Catching DPRK with Korean Linguistic Traits
2024-12-13 • 0xmh1 •
The source explains how Korean-language artifacts can support DPRK malware and phishing attribution when treated as one signal among others, not as standalone proof. It highlights wording and grammar that sound North Korean or unnatural to South Korean speakers, including 미안하다 in formal apologies, 오유 instead of 오류 for error, 현시 for at this time, 인차 for immediately, and 되여 forms where South Korean usage would write 되어. The examples come from suspected DPRK cyber operations and show how operators can expose origin clues through lure text, error messages, and interface strings. The author cautions that these linguistic traits should inform CTI analysis but should not by themselves prove North Korean attribution.