Police say North Korea impersonated horoscope writers, counterintelligence command in 120,000 phishing emails
Audio report: written by reporters, read by AI
North Korean hackers sent more than 120,000 phishing emails over a two-month period, impersonating subjects such as the Defense Counterintelligence Command and horoscope subscriptions in an attempt to steal personal information, South Korean police said on Tuesday.
An investigation into phishing emails sent last December had confirmed North Korea’s involvement, the National Office of Investigation (NOI) under the National Police Agency announced in a briefing on Tuesday.
Police began investigating after confirming that, at 1:45 p.m. on Dec. 11, an email titled “Defense Counterintelligence Command's Martial Law Documents Revealed” had been distributed to an unspecified number of recipients.
The email encouraged recipients to download an attached file, claiming it contained content prepared under the direction of former Defense Counterintelligence Commander Yeo In-hyung, reviewing whether former President Yoon Suk Yeol had the right to refuse a National Assembly request to lift martial law. The attachment contained malware that would be executed upon download.
The Ministry of Science and ICT warned of a large-scale distribution of hacking emails after these emails were distributed.
North Korean hacking groups sent 126,266 phishing emails to 17,744 individuals between November 2024 and January 2025, according to police. Police secured 15 domestic servers used to send the emails and identified evidence of North Korea's cyberattack activity. North Korean hackers are believed to have rented these servers through foreign companies to bypass spam filters and other barriers.
The North Korean group used approximately 30 types of impersonation emails. Some posed as daily horoscopes, economic articles, health newsletters or tax refund notices. Others mimicked invitations to the concerts of famous singers such as Lim Young-woong.
Recipients who clicked links within the emails were directed to spoofs of popular websites like Naver or Google. Victims were prompted to enter their IDs and passwords on these counterfeit sites.
Police discovered that the fake sites’ URLs mimicked real ones but included additional terms like “auth” or “login.” The senders' email addresses were also disguised to resemble those official agencies or acquaintances, such as “seoul-news.”
Forensic analysis of the secured servers uncovered significant traces of North Korean involvement. The servers matched those used in previous North Korean cyberattacks, and the originating IP addresses were allocated to Liaoning Province, a border region between North Korea and China.
In particular, police found that the servers used North Korean-specific vocabulary, such as pogu for “port,” gidong for “operation,” and pege for “page.”
“These terms and vocabulary were identified based on materials published by the Korea Institute for National Unification,” a police official explained.
Of the 17,744 people who received the phishing emails, 120 were found to have entered personal information such as their ID or password, though no sensitive information was leaked. Police have advised these individuals to take protective measures.
Police noted that while North Korean hackers have traditionally targeted individuals working in North Korea-related fields or government officials in defense or foreign affairs, this attack was different in that it involved the mass distribution of fake advertising emails to the general public.
Authorities are also investigating potential links to known North Korean hacking groups, such as Lazarus, under Pyongyang’s Reconnaissance General Bureau.
“To prevent damage from phishing emails, it is essential to avoid opening emails from unknown senders or clicking on attachments or links,” a police official emphasized.
Translated from the JoongAng Ilbo using generative AI and edited by Korea JoongAng Daily staff.
BY NA UN-CHAE [lim.jeongwon@joongang.co.kr]