposure of the blueprints for the diplomatic communication network itself. In essence, the negotiations, confidential reports, and foreign strategies of diplomats could have been monitored or manipulated at any time.

 

Even more shocking were the phishing attempt logs targeting spo.go.kr (the portal for the Ministry of Justice and the Prosecution Service) and mofa.go.kr (the domain for the Ministry of Foreign Affairs). These attacks were concentrated during Pyongyang’s working hours (9:00 AM to 5:00 PM KST) and a significant number originated from Chinese IP addresses. Notably, internal data confirmed that key institutions, including the Defense Counterintelligence Command (DCC), had been long-term targets of the hackers.

 

Furthermore, the theft of account and authentication keys from the Supreme Prosecutors' Office was confirmed. Authentication keys act as digital signatures proving one is a "legitimate user" within the prosecution’s internal system. The loss of these keys meant that hackers could pose as insiders to access materials or execute commands—a incident that fundamentally shook the foundation of trust in the prosecution.

 

The Ministry of the Interior and Safety was no exception. The Government Public Key Infrastructure (GPKI) and Gov.kr (Government 24) have long been considered "ticking time bombs" by the international security community. Their outdated encryption algorithms and centralized structure were fatal vulnerabilities, and actual infiltration attempts by hackers have now been confirmed in the logs. Sensitive personal data, such as resident registration, taxes, and family records, were left potentially exposed without defense.


“In early 2024 … The threat actor had thousands of these files on his workstation.
The threat actor developed a Java program to crack the passwords protecting the keys and certificates.”  Excerpt from original text (from GPKI Stolen Certificates)

 

The report presented at the DEF CON venue emphasized the following:

 

“This dataset includes spear-phishing campaigns conducted by Kimsuky, command-and-control (C2) infrastructure, and internal design documents. This demonstrates that North Korean cyber operations have moved beyond simple intrusion to target the operational structure of administrative systems themselves.”

 

International media outlets offered similar analyses. TechCrunch described it as “a rare, if not unprecedented, internal disclosure that reveals how North Korean and Chinese hackers share tools and techniques.”

 

Security researchers diagnosed the leak as “a warning that the South Korean government must redesign its entire system architecture for security.”

 

However, the South Korean government’s response was quite the opposite. The National Intelligence Service and KISA stated, “We were aware of the situation and responded accordingly, and no traces of significant information leaks were found.” Their continued insistence that “no confirmed damage has occurred,” even after the DEF CON presentation, stands in stark contrast to the FBI’s immediate launch of an investigation following the 2016 DNC server hacking incident in the United States.

 

Key Summary

 

Leak of Ministry of Foreign Affairs Kebi Mail Source Code: Entire diplomatic network blueprints are in the hands of hackers.

Theft of Supreme Prosecutors' Office Authentication Keys: Collapse of the legitimacy of the prosecution’s systems.

Access logs for spo.go.kr and mofa.go.kr: Attacks concentrated during Pyongyang hours, originating from Chinese IPs → Evidence of North Korea-China cooperation.

Targeting the Defense Counterintelligence Command (DCC): Exposure of threats even to core defense and intelligence agencies.

Vulnerabilities in GPKI and Gov.kr: Risks of total exposure of public administrative data.

Government Response: Maintaining a posture of downplaying or denying any damage.

 

Coming Up Next


Part 2 will cover the circumstances under which the media and civil society became targets. We will focus on the targeted phishing campaign dubbed ‘Operation Covert Stalker,’ malware disguised under the names of news organizations, and the silence of the South Korean media.

 

#DEFCON33 #APTDown #Kimsuky #MofaKebi #SupremeProsecutorsOffice #GovernmentPortalPhishing #DefenseCounterintelligenceCommand #CyberSecurity #MinistryOfTheInteriorAndSafety #HanmiIlboSpecialReport

관련기사
What do you think of this article?
recommend
0
great
0
moved
0

This article has 1comments.

  • Profile
    edoomok2025-08-21 09:32:28

    부정선거 유포자 처벌한다, 황교안부방대압수수색, 국민을 협박하는 한국 민주주의 선관위, 북한 중국의 해킹합작, 이런 모든 것을 오리발로 뭉게면서 국민을 길들이기하는 좌파종북정권의 행태는 반드시 시급하게 국민의 심판과 검열을 받아야 한다. 다음지방선거도 그냥 동일한 방법으로 선거를 하면 선관위가 지정한 정당이 필요한 만큼의 자리를 차지한다는 의심을 버릴 수 없다. 4.19처럼 국가시스템이 재설계되는 변혁을 겪고 말것이다.

정기구독배너
Go to Mobile Site