A Decade After OPLAN 5015 Breach, North Korea Turns to AI Hacking | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker

In September 2016, hackers believed to be North Korean breached South Korea’s Defense Integrated Data Center and extracted 235 gigabytes of material from the military’s internal network and its external internet network. Among the documents confirmed leaked were 295 classified military files, including 226 classified as Secret, 42 classified as Confidential and 27 marked restricted (For Official Use Only). Investigators also confirmed the leak of OPLAN 5015, the South Korea-U.S. combined forces operational plan.
A decade later, North Korea’s cyber operations have grown more sophisticated. Recent cases suggest the country is now using artificial intelligence in its attacks. Earlier campaigns went no further than recycling stolen documents as phishing bait or drafting phishing messages with AI. More recently, attackers have used AI to fabricate documents such as cryptocurrency and financial investment reports that look like genuine material, then lure targets into running malicious code. The North Korean hacking group Kimsuky has also been found attempting to automate parts of its operations, using AI to analyze stolen documents, identify targets and produce fake investment reports.
North Korea began using cyber warfare as a key asymmetric capability long ago. In the June 25 cyberattack of 2013, 69 organizations were hit, including the websites of the presidential office and the Office for Government Policy Coordination as well as news outlets. Messages such as “Long live General Kim Jong-un, president of unification” were posted on the presidential website at the time. In 2013, Kim Jong-un, chairman of the State Affairs Commission, said cyber warfare “is, along with nuclear weapons and missiles, an all-purpose sword that guarantees our People’s Army’s ruthless strike capability.”
North Korea’s attacks later expanded into core national technology sectors such as defense and nuclear power. Between 2014 and 2016, the North stole roughly 40,000 files from a major South Korean defense company. In 2021, nuclear technology materials were also targeted at institutions including the Korea Atomic Energy Research Institute. Korea Aerospace Industries is known to have been targeted by North Korea-linked hacking groups in the past, though experts say it is difficult to conclude that KF-21 technology was leaked.
Attempted cyberattacks on the military are also rising. According to data submitted by the Ministry of National Defense to Yoo Yong-won, a lawmaker of the People Power Party who sits on the National Assembly’s National Defense Committee, attempted attacks on the military fell to 9,115 in 2022 from 11,700 in 2021, then climbed again to 13,599 in 2023, 14,419 in 2024 and 18,951 in 2025. Of last year’s attempts, 18,792 — the vast majority — were website intrusions aimed at seizing administrator privileges.
While North Korea’s capabilities have advanced, critics say the government’s practice of announcing countermeasures after each hacking incident cannot keep pace with the speed of attack technology. Officials in the military and the defense industry say the North’s cyber strategy, covert operations structure and attack methods need closer analysis, and that laws and institutions governing cybersecurity must be overhauled quickly. Shin Jong-woo, secretary general of the Korea Defense and Security Forum, said legislation is urgently needed. “Just as major countries around the world are moving quickly to strengthen laws on cyber terrorism and terrorism, we urgently need to enact what might be called a National Cybersecurity Framework Act to curb cyber security threats,” he said.
Kimsuky, Lazarus and Andariel, all known as world-class hacking groups, belong to Bureau 3, the technical reconnaissance unit that handles cyber operations for North Korea’s Reconnaissance and Intelligence General Bureau, formerly the Reconnaissance General Bureau. All are based at Research Center 110. Kimsuky hacks defense and security agencies, Andariel targets defense contractors and advanced technology sectors, and Lazarus mainly goes after financial institutions such as cryptocurrency exchanges and banks.

