South Korea has expressed concern about North Korean hackers targeting the country's shipbuilding sector to steal military secrets from the navy. The agency said the leaks are part of North Korean leader Kim Jong Un's strategy to build larger, more advanced warships.
See also: Microsoft: North Korean hackers are attacking Russian targets

According to a statement from South Korea's National Intelligence Service, widespread attacks from North Korea on South Korean shipyards were detected in August and September.
“It is assumed that such attacks were carried out due to an order from Kim Jong-un to build medium- to large-sized warships. It is expected that North Korea will continue to carry out such attacks against South Korean shipyards and component manufacturing companies,” the organization warned.
The agency announced that it is informing shipbuilders about threats to their systems and online infrastructure and is advising major shipyards to conduct independent security audits to plug security gaps in their digital infrastructure.
South Korea's leading manufacturers of warships and submarines are Daewoo Shipbuilding & Marine Engineering Co. Ltd. and Hyundai Heavy Industries. Hyundai is building a new batch of warships with the advanced Aegis combat system produced in the United States.
Daewoo Shipyard suffered a major cyberattack in 2021 by North Korean hackers that threatened at least 60 secret naval designs, including plans for a nuclear-powered submarine. The shipyard was also attacked in April 2016 by North Korean hackers, who leaked sensitive secrets about the development of warships and submarines.
See also: "ScarCruft": North Korean hackers breached Russian missile designer

According to a Microsoft report in September , North Korean hackers carried out coordinated cyberattacks on defense companies in Brazil, the Czech Republic, Finland, Italy, Norway, and Poland starting in January 2023, with the aim of improving the country's military capabilities. The hackers previously attacked and breached defense companies in Germany and Israel from November 2022 to January 2023.
Microsoft said that three North Korean hacking groups, which it identifies as Ruby Sleet, Diamond Sleet , and Sapphire Sleet, “attacked the shipbuilding and shipping sector from November 2022 to January 2023.”
During a period of heightened tensions between the two countries due to ballistic and nuclear missile tests, Kim Yong Un inspected the Amnok, the newest warship of his navy, which is being equipped with missile armament.
South Korea's National Intelligence Service did not reveal the names of the shipyard targets, but said the hackers, with state support, were sending phishing emails to internal employees of the target shipyards, with the aim of installing malicious code on their systems.
See also: North Korean hackers breached a major hospital in Seoul
According to the NIS, the hackers specifically focused on personal computers operated by IT maintenance companies in order to penetrate their networks.
Protection measures
One of the most important measures is to strengthen cybersecurity. This includes installing up-to-date and reliable antivirus and anti-hacker programs. Also, training personnel in cybersecurity is crucial to counter attacks. Finally, cooperation with experts and security companies may be necessary to protect shipyards from attacks by North Korean hackers. Experts can provide technical support, analyze attacks and suggest improvements to security measures. Security companies can also provide specialized security services and offer solutions to counter attacks.
Source: bankinfosecurity
