기사 메일전송
[Analysis] Tracking the Reality of the Kimsuky Hacking Group… ③ The North Korea-China Alliance on the Cyber Battlefield
  • Kim Young
  • August 22, 2025 at 12:49 PM
기사수정
  • 9 a.m. to 5 p.m. Pyongyang time, the regular working pattern of North Korean hackers

  • Election interference tools with traces of Chinese partners
  • Cyber Warfare: A Threat Beyond South Korea to All of Northeast Asia
이번 3편은 DEF CON 33에서 공개된 북한 해킹조직 ‘김수키(Kimsuky)’ 내부 문건 중 북·중 합작 정황을 집중 분석한다. 로그 기록, 툴 주석, 해외 보안 기관 보고서를 종합하면, 북한 단독이 아닌 중국 파트너의 개입 흔적이 뚜렷이 드러난다. 이는 선거 안보를 넘어, 동맹 차원의 대응이 불가피한 국제 안보 이슈로 확장되고 있다. <편집자 주>

A composite image featuring North Korean and Chinese flags overlaid on a dark screen of hacking code. This symbolizes the evidence of cooperation between hackers from both countries, illustrating suspicions of a joint North Korea-China cyber operation targeting South Korea. Image courtesy of Han-Mi-Il Bo.

‘APT Down: The North Korea Files,’ presented at DEF CON 33 in Las Vegas, USA, in August 2025. 


The 8.9GB of internal documents from the North Korean hacking group ‘Kimsuky’ reveal more than just traces of intrusion; they provide concrete evidence of a joint North Korea-China operation.

 

The documents include logs showing that North Korean hackers operated within a regular work schedule, along with traces of modifications made to tools by Chinese partners.


Photo 1 Caption: Regular work logs from 9:00 AM to 5:00 PM Pyongyang time. "Phishing operation targeting the South Korean Ministry of Foreign Affairs – Review by Chinese partner complete." Original capture.



 Photo 2 Caption: Script filename: voter_id_scraper.py (Code suspected to be for extracting voter lists)

Annotation: "Modified by Chinese partner – Final version"

 



Photo 1 shows that North Korean hackers targeted the South Korean Ministry of Foreign Affairs within a structured work schedule and that a Chinese collaborator was involved in the review process.


Photo 2 suggests that this was not a tool developed solely by North Korea, but a tool for election interference that was jointly modified and completed with China.

 

Cross-Verification by International Security Agencies


In its report from the latter half of 2024, the Japan Computer Emergency Response Team (JPCERT) announced that it had captured attacks utilizing both Chinese IP addresses and North Korean-style malicious modules. With the DEF CON presentation materials and the JPCERT report aligning, it has been internationally confirmed that this incident is not merely a South Korean issue, but a joint hacking operation targeting the entire Northeast Asian region.


Inevitability of an Alliance-Level Response


In October 2024, a joint statement by the U.S. and South Korean defense ministers specified “joint response in the cyber and space domains.” This means that cyberattacks can fall under the scope of the ROK-U.S. Mutual Defense Treaty and that, if necessary, a joint ROK-U.S.-Japan response system can be activated. As evidence of the North Korea-China collaboration becomes clearer, this incident is bound to escalate from a simple security issue to a matter of alliance security.


The records revealed at DEF CON 33 demonstrate that North Korean hackers did not act alone.


From regular working hours and Chinese partner review logs to traces of joint modifications on voter list scraping code, the issue is no longer just a technical one—it is an international joint cyberwar.


To protect the heart of democracy, South Korea can no longer fight alone. Substantive cooperation with allies, along with compulsory investigations and forensic verification, are the only solutions.

 

Coming Up in the Next Part

 

In this third part, we examined how North Korea and China targeted South Korean government agencies and election systems through regular work schedules and collaboration channels. However, hacking does not end with simple information theft. Stolen accounts and data are repurposed for money laundering and weapons programs.

 

In the upcoming fourth part, under the theme 'How Hacking Turns into War Funds,' we will focus on cryptocurrency wallet access logs identified in the Kimsuky internal materials, illegal laundering routes, and the evidence indicating how these are utilized for North Korea's weapons development programs and the evasion of international sanctions.

 

We will track the process by which cyberattacks are converted directly into war funds, not just treated as simple crimes, and examine the repercussions for the international security order.


#Kimsuky #NorthKoreaChinaJointHacking #DEFCON33 #APTDown #CyberSecurity #ElectionInterference #ROKUSJapanAlliance #JPCERT



관련기사
What do you think of this article?
recommend
0
great
0
moved
0
정기구독배너
Go to Mobile Site