North Korea — Cyber Threat Profile
North Korea operates one of the most aggressive state-sponsored cyber programs globally. The Lazarus Group and affiliated units conduct financially motivated attacks , including cryptocurrency theft, ransomware, and SWIFT system exploitation , directly funding the regime and circumventing international sanctions. Estimated billions stolen from global financial institutions and crypto exchanges. Separately, cyber espionage targets defense contractors, governments, and nuclear programs. Domestic internet access is virtually nonexistent for citizens. The regime faces zero accountability, enabling persistent and escalating operations. Allied nations consistently attribute attacks publicly, but deterrence remains limited. North Korea treats cyberspace as a primary asymmetric instrument of national power and revenue generation.- World Cybercrime Index 2024 (origin significance): 10.61 / 100, #7 worldwide
- Secure Internet servers per 1M people (2024): 10.4 (source: World Bank)
Latest North Korea coverage
- North Korea's hacking machine is bigger than Lazarus 2026-09-07 · Nation-State
- ScoringMathTea: Inside Lazarus Group's Modular RAT with Reflective Plugin Loading and PEB-Walking API Evasion 2026-02-16 · Nation-State
- Lazarus Group Targets Aerospace and Defense with New Comebacker Variant: ChaCha20 Encryption and AES-Encrypted C2 Mark Evolving Tradecraft 2026-02-16 · Nation-State
- Operation DreamJob Targets European UAV and Defense Manufacturers: Lazarus Deploys ScoringMathTea via Trojanized Open-Source Tools 2026-02-16 · Nation-State
- Kimsuky Abuses GitHub as C2 Infrastructure: Hardcoded Private Tokens Enable Malware Delivery and Exfiltration via Nine Private Repositories 2026-02-16 · Nation-State
- Kimsuky Deploys HttpTroy Backdoor via VPN Invoice Lure: Three-Stage Chain Using MemLoad and COM-Based Persistence 2026-02-16 · Nation-State
- TraderTraitor (Lazarus/UNC4899): JumpCloud Supply Chain Compromise, Bybit $1.5B Safe{Wallet} AWS Session Token Theft, and DMM Bitcoin $308M RN Stealer Campaign 2026-02-16 · Nation-State
- APT37 Deploys Rust-Based Backdoor and Python Loader in Targeted Campaign Against South Korean Dissidents 2026-02-16 · Nation-State
- Kimsuky's LNK-to-PowerShell Espionage Chain: Credential Theft, Keylogging, and Exfiltration Targeting South Korean Government 2026-02-16 · Nation-State
- Lazarus Contagious Interview Deploys Tsunami Framework: Modular Malware Uses TOR and Pastebin for C2 in Cryptocurrency Theft Campaign 2026-02-16 · Nation-State
- Lazarus Group's LinkedIn Recruiting Scam Deploys Cross-Platform Stealer Chain Leading to Tsunami Framework and Tor C2 2026-02-16 · Nation-State
- North Korean Andariel Group Linked to Play Ransomware in Unprecedented Nation-State Collaboration 2026-02-16 · Ransomware
- Operation Dream Magic: Lazarus Group Exploits MagicLine Vulnerability in Watering Hole Campaign Targeting 40 South Korean Organizations 2026-02-16 · Nation-State
- Kimsuky Adds Chrome Remote Desktop to Remote Control Arsenal Alongside AppleSeed, RDP Patcher, and Ngrok 2026-02-16 · Nation-State
- Lazarus Group (APT38): North Korea's Most Prolific Cyber Threat Actor Targets Banks, Crypto, and Critical Infrastructure 2026-02-16 · Nation-State