North Korean hackers weaponise Google, KakaoTalk in first-of-its-kind cyberattack targeting South Koreans

North Korean hackers weaponise Google, KakaoTalk in first-of-its-kind cyberattack targeting South Koreans
North Korean hackers weaponise Google, KakaoTalk in first-of-its-kind cyberattack targeting South Koreans

Hello and welcome to the details of North Korean hackers weaponise Google, KakaoTalk in first-of-its-kind cyberattack targeting South Koreans and now with the details

Nevin Al Sukari - Sana'a - Cybersecurity experts say North Korean hackers used Google’s Find Hub service and KakaoTalk messenger to remotely control and wipe Android devices in South Korea. — Reuters pic

By Malay Mail

Monday, 10 Nov 2025 3:02 PM MYT

SEOUL, Nov 10 — North Korean state-sponsored hackers have hijacked Google accounts to take remote control of smartphones and tablets belonging to South Koreans, later using the KakaoTalk messenger app to spread malware to their contacts, The Korea Herald reported today.

According to South Korean cybersecurity firm Genians, the incident marks “the first confirmed case of a North Korean state-sponsored hacking group compromising Google accounts to gain remote control over smart devices.” 

The attack was attributed to North Korea’s Konni advanced persistent threat (APT) cyber espionage group, long suspected of targeting South Korean individuals and institutions.

Genians said the hackers initially infiltrated victims’ devices through spear-phishing emails impersonating South Korea’s National Tax Service. 

Once inside, the group gathered data and conducted internal reconnaissance before exploiting Google’s Find Hub service — a legitimate tool used to locate and secure lost Android devices — to execute data-wiping and tracking operations.

“This development demonstrates a realistic risk that the feature can be abused within advanced persistent threat (APT) campaigns,” the report stated.

The hackers allegedly abused Find Hub’s remote-control functions to track locations and perform factory resets on victims’ devices. 

This neutralised phones and tablets, disrupted normal recovery, and blocked KakaoTalk notifications — delaying detection of the breach.

After wiping victims’ Android devices, the hackers gained access to their KakaoTalk PC accounts, which they then used to send malicious files to contacts. 

Genians described it as “a typical social-engineering attack that leveraged trust-based communications to precisely exploit the target’s psychological and social context.”

One notable victim was a counsellor who provides psychological support to North Korean defector students. The attackers used the counsellor’s compromised KakaoTalk account to send a malicious file disguised as a “stress-relief programme,” infecting recipients’ devices when opened.

On September 15, a similar mass malware distribution was detected through another compromised KakaoTalk account.

“This combination of device neutralisation and account-based propagation is unprecedented among previously known state-sponsored APT scenarios,” Genians said, adding that it “demonstrates the attacker’s tactical maturity and advanced evasion strategy, marking a key inflection point in the evolution of APT tactics.”

The report highlighted a growing sophistication in North Korea’s cyber-espionage operations — one that weaponises legitimate digital tools and trusted social networks in ways that may be harder to detect or contain, The Korea Herald noted.

 

These were the details of the news North Korean hackers weaponise Google, KakaoTalk in first-of-its-kind cyberattack targeting South Koreans for this day. We hope that we have succeeded by giving you the full details and information. To follow all our news, you can subscribe to the alerts system or to one of our different systems to provide you with all that is new.

It is also worth noting that the original news has been published and is available at Malay Mail and the editorial team at AlKhaleej Today has confirmed it and it has been modified, and it may have been completely transferred or quoted from it and you can read and follow this news from its main source.

PREV ‘Breathing is killing us’: Dozens detained in rare clean-air protest at New Delhi’s India Gate
NEXT On the rise in Germany, far-right AfD deepens ties to Trump administration

Author Information

I am Joshua Kelly and I focus on breaking news stories and ensuring we (“Al-KhaleejToday.NET”) offer timely reporting on some of the most recent stories released through market wires about “Services” sector. I have formerly spent over 3 years as a trader in U.S. Stock Market and is now semi-stepped down. I work on a full time basis for Al-KhaleejToday.NET specializing in quicker moving active shares with a short term view on investment opportunities and trends. Address: 838 Emily Drive Hampton, SC 29924, USA Phone: (+1) 803-887-5567 Email: [email protected]