News
Interview
"North Korean hackers combed blogs to pick out coin investors, planted malware in a "North Korea missions" folder"
2026.07.24

🚨 "North Korea's hackers really do their homework."

In a recent interview with Monthly JoongAng, S2W's CPO, Jaeki Kim, shared his insights on how North Korean cyber threat actors are evolving their operations.

"They don't miss a single new technology. When Web3 emerged, attacks exploiting it appeared almost immediately. As AI advanced, they quickly incorporated phishing and AI-generated images into their operations."

Their targets, objectives, and tradecraft are evolving faster than ever. Here are a few of the key shifts Kim highlighted in how North Korean threat actors operate.

━━━━━━━━━━━━

✔️ Targets — Not just anyone, but the "hand-picked"
Researchers discovered malware designed to target only users who had written about Bitcoin or Ethereum on blogs and online communities. Rather than launching indiscriminate campaigns, they carefully research and select their victims before deploying malware.

✔️ Objectives — From information to "financial gain"
As international sanctions tightened, North Korea increasingly turned to cyberattacks as a source of revenue. Their operations have expanded beyond information theft to include ransomware attacks aimed at financial gain.

✔️ Tradecraft — Beyond human hands, with "AI"
North Korean threat actors are rapidly adopting AI to make their operations more convincing and sophisticated. Beyond phishing emails, AI is being used to create fake personas and AI-generated images that help build trust with victims before an attack.

━━━━━━━━━━━━

As Kim explains, understanding an adversary isn't just about tracking malware or indicators of compromise. It's also about understanding how they think, how they adapt, and where they may go next.

Among the cases he shared was malware containing a folder labeled "North Korea missions" in Korean, offering a glimpse into how these operations may be organized. If you're interested in learning more about how North Korean threat actors continue to evolve, read the full interview below.

📰 [Monthly JoongAng] North Korean hackers combed blogs to pick out coin investors, planted malware in a "North Korea missions" folder
🔗 https://bit.ly/4wwpEzC

List