uniladtech homepage
  • News
    • Tech News
    • AI
  • Gadgets
    • Apple
    • iPhone
  • Gaming
    • Playstation
    • Xbox
  • Science
    • News
    • Space
  • Streaming
    • Netflix
  • Vehicles
    • Car News
  • Social Media
    • WhatsApp
    • YouTube
  • Advertise
  • Terms
  • Privacy & Cookies
  • LADbible Group
  • LADbible
  • UNILAD
  • SPORTbible
  • GAMINGbible
  • Tyla
  • FOODbible
  • License Our Content
  • About Us & Contact
  • Jobs
  • Latest
  • Archive
  • Topics A-Z
  • Authors
Facebook
Instagram
X
TikTok
Snapchat
WhatsApp
Submit Your Content
North Korean hacker's Google search history exposed as sleuths infiltrate top-secret documents
Home>News
Published 11:04 15 Aug 2025 GMT+1

North Korean hacker's Google search history exposed as sleuths infiltrate top-secret documents

The breach also included passwords and stolen data

Rebekah Jordan

Rebekah Jordan

google discoverFollow us on Google Discover
Featured Image Credit: Wong Yu Liang / Getty
Cybersecurity

Advert

Advert

Advert

Hackers expose North Korean hacking group's secrets.

Two vigilante hackers have successfully infiltrated a North Korean state-sponsored hacking group and leaked their classified data online.

The breach targeted the notorious Kimsuky group and was detailed in the latest issue of cybersecurity magazine Phrack.

Carried out by hackers identifying themselves as Saber and cyb0rg, the hack includes the personal Google search history of a North Korean operative.

Advert

The 9GB data dump also included passwords, stolen data and hacking tools.

“This article is an invitation for threat hunters, reverse engineers and hackers,” the hackers wrote.

Two hackers successfully infiltrated a North Korean state-sponsored hacking group. (d3sign/Getty)
Two hackers successfully infiltrated a North Korean state-sponsored hacking group. (d3sign/Getty)

“You are driven by financial greed, to enrich your leaders, and to fulfill their political agenda."

Revealing their motivations for targeting Kimsuky, the hackers added: “You steal from others and favour your own. You value yourself above the others: you are morally perverted.”

The 8.9GB trove was released publicly during DEF CON 33 in Las Vegas and is reportedly available for free download on the Distributed Denial of Secrets (DDoSecrets) website.

Analysts believe the leaked documents appear genuine and fit with what you'd expect from real spy operations. While some items were previously known, the new data connects multiple tools and campaigns, providing unprecedented insight into Kimsuky's infrastructure and methods.

The stolen files reveal the tactics and techniques used by Kimsuky, including logs that appear to document attacks on South Korea's military intelligence security agency and Ministry of Foreign Affairs.

According to a report, the Kimsuky hacking group operates like a regular office job, 'always connecting at around 9:00 and disconnecting by 17:00 Pyongyang time.'



Phrack #72 release reveals TTPs, backdoors and targets of a Chinese/North Korean state actor mimicking Kimsuky

A copy of his workstation data was done and is now available for all researchers to analyse!

Article: https://t.co/iCI70eUbuQ
Data dump: https://t.co/vDRLKk8DKD

— Saber (@saber__rt) August 9, 2025


The Kimsuky group has been active since at least 2012 and has conducted numerous attacks on institutions and government agencies worldwide. However, recent analysis shows they've changed focus.

A cybersecurity firm ESET report noted that Kimsuky has shifted away from targeting US and European institutions to concentrate on South Korea.

“In our previous APT Activity Report we noted that Kimsuky was actively targeting, under the guise of interview requests, English-speaking think tanks, NGOs, and North Korea experts,” the report stated.

“These types of campaigns have decreased. Over the past six months, the majority of campaigns attributed to Kimsuky has been targeting South Korean individuals and companies, as well as embassies and diplomatic personnel located in South Korea.”

While most Kimsuky operations involve traditional espionage and data theft, the group has also been linked to cryptocurrency heists.

The stolen digital currency is reportedly used to help pay for North Korea's nuclear weapons program, which makes these hacking attacks a serious threat to global security.

Choose your content:

an hour ago
2 hours ago
  • Stefani Reynolds/Bloomberg via Getty Images
    an hour ago

    Rude three-word tweet aimed at Elon Musk that allegedly cost California billions has resurfaced

    Elon Musk has since become the world's first trillionaire

    News
  • BRENDAN SMIALOWSKI / Contributor via Getty
    an hour ago

    OpenAI is quietly hoping you don’t actually max out your ChatGPT subscription

    Making the most of your subscription could be costly for leading AI companies

    News
  • Cris Cantón / Getty
    2 hours ago

    Covid lab caught 'deliberately overcharging' up to $1,000 per test is now handing out refunds

    Americans from 18 states could be eligible for refunds

    Science
  • Bloomberg / Contributor via Getty
    2 hours ago

    FBI issue urgent PSA to anyone using Microsoft Teams, Outlook or OneDrive

    The announcement warns about a new phishing risk

    News
  • Concerning new satellite images expose top-secret North Korean plant that confirms Kim Jong Un's bone-chilling plan
  • Trump's Justice Department mortified as public realizes they can easily un-redact top secret Epstein files
  • Google issues warning as 48M Gmail logins are stolen in major breach
  • Google issues eerily dystopian warning as hackers use AI to break into company computers