THREAD: Seeing a trend in the drama abt Zhang Guo James Willy et al: "You can't find him, he's in Pyongyang" "DPRK spies" etc, just a general lack of info about N Korea.

I'm from NK Twitter.

Infosec Twitter is shook, but the big context is this s* has been happening for years.
(This assumes Zhang, Willy, Brown and co. ARE DPRK-linked hackers.)

If they are, they are most likely based in China. You /can/ get internet in the DPRK if you are elite (plebs get their intranet, Kwangmyong), but their telecoms setup is elderly and access is limited by design.
Given the open, real-time communication of the hackers on multiple platforms to folks like @razhael, they are likely NOT based in the DPRK. CN, RU, Malaysia etc

Working abroad, there's 1) better internet access 2) can thwart IP-based attribution to DPRK
NK hackers also began teaming w intl cybercrime orgs, ie Trickbot.

Experts once saw NK hackers as isolated state actors who re-used their own code bits bc they couldn't study other malware due to lack of internet.

They've shed hermit mode and are interacting w targets & collabs
About the spy thing -- They're not TRAINED spies, that's why they do oopsies like respond to DMs from journos

Even tho they're under Reconnaissance General Bureau, NK hackers (AFAIK) funnel thru IT universities onto 'finishing school' in CN/RU. They don't get tradecraft training
No doubt COVID-19 played a role in the 'leveling up.' The bigger context is the DPRK is HURTING right now, & is taking big risks to get cash and vulns through cyber.

Knowing full-on COVID would end the regime, NK closed its borders in Jan 2020, causing trade to crash 81% YoY(!)
Infosec Twitter is taking the attack personally, but highly specific targeting is just NK's MO now! They were after your vulns and your crypto, but not your nudes.

Zhang+Willy are prob just 1-4 guys sitting in a shitty apt in Liaoning/Jilin under lockdown like all of us.
If you enjoyed this v long thread (thank you for reaching the end) please give the cyber archives at NK News a read~ 

Also, feel free to Twitter DM me and if you're not a troll I'll get back to you!
You can follow @minchaochoy.
Tip: mention @twtextapp on a Twitter thread with the keyword “unroll” to get a link to it.

Latest Threads Unrolled:

By continuing to use the site, you are consenting to the use of cookies as explained in our Cookie Policy to improve your experience.