
The targets of North Korean hacking groups are expanding well beyond cryptocurrency to include software (SW) used for developing artificial intelligence (AI). Six malicious packages, detected and disclosed on Thursday by the JFrog security research lab in Silicon Valley, were found to disguise themselves as well-known code packages downloaded more than 1.2 million times a month. They were identified as an "SW supply chain attack" that uses developers' computers as stepping stones to infect entire companies. This is a malicious attempt to hack companies or financial firms wholesale using fake code packages.
The problem is that the multi-stage infiltration structure and disguise techniques of this attack match the activity patterns of "Lazarus," which has been identified as a North Korean hacking group. Along with Kimsuky and Andariel, Lazarus is one of three major hacking groups under North Korea's Reconnaissance General Bureau, and it is notorious these days for stealing cryptocurrency globally. According to blockchain analysis firm TRM Labs, North Korea stole $643 million (about 989.9 billion won) in the first half of this year alone, accounting for a staggering 66% of global cryptocurrency hacking losses. Korea's largest cryptocurrency exchange also had cryptocurrency worth about 58 billion won and 44.5 billion won stolen through hacking in 2019 and last year, respectively. North Korea uses the cryptocurrency stolen through hacking and other means as a funding source to circumvent international sanctions, channeling it into the development of weapons of mass destruction and ballistic missiles.
We must not sit idly by amid the chilling reality that North Korea's SW hacking attacks are aimed at our advanced industries as a whole, including AI development. With high-performance AI that neutralizes existing security systems, such as Anthropic's Mithos, having emerged, if North Korea uses it, the scale of damage and its ripple effects could exceed imagination. Rather than shrugging it off as "just a few code packages," we must recognize cyber security as a core pillar of national security and respond accordingly. Above all, it is urgent to build an "AI defense automation" system that detects and blocks hacking attacks in real time through public-private cooperation. Companies and financial institutions should actively consider introducing a "cyber circuit breaker" that immediately shuts down systems when hacking occurs. Cyber security has now become a core security task that determines national survival. The old practice of trying to gloss things over by saying "it's minor damage, no need to blow it out of proportion" can never be tolerated.






