기사 메일전송
North Korea Plundered 2 Trillion Won in Virtual Assets Last Year... Record-High Hacking
  • Yonhap News
  • May 10, 2026 at 7:54 PM
기사수정
  • Deepfake for Employment and Supply Chain Infiltration... North Korea's Hacking Methods Becoming More Sophisticated
  • NIS "New types of attacks, such as remote smartphone initialization, confirmed"


National Cybersecurity Center ReportNational Cybersecurity Center Report [Provided by the National Intelligence Service National Cybersecurity Center]

North Korea reportedly stole over 2 trillion won worth of virtual assets last year, the largest amount ever.


◇ North Korea's Hacking Evolves: Penetrating Document Management Solutions & Using Deepfakes for Employment


On the 10th, the National Intelligence Service's National Cybersecurity Center (NCSC) released its annual report detailing cybersecurity threats and response activities from the past year.


North Korea is engaged in technological theft and large-scale financial asset theft across various sectors, including defense and information technology (IT).


North Korean organizations exploited vulnerabilities in three domestic document management solutions to create administrator accounts and steal data.


The sensitive data leaked in this process is reported to range from at least 700 to up to 2.6 million cases.


The North Korean hacking group Andariel infiltrated the IT maintenance systems of infrastructure networks, seized over 20 servers, and stole core materials such as blueprints.


Authorities on Upbit HackLazarus, a hacking group under North Korea's Reconnaissance General Bureau, is strongly suspected of being behind the 44.5 billion won virtual asset hacking incident at Upbit, South Korea's largest virtual asset exchange. The photo shows an Upbit advertisement displayed in a Seoul subway station on the 28th. [Yonhap News Agency] 

In particular, attack methods have been identified where hackers infiltrate open-source supply chains or use video interviews employing deepfakes to impersonate individuals and gain fraudulent employment at overseas IT companies.


Furthermore, unprecedented tactics have emerged, such as remotely resetting smartphones to neutralize security responses.


Through these techniques, North Korea is estimated to have stolen over 2 trillion won in virtual assets last year alone.


◇ Government Pursues Cyber119 and Post-Quantum Cryptography, Kicking Off N2SF Framework


In response to these threats, the government launched Cyber119, a nationwide response organization, in August 2024.


This organization divides the country into five regions, including the metropolitan and Yeongnam areas, and deploys over 130 experts from 46 institutions to enable initial response to large-scale hacking or network paralysis incidents.


The government has also implemented the National Network Security Framework (N2SF), which applies differential security controls based on data criticality—classified as confidential, sensitive, or public—thereby laying the groundwork for safely utilizing new technologies such as generative AI and cloud in the public sector.


Preparations are also accelerating in the future security domains of space and quantum technology.


Cybersecurity guidelines for space systems have been established, and four types of Korean post-quantum cryptography have been finalized to prepare for the threat of quantum computers.


The government is currently pursuing a comprehensive roadmap to transition the national cryptographic system to post-quantum cryptography by 2035.


The National Cybersecurity Center stated, "The large-scale personal information leaks and government network paralysis incidents experienced last year demonstrate that cyber threats can directly lead to physical damage," and added, "We will continue to proactively respond to threats utilizing AI and new technologies to build a digital environment that citizens can trust."


What do you think of this article?
recommend
0
great
0
moved
0
정기구독배너
Go to Mobile Site