기사 메일전송
[Analysis] Tracking the Reality of the Kim Suki Hack... ⑤ Rebuild the Shield of Democracy
  • Kim Young
  • August 24, 2025 at 10:18 AM
기사수정
  • Election Commission, Government Agencies, Media, and Civil Society: Circumstances Suggesting Widespread Infiltration
  • North Korea-China Joint Hacking Linked to Money Laundering and Weapons Development
  • Silence is collapse, only reform protects democracy
최종본인 5편은 DEF CON 33에서 공개된 ‘APT Down: The North Korea Files’ 전체 자료를 종합해 한국 사회가 직면한 사이버 안보 위기를 진단한다. 선관위, 정부기관, 언론, 시민사회, 그리고 북한·중국 합작 정황과 자금조달 연결까지, 민주주의 심장을 겨냥한 총체적 위협을 다뤘다. 이 기사는 단순 해킹 스캔들이 아니라, 은폐와 침묵으로는 더 이상 버틸 수 없는 민주주의의 안보 과제를 고발한다. <편집자 주>

North Korean (left) and Chinese (right) flags are overlaid on a screen displaying a cyber attack warning icon over a map of South Korea. This symbolically represents the joint cyber attack targeting South Korea by North Korea and China. Photo courtesy of Yonhap News Agency.

 August 2025, DEF CON 33, the world's largest hacking conference, held in Las Vegas. The presentation of "APT Down: The North Korea Files" revealed the reality of cyber operations that had targeted the heart of South Korean society.


The 8.9GB of internal data, extracted from the workstations and VPS servers of North Korean hacking group Kimsuky, contained traces of a comprehensive crisis: access logs to the National Election Commission's servers, theft of government agency certificates, targeted attacks on media and academia, evidence of North Korea-China collaboration, and cryptocurrency money laundering routes.


The most shocking revelation was the penetration record targeting the National Election Commission.


The 'Operation Log' in the data included logs of repeated connection attempts to the vote counting and tabulation servers just before the election, as well as records of successful access to port 8443. The presence of traces of malicious module uploads, in addition to mere attempts, indicates potential actual penetration rather than just simple attempts.


Furthermore, thousands of GPKI certificates and keys were stolen simultaneously, and a Java program to decrypt them was found on the attacker's workstation. While the National Election Commission and the government still denied any "signs of penetration," the international security community and experts concluded that "the heart of democracy has already been exposed."


Government agencies were not exempt.


The source code for the Ministry of Foreign Affairs' Kebi mail was leaked, accounts and authentication keys for the Supreme Prosecutors' Office were stolen, and certificates for the Ministry of the Interior and Safety and the Ministry of Unification were also compromised. This exposes a structural vulnerability where the entire government's authentication system is interconnected. The statement from a former CERT operative, "If one ministry is breached, the National Election Commission and Government24 will fall in sequence," illustrates how the entire South Korean administration could be exposed in an instant.


Media and civil society were also not safe.


The operation logs named 'Operation Covert Stalker' documented the dispatch of phishing emails targeting journalists, scholars, and politicians. Opening documents disguised as "requests for manuscript correction of academic papers" or "invitations to policy advisory meetings" would activate malicious modules, leading to information theft.


Even more alarming is the fact that actual South Korean media outlet names appeared in the comments of the backdoor code named Spawn Chimera. Security experts analyze this as the media outlet servers being used as attack transit points, or at the very least, their names being exploited for social engineering tactics. However, South Korean media outlets themselves reported very little on this matter. Not only were the guardians of democracy vulnerable to attack, but they also failed to warn the public.


Evidence of North Korea-China collaboration is even clearer.


Regular work logs from 9 AM to 5 PM Pyongyang time were found, including a memo stating, "Phishing targeting the South Korean Ministry of Foreign Affairs – China partner review complete." Additionally, a script named voter_id_scraper.py, created to steal voter registration lists, contained a comment stating, "Modified by Chinese partner – final version."


This constitutes concrete evidence that North Korea was not acting alone but was collaborating with China to target South Korea's elections. The Japanese Cybersecurity Center (JPCERT) reported in the latter half of 2024 that attacks simultaneously utilizing Chinese IP addresses and North Korean-style malicious modules had been detected, further supporting this scenario.


North Korean hacking extends beyond information gathering to funding and arms procurement.


Furthermore, the data shows that North Korea's hacking activities go beyond mere information gathering to include funding and weapons programs.


Access records to cryptocurrency wallets, money laundering routes, and documents connected to weapons development programs were discovered together. Cryptocurrencies stolen through hacking were laundered to bypass international sanctions, and then reinvested in North Korea's nuclear and missile development. This reveals a direct link between cyber attacks and the funding of warfare.


The comprehensive picture, encompassing the National Election Commission, government agencies, media/civil society, North Korea-China collaboration, and funding, vividly illustrates the multifaceted crisis facing South Korean society. The heart of democracy, the gate of administration, the watchtower of the media, the fence of national defense, and the foundation of the economy were all under simultaneous attack.


Despite this, the National Election Commission and the government continue to repeat denials of "no traces" and are focused on concealment. However, the international security community and foreign media have already disclosed the facts, and if only South Korea remains silent, it risks losing international trust.


The future tasks are clear.


The National Intelligence Service, the prosecution, and the police must conduct joint compulsory investigations and forensic verifications.


The authentication systems of the National Election Commission and government agencies must be completely overhauled, and security verification of the vote counting and tabulation systems must be mandated.


Furthermore, in accordance with the principle of "joint response in cyberspace and space" announced in the joint statement by the South Korean and US defense ministers in October 2024, a practical response system at the level of the South Korea-US-Japan alliance must be activated.


Democracy is not protected by silence. What is needed now is truth-finding, accountability, institutional reform, and alliance cooperation.


Will it crumble in concealment, or be rebuilt through reform? The choice for South Korean democracy has arrived at a time that can no longer afford delay.

 

#Kimsuky #NorthKoreaChinaJointHacking #NationalElectionCommissionPenetration #GPKI #CyberSecurityCrisis #DEFCON33 #APTDown #DemocracyInPeril #ConcealmentOrReform



관련기사
What do you think of this article?
recommend
0
great
0
moved
0
정기구독배너
Go to Mobile Site