Advancing UK Aerospace, Defence, Security & Space Solutions Worldwide
  • Home
  • /
  • Security
  • /
  • NCSC and partners warn of DPRK-sponsored cyber ops

Security

NCSC and partners warn of DPRK-sponsored cyber ops

The National Cyber Security Centre (NCSC) – a part of GCHQ – issued a new advisory yesterday alongside partners in the US and the Republic of Korea, which reveals how a Democratic People’s Republic of Korea (DPRK) sponsored cyber threat group known as Andariel, has been compromising organisations around the world to steal sensitive and classified technical information and intellectual property data.

Image copyright Shutterstock

The NCSC assesses that Andariel is a part of DPRK’s Reconnaissance General Bureau (RGB) 3rd Bureau and that the group’s malicious cyber activities pose an ongoing threat to critical infrastructure organisations globally.  

The cyber actors have primarily targeted defence, aerospace, nuclear and engineering entities and organisations in the medical and energy sectors to a lesser extent, in order to obtain information such as contract specification, design drawings and project details.

Advertisement
ODU RT

As part of its operations, Andariel has also launched ransomware attacks against US healthcare organisations in order to extort payments and fund further espionage activity.

This advisory shares technical details and mitigation advice to help defend against the actors who have been seen exploiting known vulnerabilities to access victims’ systems before deploying malware and other tools to maintain persistence, evade detection and exfiltrate data.  

Paul Chichester, NCSC Director of Operations, said: “The global cyber espionage operation that we have exposed today shows the lengths that DPRK state-sponsored actors are willing to go to pursue their military and nuclear programmes.

“It should remind critical infrastructure operators of the importance of protecting the sensitive information and intellectual property they hold on their systems to prevent theft and misuse.  

“The NCSC, alongside our US and Korean partners, strongly encourage network defenders to follow the guidance set out in this advisory to ensure they have strong protections in place to prevent this malicious activity.”

Advertisement
Security & Policing Rectangle

The advisory outlines how Andariel has evolved its operations from conducting destructive attacks targeting US and South Korea organisations to conducting specialised cyber espionage and ransomware attacks.

It warns that in some cases the actors have even been observed launching ransomware attacks and espionage operations on the same day and leveraging both activities against the same victim.

The advisory has been co-sealed by the NCSC, the US Federal Bureau of Investigation (FBI), the US Cyber National Mission Force (CNMF), the US Cybersecurity and Infrastructure Security Agency (CISA), the US Department of Defense Cyber Crime Center (DC3), the US National Security Agency (NSA), the Republic of Korea’s National Intelligence Service (NIS) and the Republic of Korea’s National Police Agency (NPA).

It can be read on the FBI website: www.ic3.gov/Media/News/2024/240725.pdf
 

Advertisement
ECS leaderboard banner
ALL.SPACE and Viasat advance Ka-band connectivity

Defence Security Space

ALL.SPACE and Viasat advance Ka-band connectivity

10 March 2026

ALL.SPACE today announced a strategic collaboration with Viasat and the successful certification of the ALL.SPACE Hydra terminal to operate on the Viasat Global Xpress (GX) network, which provides integrated military Ka-band spectrum access for government and defence missions.

IFS completes acquisition of Softeon

Aerospace Defence Security Space

IFS completes acquisition of Softeon

10 March 2026

IFS today announced the completion of its acquisition of Softeon, providing enterprises across manufacturing, logistics and retail, with access to a new category of supply chain technology.

NPAS shares innovation insights at CAA Future of Flight Day

Aerospace Security Events

NPAS shares innovation insights at CAA Future of Flight Day

9 March 2026

At the UK Civil Aviation Authority’s Future of Flight Day, David Walters, Head of Futures and Innovation, National Police Air Service (NPAS), shared the latest progress in NPAS’s Beyond Visual Line of Sight (BVLOS) development programme and showcased a recent multiagency search and rescue demonstration.

UK space tech startups target debris, wildfires and climate risk

Security Space

UK space tech startups target debris, wildfires and climate risk

9 March 2026

Six UK space tech startups have joined the European Space Agency Business Incubation Centre UK (ESA BIC UK) to develop technologies that deliver practical benefits in space and on Earth, applying space technology to some of today’s most urgent challenges, from clearing space junk to detecting wildfires in seconds.

Advertisement
PTC rectangle
Blighter wins ground surveillance radars contract

Defence Security

Blighter wins ground surveillance radars contract

9 March 2026

Blighter has won a contract to supply its ground surveillance radars and BlighterNexus AI-assisted software to an undisclosed Eastern European Army to protect the country’s national borders.

Serco continues health support for ADF readiness

Defence Security

Serco continues health support for ADF readiness

6 March 2026

Serco has been awarded a contract extension with Bupa to deliver health services across Australian Defence Force (ADF) Health Centres for a further 12 months to 30th June 2027.

Advertisement
ODU RT
Advertisement
Security & Policing 2026