EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/cyberattack/darkseoul-2013
313/430

File EL-0118CriticalResolvedCyberattack / Espionage Operation

DarkSeoul Attack

Also filed as DarkSeoul · South Korea Cyberattack 2013

The DarkSeoul Attack was a sophisticated cyber espionage campaign targeting critical infrastructure in South Korea in 2013. The operation utilized custom malware to infiltrate financial institutions and media organizations. Its primary goal was believed to be the theft of sensitive financial data and proprietary information.

  • #lazarus-group
  • #south-korea
  • #apt
  • #banking-malware
  • #espionage
  • #cyberattack
Notoriety8/10
Event
20 Mar 2013
Disclosed
20 Mar 2013
Target
South Korean Financial and Media Targets
Actor
Lazarus Group
Status
Resolved

01Summary

The DarkSeoul campaign, attributed to the Lazarus Group, involved the deployment of highly customized malware designed for deep penetration into South Korean networks. The attackers successfully compromised multiple banks and media companies, suggesting a coordinated effort to gather diverse types of intelligence. The malware was capable of lateral movement and data exfiltration, indicating a high level of operational sophistication. While the exact scope of data theft remains classified, the attack demonstrated the group's capability to conduct targeted, long-term espionage operations against a developed nation's core economic and informational sectors. The incident significantly raised global awareness regarding the threat posed by state-sponsored cybercrime.

02Background

Prior to 2013, South Korea was already a known target for advanced persistent threats (APTs) due to its advanced technology sector and strong financial markets. The DarkSeoul attack represented a significant escalation in the sophistication and breadth of cyber espionage targeting the nation's most vital assets.

03Key revelations

  1. 01The successful infiltration of multiple major South Korean banks and media outlets simultaneously.
  2. 02The use of highly customized, multi-stage malware indicating significant state-level resources.
  3. 03The focus on both financial data (banking credentials) and journalistic sources (media targets).

04Technical analysis

The malware used in the DarkSeoul attack was highly modular and featured multiple components, including banking Trojans and information stealers. It was designed to evade modern security measures, utilizing techniques like process injection and rootkit functionality. The attackers focused on establishing persistent footholds within the victim networks before initiating data collection and exfiltration.

Attack vector
Spear-phishing or exploitation of unpatched vulnerabilities in network perimeter devices.
Attack method
Espionage and Financial Theft
Initial access
Phishing/Exploitation
Lateral movement
Pass-the-Hash / Network Exploitation
Persistence
Registry Modification / Scheduled Tasks
Exfiltration
Encrypted Channels / DNS Tunneling
Tool / malware
DarkSeoul Malware
Malware family
Banking Trojan / Info Stealer
Malware type
Spyware, Trojan, Stealer

MITRE ATT&CK techniques

  • T1022
  • T1059.003
  • T1566.001

05Threat actor

The Lazarus Group is widely believed to be a state-sponsored hacking collective operating out of North Korea. They are known for their dual focus on financial theft (e.g., bank heists) and intelligence gathering, making them one of the most versatile and dangerous cyber threats globally.

Aliases

  • APT31
  • Hidden Cobra

APT designations

  • APT31

MITRE groups

  • T1071.001
  • T1566.001

Attribution sources

  • Mandiant
  • FireEye
  • Cybersecurity Industry Reports

06Victims and impact

Additional victims

  • South Korean Media Outlets
  • South Korean Banks

Countries affected

  • South Korea

07Data exposed

Data types

  • Financial records
  • Credentials
  • Proprietary corporate data
  • Journalistic sources

08Financial damage

Damage was primarily intellectual property loss and operational disruption, not direct ransom payment.

09Timeline

  1. 2013-03-20DarkSeoul malware detected and initial compromise confirmed.
  2. 2013-03-20South Korean authorities and private firms begin investigation into the scope of the breach.

10Reaction and fallout

Public reaction

The attack prompted immediate, high-level warnings from South Korean government agencies and increased public scrutiny of national cybersecurity defenses. It served as a major wake-up call regarding the threat of state-sponsored cyber espionage.

Political impact

The incident heightened geopolitical tensions between South Korea and North Korea, solidifying the narrative of North Korea's involvement in cyber warfare. It also spurred increased international cooperation on cyber defense standards.

Geopolitical consequences

It contributed to the global shift in viewing cyberattacks as a primary tool of state conflict, influencing international norms and treaties regarding digital warfare.

11Legal

No specific criminal charges were filed against the Lazarus Group, as they are state-sponsored actors. However, the incident contributed to increased international sanctions and diplomatic pressure against North Korea.

12Aftermath

Policy changes

  • Increased mandatory reporting requirements for critical infrastructure in South Korea.

Regulatory changes

  • Strengthening of national cybersecurity laws and protocols.

Security improvements

  • Adoption of Zero Trust Architecture (ZTA) principles in critical sectors.
  • Enhanced network segmentation and behavioral monitoring.

13Significance and legacy

Significance

DarkSeoul is a landmark case study in state-sponsored cyber espionage. It demonstrated the ability of a non-traditional military power (DPRK) to conduct highly sophisticated, multi-sector attacks against a technologically advanced economy, setting a precedent for modern cyber warfare.

Legacy

The attack contributed significantly to the commercialization of threat intelligence, forcing private security firms and governments to collaborate more closely. It also accelerated the development of advanced defensive technologies like AI-driven behavioral analytics.

14Disclosure and media

Authentication
Technical analysis of malware samples and network logs

Media partners

  • Mandiant

Publishing organisations

  • Mandiant

15Related files

Related events

  • Sony Pictures Hack
  • Bangladesh Bank Heist

Went on to inspire

16Field notes

  1. 01The malware was reportedly designed to steal credentials and proprietary information, rather than simply causing disruption.
  2. 02The attack was one of the earliest publicly attributed examples of a state-sponsored group using sophisticated banking Trojans for espionage purposes.

17Resolution

The immediate threat was mitigated through network hardening and the deployment of advanced threat detection systems by the victim organizations and government agencies.

18Sources

Official documents

  • Mandiant Threat Report (2013)

References

  1. [1]Mandiant
  2. [2]South Korean Government Statements
Fact sheetEL-0118

Dates

Event
20 Mar 2013
Started
20 Mar 2013
Ended
20 Mar 2013
Duration
1 days
Discovered
20 Mar 2013
Disclosed
20 Mar 2013
Ongoing
No

Target

Organisation
South Korean Financial and Media Targets
Type
Financial Institution
Sector
Banking, Media, Government
Country
South Korea
Gov. level
Federal

Actor

Name
Lazarus Group
Type
Nation-State Actor
Nationality
North Korea
Nation-state
Democratic People's Republic of Korea (DPRK)
Motivation
Financial gain and intelligence gathering, attributed to state objectives.
Attribution
Medium
Status
Active
Arrested
No
Convicted
No

Data

Sensitivity
Secret
Published
No

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.