North Korean hackers compromised at least two semiconductor firms in South Korea

North Korean hackers compromised at least two semiconductor firms in South Korea

A threat actor linked to the North Korean government has infiltrated at least two semiconductor manufacturers in South Korea, the National Intelligence Service (NIS) revealed.

According to Seoul’s spy agency, the attacks, aimed at obtaining chipmaking equipment designs, occurred in December 2023 and February 2024. The campaign is believed to be part of North Korea's efforts to bypass sanctions and bolster its semiconductor capabilities for military purposes.

“The National Intelligence Service believes that North Korea may have begun preparing to produce its own semiconductors due to difficulties in procuring semiconductors due to sanctions against North Korea and increased demand due to the development of weapons such as satellites and missiles,” the agency said.

North Korean hackers breached the servers of the targeted firms, absconding with valuable product design blueprints and facility images.

The intruders employed a technique known as “living off the land,” which involves the use of legitimate tools and features already present in the target system to evade detection by security software. Exploiting vulnerabilities in internet-connected systems, the threat actors compromised servers responsible for maintaining computer infrastructure and security protocols.

The NIS didn’t disclose the targeted companies but said it notified the affected manufacturers of the cyber intrusion and shared threat intelligence about the attacks with other domestic semiconductor firms.


Back to the list

Latest Posts

Researchers caught embedding hidden AI prompts to sway research reviewers

Researchers caught embedding hidden AI prompts to sway research reviewers

The investigation analyzed English-language preprints published on the research platform arXiv and found concealed AI instructions in 17 papers.
7 July 2025
Brazilian programmer arrested for role in $185 million bank hack

Brazilian programmer arrested for role in $185 million bank hack

João Nazareno Roque, a junior back-end developer at C&M, was allegedly recruited by hackers in a bar in São Paulo.
7 July 2025
APT36 cyber-espionage campaign targeting Indian defense sector via BOSS Linux

APT36 cyber-espionage campaign targeting Indian defense sector via BOSS Linux

More recently, APT36 has shifted its focus to Linux-based environments.
7 July 2025