North Korea: A Cyber Threat Assessment

On 25 July, the UK National Cyber Security Centre Centre (NCSC) issued a warning that North Korea is sponsoring cyber operations on critical infrastructure and organisations. The NCSC warning coincided with similar warnings from US and South Korean intelligence agencies. All three countries highlighted cyber attacks by Andariel Group (APT45) over the past three years as a demonstration of the growing sophistication of North Korea’s cyber capabilities.

The Reconnaissance General Bureau (RGB) – North Korea’s primary intelligence agency – sponsors national advanced persistent threat (ATP) actors. North Korean APTs primarily steal intellectual property and sensitive information that furthers the goals of the regime in Pyongyang. Multiple sectors report cyberattacks by North Korean APTs, from defence through to agriculture. Especially as the regime compensates for North Korea’s technological isolation. Furthermore, North Korean cyber operations are not limited to South Korea and the US. Reported attacks come from across the globe, from Brazil to India. 

Key Judgement 1. It is highly likely North Korean hackers are targeting defence, aerospace and energy sectors to advance Pyongyang’s military and nuclear technology.

Key Judgement 2. It is likely North Korea’s self-imposed isolation and risk of famine is driving the theft of agricultural intellectual property as Pyongyang seeks to boost crop yields.

Key Judgement 3. It is highly likely North Korean ransomware attacks enable Pyongyang to generate revenue for further cyber attacks and other illicit activities.

Rest of this post is for members only

Already have an account?  Log in

6 Months
£1500
12 months
£3000
Already a member? Log in here

Jake Cremin

Jake Cremin is an Intelligence Analyst specialising in the Russo-Ukraine War and Western Defence. Jake holds a Masters in Intelligence and Security Studies from Brunel University London as well as BA in Military and International History. His research interests are Western Defence, West African Security and Terrorism.
Table of Contents

Related Content

Locked

Ukraine Frontline Update: Pokrovsk 

Location:_ Europe
Locked

Takeaways from China’s September 2025 Parade

Location:_ Far East
Locked

UAT-7237: China’s Silent Watcher in Taiwan

Location:_ Far East

Stay in the loop

Get a free weekly email that makes reading
intel articles and reports actually enjoyable.

Table of Contents

Log in

Stay in the loop

Join thousands of people receiving ground truth based reports that affect their business, investments and personal life.

Contact

Contact

"*" indicates required fields

This field is for validation purposes and should be left unchanged.