
For years, North Korea's state-trained hackers have been one of the world's most prolific robbers of banks - stealing huge sums of money from foreign financial instituions, draining cryptocurrency exchanges of billions, and funnelling the proceeds into the country's weapons programme.
But now, in a remarkable twist, some of the same elite hackers appear to have decided to rob their own government instead. And, it doesn't sound as if it has ended that well for them.
According to a report by Daily NK, which specialises in reporting on the internal affairs of North Korea, the country's National Intelligence Agency arrested a hacking ring on 12 July after uncovering a sophisticated scheme to steal from the Chosun Central Bank and the Foreign Trade Bank - the two institutions sitting at the very heart of North Korea's financial system.
The ringleaders of the group are said to be discharged veterans from a cyber operations unit under North Korea's Reconnaissance and Intelligence General Bureau. That is the same shadowy military intelligence agency that runs the Lazarus Group, the hackers responsible for stealing billions from foreign banks and cryptocurrency exchanges over the past decade.
Those arrested are not Lazarus members themselves, but - if reports are correct - were trained in the same system, by the same institution, and had the same skills.
After leaving military service, the veterans allegedly recruited young IT prodigies from Kim Chaek University of Technology and Pyongyang University of Science and quietly built an operation to enrich themselves personally rather than fill the North Korean state's coffers.
Using Chinese-made specialist wireless equipment and encrypted messaging apps, the group is said to have broken into the well-guarded internal networks and foreign payment systems of both banks. Once inside, they allegedly took split portions of state trade funds into tiny increments - in an attempt to avoid detection - and moved the funds into cryptocurrency wallets.
Brokers in China are reported to have converted the cryptocurrency back into cash, while contacts in border areas exchanged the laundered funds for US dollars and Chinese yuan.
In short, the hackers are accused of building a mini version of the same kind of money-laundering infrastructure North Korea deploys internationally, and turned it inwards.
Unfortunately for the hackers, officials in Pyongyang began noticing small discrepancies in foreign currency payment approvals and flagged suspicious access to overseas IP addresses. Investigators for the National Intelligence Agency traced encrypted cryptocurrency traffic to a location in Pyongyang, and raided it on the night of 12 July - seemingly catching the hackers while they were laundering funds via their computers.
Computer equipment and burner phones have been confiscated by the authorities, as part of the investigation.
Lets not forget - this is all happening in the dictatorship of North Korea. Any punishment dealt out by the authorities against the hackers is likely to not just be harsh, but also extend beyond the individuals involved to include their families as well.
NK Daily quotes a source as reporting that an official had said in response to the case:
"They used the skills the state trained them with to defend the country, and instead robbed the country’s coffers. This goes beyond ordinary guilt-by-association penalties. It will be hard for the entire family line to survive."
tags
Graham Cluley is an award-winning security blogger, researcher and public speaker. He has been working in the computer security industry since the early 1990s.
View all posts