DEF CON 33 - Blurred Lines: Evolving Tactics of North Korean Cyber Threat Actors - Seongsu Park

DEF CON 33 - Blurred Lines: Evolving Tactics of North Korean Cyber Threat Actors - Seongsu Park

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 26:54

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Attribution in cyber threat intelligence is increasingly challenging due to the expansion, collaboration, and internal reorganization of threat actors, particularly North Korean groups 2:30.

• North Korean threat actors have expanded significantly, with the Lazarus group growing from ~3,000 to over 8,300 members by 2018, leading to the emergence of subclusters like Diamond, Moonstone, and Citrine with distinct tactics and targets 3:54.
• Intergroup collaboration is evident, such as in a 2023 South Korean cryptocurrency exchange attack where both Kimsky and Lazarus groups operated in tandem—initially using a backdoor, then transferring control to Kimsky for deeper operations 14:53.
• Resource reshuffling occurs, as seen in a 2022–2025 campaign where a Lazarus-style malware (Pebble Dash) was initially used, but evidence from C2 servers and Korean-language spear phishing links pointed to Kimsky group involvement 18:14.
• A new, previously unattributed threat actor emerged in late 2024, leveraging public tools and known code, with evidence suggesting familiarity with Korean culture and operations, likely tied to North Korean actors 23:54.

Accurate attribution requires full infection chain analysis and context-based conclusions, as isolated indicators often lead to errors. Cross-agency cooperation is essential to address evolving threat behaviors.

Sources:

  • 2:30 Explains the growing complexity of North Korean threat actors and the challenges in attribution.
  • 3:54 Details the expansion of Lazarus group and the emergence of distinct subclusters.
  • 14:53 Describes a case of intergroup collaboration between Kimsky and Lazarus groups in a supply chain attack.
  • 18:14 Outlines resource reshuffling from Lazarus to Kims

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Hello everyone. First of all, thank you for having me the Defcon Adversary Village team and thank you for be being here. I didn't expect so many people in here. I yesterday when I came here, I just expect 10 or 50 people is in front of me, but I'm really surprised about that. My story my name is Sonpa from South Korea and this this my talk is about the cyber threat intelligence and some attributions and I want to share some why attribution is so challenging based on my experience tracking the North Korean threat actors okay let's start I'm working in the Gscaler a research team and as a staff threat researcher and I've been tracking the North Korean threat a vectors more than decades So and from when I start the thread intelligence job I I'm I'm the only one who can speak the Korean in our…