기사 메일전송
[Analysis] Tracing the Reality of the Kim Su-ki Hack… ② Guardians of Democracy Also Become Hosts for Hackers
  • Kim Young
  • August 21, 2025 at 8:45 PM
기사수정
  • Targeted phishing attacks aimed at journalists, politicians, and academics
  • Backdoor Module Mentioned by Name Stuns News Outlet
  • The Silent Korean Press, Democracy Defenseless
이번 3편은 DEF CON 33에서 공개된 북한 해킹조직 ‘김수키(Kimsuky)’ 내부 자료 중 언론·시민사회 관련 정황을 집중적으로 다룬다. 민주주의의 감시자여야 할 언론과 여론 형성에 직접 영향을 미치는 정치인·학자가 공격 대상이 된 사실은 충격적이다. 더구나 일부 언론사의 서버 이름이 해커 도구에 직접 언급된 사실까지 확인됐지만, 국내 언론은 여전히 침묵하고 있다. <편집자 주>

A reporter looks at a 'Phishing Attack' warning displayed on a laptop screen. Recently disclosed internal Kimsuky data reveals evidence of targeted phishing attacks aimed at journalists and politicians, highlighting the severity of security threats to the media industry. Composite image by Hankyoreh

Presented at DEF CON 33, the world's largest hacking conference held in Las Vegas in August 2025, the report "APT Down: The North Korea Files" starkly exposed North Korea's cyber operations against South Korea. The 8.9GB of data, stolen from within the organization, contained records demonstrating that not only government agencies but also the media and civil society were direct targets of these attacks.

 

The operation log named 'Operation Covert Stalker' was particularly shocking. It listed email accounts of journalists, politicians, and scholars as targets, and the subject lines of the phishing emails sent were meticulously disguised. Phrases such as "Request for Manuscript Proofreading," "Invitation to Policy Advisory Meeting," and "Sharing Election Poll Results" deceived recipients, leading to the execution of malicious modules upon clicking, resulting in information theft. It was clear that the targets were not ordinary citizens but groups with influence over public opinion and policy-making.




Photo caption: A phishing email is sent to a reporter's account (reporter@press.co.kr). "Delivered" indicates normal receipt. Malicious payload (executable code) uploaded to the server. This suggests potential infection after clicking the email. Original data capture.

Korean media company names are listed within the code, implying that actual media servers were used as transit points or that media names were leveraged in the attack.


Even more concerning was the backdoor named 'Spawn Chimera.' This was a sophisticated module employing port knocking, a technique that only allows access after specific secret signals are matched. The internal file names and comments directly mentioned the names of South Korean media companies.


Security experts interpreted this as "the possibility that actual media company servers were used as transit points" or "a social engineering technique that exploited the names of media companies to deceive recipients."


While interpretations differ on whether actual servers were used as attack transit points or if it was merely a social engineering tactic for deception, it reveals the alarming possibility that media organizations, guardians of democracy, could be transformed into conduits for attacks.

 

What is even more serious is that while international security reports and experts pointed this out publicly, major South Korean media outlets largely failed to report on it. Only a few outlets mentioned the infiltration of state agencies, while the direct naming of media companies was completely obscured. Those media companies that have not even offered an explanation to the public cannot escape criticism. Silence is complicity, and complicity makes democracy more vulnerable.

 

This incident exposes how defenseless the media and civil society are against cyber warfare. Journalists and politicians became precision targets, media servers were identified as hacker transit points, and scholars and researchers were heavily targeted due to their influence. This was not merely a technical hacking incident but part of a strategic cyber warfare aimed at shaping public opinion and the democratic system itself.

 

The DEF CON presentation presented an uncomfortable truth: "When the media remains silent, democracy crumbles." This incident proves that this statement is no longer an abstract adage. Logs and malicious code provide concrete evidence of this fact. The media must now respond responsibly to the public. Silence can no longer be an excuse.

 

Next Article Preview

 

The next article will cover evidence of North Korea-China joint hacking operations revealed in the internal Kimsuky data. We will conduct an in-depth analysis of the possibility of a joint North Korea-China operation, which is shaking the Northeast Asian security landscape, going beyond mere North Korean solo operations. This includes "regular working hours records" according to Pyongyang time, traces of Chinese IP addresses and translator usage, and reports from Japan's JPCERT. Shocking records revealing a new Cold War in cyberspace, extending beyond interference in democratic elections, are set to be unveiled.


#DEFCON33 #Kimsuky #Cybersecurity #MediaSilence #DemocracyCrisis #TargetedPhishing #SpawnChimera



관련기사
What do you think of this article?
recommend
0
great
0
moved
0

This article has 1comments.

  • Profile
    guest2025-08-22 14:22:37

    대만식 현장즉석칠판까기가 정답이다

정기구독배너
Go to Mobile Site