A hacking group believed to be linked to North Korea has reportedly carried out a highly destructive cyberattack capable of remotely controlling Android smartphones and PCs, deleting key data, and spreading malware through hijacked messenger accounts — a method never before seen in such scale and precision.
In a threat analysis report released on November 10, cybersecurity firm Genians Security Center stated that the hackers, attributed to North Korea, have “moved beyond simple data theft to causing direct, real-world harm to individuals.”
According to the report, on September 5, the smartphone of a South Korean psychotherapist was remotely wiped by the hackers. Using the victim’s stolen KakaoTalk account, the attackers sent out malware disguised as a “stress relief program” to numerous contacts. Ten days later, on September 15, a similar incident targeted a North Korean human rights activist whose phone was also reset remotely, leading to malware being distributed to 36 acquaintances.
While the social engineering tactics used in these incidents match North Korean-style attacks, this time the hackers employed an unprecedented level of coordination and control. After infiltrating victims’ smartphones and PCs, they reportedly remained dormant for weeks while stealing credentials for Google and other major Korean online services.
Once the hackers confirmed that victims were away from their devices — using Google’s Find My Device (Find Hub) feature — they triggered a remote factory reset of the phones and simultaneously spread malicious files through the compromised PCs.
During the attacks, victims’ devices were rendered completely unresponsive, cutting off calls and messages, which delayed countermeasures and worsened secondary damage. Some lost all personal data, including photos, documents, and contacts.
The report also suggested that webcam and microphone control features found inside the malware could have allowed the hackers to monitor victims in real time, raising concerns physical surveillance.
Genians described the case as “an unprecedented, multi-layered operation combining Android device wipes, account hijacking, and remote attack propagation,” adding that “North Korean cyber operations are evolving from mere data theft to real-world disruption within personal spaces.”
Security experts urged users to adopt basic but essential safety measures — including enabling two-factor authentication, disabling password auto-save in browsers, and powering off PCs when not in use. They also called on device manufacturers to strengthen built-in multi-authentication systems to prevent similar attacks.
Meanwhile, the Gyeonggi Provincial Police Agency’s Cyber Security Investigation Division is currently investigating the case involving the North Korean rights activist. Investigators confirmed that the malware’s structure closely resembles that used in North Korean hacking operations.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
