China and North Korea Share More Than Shady Economic Ties: Bureau 21
Hey Library Readers!
It's been a bit since I put anything up on here, much longer since it was Library material. Life has been busy, as I have an 8-5 job and a couple of development projects.
Today though, I'll make it worth the wait.
Today we sit down and have a chat about North Korea's second most dangerous weapon, second only to their well-tested missile program.
Bureau 121 is a North Korean threat actor with significant ties to the People's Republic of China. I'm not talking about overlapping domains and IPs, and I'm not talking about overlapping targets.
Bureau 121 operates inside of the People's Republic of China.
They are an incredibly advanced threat actor thought to have ties to the People's Liberation Army (PLA) and other portions of the Communist Party. Their manpower is thought to be over 5,000 North Korean cyber soldiers, all with training from top North Korean and Chinese universities.
Inside of the Chilbosan Hotel in Shenyang, China, the North Korean digital warriors enjoy an environment far more lavish than their starving countrymen. Besides a beauty parlor, sauna, fitness center, and karaoke bar, the hotel enjoys a fiber internet connection, infrastructure that far eclipses the home country's extremely limited pseudo-intranet that it has only been able to access since 2010.
Bureau 121 has a pretty extensive resume.
Remember the Sony hack? That is widely attributed to North Korea, for obvious reasons, and more specifically to Bureau 121. They were also behind wiper attacks in Seoul government, DDoS attacks against South Korean media companies, and phishing attacks against other companies in South Korea. There are several personas thought to be attached to Bureau 121, but because of their secretive nature, there is not much confirmed information regarding the threat.
Bottom Line: Bureau 121 is dangerous.
They're at the top of my list of (kinda) Chinese threat actors, and there will be updates to this post in the future. They have a dangerous potential to disrupt, destroy, and infiltrate high-profile networks, and pose a serious threat to US interests as North Korean-US relations deteriorate further.
Thank you for your reading. If you enjoyed this content, upvote the post, give me a follow, or donate via Bitcoin at my address below.
1Gq2KagLsJPMaVCB5Anfb8d8J22tiDEZFS