NEWS Receive a letter from the police? Learn the tactics of new attacks by North Korean spies

Gold Surfer

Administrator
Staff member
Administrator
Moon-Club
Exclusive
Infinity
Premium
Member
Joined
Jan 20, 2026
Messages
345
Reaction score
2,517
North Korean special services have changed the tactics of cyber attacks.
1779278163068.png
North Korean hackers have been posing as police, military officials and North Korean experts to fraudulently commit people related to South Korea’s security and politics. According to the South Korean company Genians, behind the attacks may be APT37, a group that is associated with military intelligence of the DPRK.

APT37 has long been known for cyber espionage against people working with North Korean topics, as well as attacks for money. In the new campaign, the attackers chose not random users, but specific goals in the field of defense, national security and the study of the DPRK.

The hackers adjusted the letters to the victims and used details that helped to evoke trust. In some reports, they were presented to police officers and wrote that during the investigation of the hack, they found the recipient’s address on a suspicious server. Others pretended to be representatives of defense structures, airfare employees, or participants of research organizations in North Korea.

In one case, the attackers stated that they received materials about the North Korean nuclear power plant and prepare a program that would help specialists better understand the topic. In another case, the author of the letter was introduced to an employee of the defense department, who soon retires and wants to engage in useful projects together with people from the same area.

Genians writes that the hackers took open information about the victims, as well as personal data obtained during past attacks. The letters looked convincing. The campaign continued until at least last month, and one of the malicious files last time was kept on the morning of April 17.

This file was associated with the “Lailey” account. According to Genians, the same account appeared in the 2022 attacks when the attackers posed as the National Advisory Council for the Unification of Korea and the Seoul branch of the UN Human Rights Office.

The report came out against the backdrop of the restructuring of the North Korean special services. In March, the DPRK renamed the Ministry of State Security to the State Intelligence Bureau. In September 2025, the Main Intelligence Agency expanded and renamed the Main Intelligence and Information Bureau. The last department is believed to be associated with APT37.

Genians believe that the appearance of the word “intelligence” in the names of both structures speaks of Pyongyang’s desire to strengthen the collection of information abroad, data analysis and cyber operations.

It is not only officials and specialists who can be at risk. North Korea is also attacking cryptocurrency owners as hacks help the regime to receive foreign currency. South Korea’s National Intelligence Service previously reported that North Korean hackers had stolen more than 2 trillion won, about $1.4 billion, through attacks on cryptocurrency and other targets in South Korea and abroad. According to the agency, the amount was a record for North Korean hackers.

In addition to money, Pyongyang, according to South Korean authorities, is trying to steal defense, industrial and information technology.
 
6,246Threads
82,664Messages
5,994Members
inmeritosLatest member
Top Bottom