An exploratory analysis of the DPRK cyber threat landscape using publicly available reports

2025-01-20 lazarusholic

https://link.springer.com/article/10.1007/s10207-025-00980-x

Thumbnail for An exploratory analysis of the DPRK cyber threat landscape using publicly available reports

The Springer study analyzes DPRK cyber activity by mining more than 2,000 public reports from 2009 through May 2024. It clusters vendor naming conventions into 160 actor code names, maps those names into seven widely recognized DPRK threat groups, and extracts 154 notable incidents with motivation and target-sector context. The paper frames DPRK operators as global espionage and financially motivated actors whose activity extends beyond South Korea into ransomware, cryptocurrency theft, and other operations. Its dataset is intended to help researchers reconcile aliases, incidents, and public CTI reporting on North Korean state-sponsored activity.

Related Actors

First seen: Jul 2017
Last seen: May 2026

Related Reports

« Back