Hackers Uncover Reasons for Exposing North Korean Cybercriminal Activities
Earlier this year, a pair of hackers breached a computer and quickly recognized its significance. They stumbled upon the machine of an individual believed to have ties to the North Korean government.
Determined to dig deeper, the duo uncovered what they asserted was evidence linking the hacker to North Korean cyberespionage efforts, various hacking tools, and the infrastructure supporting those operations.
Saber, one of the hackers, disclosed to TechCrunch that they had access to the government worker’s computer for around four months. Once they understood the magnitude of the data they had discovered, they felt an obligation to leak it and publicize their findings.
“These nation-state hackers are operating for entirely the wrong reasons. I hope more of their actions come to light; they deserve it,” Saber remarked after he and cyb0rg published their findings in the well-known hacking e-zine Phrack.
Numerous cybersecurity firms and researchers keep a close watch on the activities of the North Korean government and its various hacking collectives. This includes espionage missions, significant cryptocurrency thefts, and elaborate ruses where North Koreans impersonate remote IT workers to support the regime’s nuclear ambitions.
In this case, Saber and cyb0rg went a step further by hacking the hackers, shedding light on the daily operations of these state-sponsored groups, as Saber described.
The hackers prefer to use the aliases Saber and cyb0rg to shield themselves from potential retaliation from the North Korean government and others. Saber identifies as a hacktivist and draws inspiration from the legendary hacktivist Phineas Fisher, known for targeting spyware companies FinFisher and Hacking Team.
TechCrunch event
San Francisco
|
October 27-29, 2025
At the same time, the hackers are aware of the illegal nature of their actions, yet they find it crucial to bring these matters to light.
“Keeping this information to ourselves wouldn’t do much good,” Saber commented. “By revealing it publicly, we aim to equip researchers with more tools to detect these activities.”
“We hope this will also aid in identifying many of their ongoing victims, resulting in the North Korean hackers losing access,” he added.
“Regardless of the legality, this action has generated tangible benefits for the community; that’s what truly counts,” cyb0rg conveyed through a message from Saber.
Saber suspects that the hacker, known as “Kim,” may actually be Chinese and could be working for both countries, based on evidence suggesting Kim took no holidays in China, indicating he could be residing there.
Additionally, Saber noted that Kim sometimes translated Korean documents into simplified Chinese using Google Translate.
Saber has never reached out to Kim. “I don’t think he would heed my words; he supports his rulers, the same rulers who oppress his people,” he said. “I would probably suggest he use his skills for good, not harm. But given the relentless propaganda he’s subjected to, that would likely fall on deaf ears.” This remark emphasizes the severe information isolation faced by North Koreans.
Saber chose not to disclose how he and cyb0rg accessed Kim’s computer, believing they could replicate these methods to infiltrate other systems in the future.
During their investigation,
Saber and cyb0rg uncovered evidence of Kim conducting active hacks against companies in South Korea and Taiwan, which they reported to the pertinent organizations.
North Korean hackers are also known to target individuals within the cybersecurity industry. Although Saber is aware of this danger, he mentioned, “I’m not overly concerned.”
“There’s not much that can be done about it, but I’ll definitely exercise more caution :),” Saber added.
We’re constantly seeking to improve, and by sharing your perspective and feedback on TechCrunch and our coverage and events, you can help us! Fill out this survey to let us know how we’re doing and get a chance to win a prize in return!


