North Korea’s Cybercrime: A Threat to Global Security and Stability

Christian Baghai
3 min readJan 18, 2024

North Korea is widely known as a rogue state that defies international norms and pursues nuclear weapons. But less attention is paid to its other weapon of mass destruction: cybercrime. The video by BBC reveals how a group of hackers from North Korea, known as Lazarus, has stolen more than 1.3 billion dollars from foreign banks and cryptocurrency exchanges in recent years. This is not only a serious crime, but also a threat to global security and stability.

Why North Korea Hacks

North Korea’s cybercrime is driven by two main factors: survival and ambition. Survival means securing the resources and funds needed to sustain its regime and its nuclear program, especially under the pressure of international sanctions and isolation. Ambition means challenging and undermining its enemies, such as South Korea, the United States, and their allies, and asserting its power and influence in the region and beyond.

North Korea has a long history of using unconventional and asymmetric tactics to achieve its goals, such as espionage, sabotage, terrorism, and counterfeiting. Cybercrime is just the latest and most sophisticated manifestation of this strategy. As The Diplomat notes, North Korea has a narrow set of duties for its intelligence and defense agencies: support the Kim regime at all costs through information and economic espionage. Cybercrime offers a low-cost, high-reward, and low-risk way of doing so.

How North Korea Hacks

North Korea’s cybercrime is characterized by its audacity, complexity, and adaptability. The video shows how Lazarus carried out some of the most daring and lucrative cyberattacks in history, such as the 81 million dollar heist from the central bank of Bangladesh, the 275 million dollar theft from Singapore-based KuCoin, and the Sony Pictures hack. These attacks involved sophisticated techniques, such as malware, phishing, social engineering, and blockchain analysis, to infiltrate, manipulate, and exfiltrate data and funds from the targets.

North Korea’s cybercrime is also marked by its ability to evade detection and prosecution, and to adapt to new security measures and technologies. The video reveals how Lazarus used cryptocurrency mixers and over-the-counter brokers to hide the origin of the stolen funds and to cash out. It also suggests that North Korea has a wide network of accomplices and intermediaries across Asia, who help launder and transfer the money. Moreover, North Korea has shown a willingness to learn from its mistakes and to improve its hacking and laundering operations over time.

What North Korea’s Hacks Mean

North Korea’s cybercrime has significant implications for the world, both in terms of security and stability. On the one hand, North Korea’s cybercrime poses a direct threat to the integrity and safety of the financial system, the digital infrastructure, and the personal and corporate data of millions of people and entities. On the other hand, North Korea’s cybercrime also has indirect and long-term consequences for the regional and global order, as it fuels North Korea’s nuclear ambitions, undermines the effectiveness of sanctions, and erodes the trust and cooperation among nations.

North Korea’s cybercrime raises ethical and political questions, such as whether it can be considered an act of war or self-defense, and how the international community should respond to it. Some argue that North Korea’s cybercrime is a legitimate and rational response to the harsh and unfair sanctions imposed by the West, and that it is a way of leveling the playing field and asserting its sovereignty and dignity. Others contend that North Korea’s cybercrime is a blatant and unacceptable violation of international law and norms, and that it is a way of destabilizing and provoking the world and endangering peace and security.

Conclusion

North Korea’s cybercrime is a serious and growing problem that deserves more attention and action from the international community. It is not just a matter of crime, but also a matter of security and stability. North Korea’s cybercrime is not only a means of survival and ambition, but also a weapon of mass destruction. The world needs to understand the strengths and vulnerabilities of North Korea’s hackers, and to devise effective and coordinated strategies to counter and deter them. Otherwise, North Korea’s cybercrime will continue to pose a threat to global security and stability.

--

--