Hackers Expose Major North Korean Spying Operation
Hackers claim to have accessed the computer of a North Korean state hacker and have made its contents public, offering a rare look into the insidious hacking practices of this reclusive nation.
The hacker duo, known as Saber and cyb0rg, outlined the breach in the latest issue of Phrack, a prominent cybersecurity electronic magazine that launched in 1985. The current edition was distributed at the Def Con hackers conference held in Las Vegas last week.
As per their article, the hackers compromised a workstation that housed a virtual machine and a virtual private server owned by the individual identified as “Kim.” They allege that Kim is associated with the North Korean espionage unit referred to as Kimsuky, which is also known as APT43 and Thallium. The compromised data has been disclosed to DDoSecrets, a nonprofit organization dedicated to archiving leaked information for public interest.
Kimsuky is recognized as a significant advanced persistent threat group (APT) that reportedly operates under the North Korean government, focusing on targets like journalists, South Korean government bodies, and other entities of intrigue for North Korea’s intelligence strategies.
Beyond governmental operations, Kimsuky also participates in illicit activities typical of cybercriminal organizations, such as cryptocurrency theft and laundering to support North Korea’s nuclear weapon developments.
This hack provides a unique perspective into Kimsuky’s activities, as the hackers managed to breach a member’s workstation instead of relying on the conventional data breach methods typically employed by cybersecurity analysts.
“It highlights the extent to which Kimsuky collaborates with Chinese government hackers, exchanging tools and techniques,” the hackers remarked.

While the actions of Saber and cyb0rg technically constitute a crime, it is improbable that they will face legal consequences due to the extensive sanctions against North Korea. The hackers appear intent on revealing and shaming Kimsuky members.
“Kimsuky, you are not true hackers. Your motivations lie in financial greed to enrich your leaders and propel their political ambitions. You steal from others while advancing your own selfish interests: You are morally corrupt,” the hackers stated in Phrack. “You engage in hacking for all the wrong reasons.”
Saber and cyb0rg claim to have gathered evidence of Kimsuky’s infiltration into multiple South Korean governmental networks and corporations, encompassing email addresses, hacking tools, internal manuals, passwords, and much more.
Emails sent to addresses supposedly belonging to the hackers, as listed in their research, did not elicit any responses.
The hackers mentioned that they identified Kim as a North Korean government hacker through “artifacts and hints” indicating this connection, including configuration files and domain names previously associated with the Kimsuky group.
They also observed that Kim maintained “strict office hours, connecting around 09:00 and disconnecting by 17:00 Pyongyang time.”


