Advancing UK Aerospace, Defence, Security & Space Solutions Worldwide
  • Home
  • /
  • Security
  • /
  • NCSC and partners warn of DPRK-sponsored cyber ops

Security

NCSC and partners warn of DPRK-sponsored cyber ops

The National Cyber Security Centre (NCSC) – a part of GCHQ – issued a new advisory yesterday alongside partners in the US and the Republic of Korea, which reveals how a Democratic People’s Republic of Korea (DPRK) sponsored cyber threat group known as Andariel, has been compromising organisations around the world to steal sensitive and classified technical information and intellectual property data.

Image copyright Shutterstock

The NCSC assesses that Andariel is a part of DPRK’s Reconnaissance General Bureau (RGB) 3rd Bureau and that the group’s malicious cyber activities pose an ongoing threat to critical infrastructure organisations globally.  

The cyber actors have primarily targeted defence, aerospace, nuclear and engineering entities and organisations in the medical and energy sectors to a lesser extent, in order to obtain information such as contract specification, design drawings and project details.

Advertisement
ODU RT

As part of its operations, Andariel has also launched ransomware attacks against US healthcare organisations in order to extort payments and fund further espionage activity.

This advisory shares technical details and mitigation advice to help defend against the actors who have been seen exploiting known vulnerabilities to access victims’ systems before deploying malware and other tools to maintain persistence, evade detection and exfiltrate data.  

Paul Chichester, NCSC Director of Operations, said: “The global cyber espionage operation that we have exposed today shows the lengths that DPRK state-sponsored actors are willing to go to pursue their military and nuclear programmes.

“It should remind critical infrastructure operators of the importance of protecting the sensitive information and intellectual property they hold on their systems to prevent theft and misuse.  

“The NCSC, alongside our US and Korean partners, strongly encourage network defenders to follow the guidance set out in this advisory to ensure they have strong protections in place to prevent this malicious activity.”

Advertisement
ODU RT

The advisory outlines how Andariel has evolved its operations from conducting destructive attacks targeting US and South Korea organisations to conducting specialised cyber espionage and ransomware attacks.

It warns that in some cases the actors have even been observed launching ransomware attacks and espionage operations on the same day and leveraging both activities against the same victim.

The advisory has been co-sealed by the NCSC, the US Federal Bureau of Investigation (FBI), the US Cyber National Mission Force (CNMF), the US Cybersecurity and Infrastructure Security Agency (CISA), the US Department of Defense Cyber Crime Center (DC3), the US National Security Agency (NSA), the Republic of Korea’s National Intelligence Service (NIS) and the Republic of Korea’s National Police Agency (NPA).

It can be read on the FBI website: www.ic3.gov/Media/News/2024/240725.pdf
 

Advertisement
FIA2026 animated banner
MGI Engineering expands into Italy with Vigilar Group

Aerospace Defence Security

MGI Engineering expands into Italy with Vigilar Group

5 June 2026

Oxfordshire based MGI Engineering has entered into a strategic partnership with Vigilar Group, marking MGI’s expansion into Italy and a significant new phase of growth across Europe.

Smiths Detection’s HI-SCAN 10080 XCT achieves TSA ACSTL Qualified status

Aerospace Security

Smiths Detection’s HI-SCAN 10080 XCT achieves TSA ACSTL Qualified status

5 June 2026

Smiths Detection's Explosives Detection System (EDS) HI-SCAN 10080 XCT advanced X-ray computed tomography system for hold baggage and air cargo has progressed from the 'Approved' section to the 'Qualified' section of the US Transportation Security Administration’s (TSA) Air Cargo Screening Technology List (ACSTL).

UTAC Special Vehicles produces 1,000th armoured vehicle

Defence Security

UTAC Special Vehicles produces 1,000th armoured vehicle

4 June 2026

UTAC Special Vehicles has reached the milestone of producing its 1,000th armoured vehicle at the division’s headquarters at Millbrook, Bedfordshire, UK.

NATS, DroneCloud and Network Rail complete CNI drone trial

Aerospace Security

NATS, DroneCloud and Network Rail complete CNI drone trial

3 June 2026

NATS, DroneCloud and Network Rail have completed a major project exploring how drones could be safely used at scale around Critical National Infrastructure (CNI), including for rail inspections and incident response.

Advertisement
ODU RT
DSEI Germany adds fourth exhibition hall

Defence Security Space Events

DSEI Germany adds fourth exhibition hall

3 June 2026

The organisers of DSEI Germany have announced that, due to unprecedented industry demand, they will be opening a fourth exhibition hall ahead of its debut in March 2027.

Getac launches rugged ZX80W and ZX80W-EX tablets

Aerospace Defence Security

Getac launches rugged ZX80W and ZX80W-EX tablets

3 June 2026

Getac today announced the expansion of its ZX80 range of eight inch fully rugged tablets with the launch of the new ZX80W and ZX80W-EX, which are two lightweight, highly mobile Windows 11 devices built on ARM architecture.

Advertisement
ODU RT
Advertisement
General Atomics LB