North Korea's Coercive Diplomacy through the Expansion of Cyber and Space Capabilities: Risk Analysis and Response Measures
Executive Summary
North Korea is concurrently expanding its cyber and space capabilities as a subordinate means of enhancing its nuclear force. The structural motivation behind this is to offset its disadvantages in conventional military power and economic strength through asymmetric leverage. The joint alert regarding IT worker schemes from 11 countries and the automation of attacks utilizing AI by the Kimsuky organization demonstrate both the gaps in the sanctions regime and the escalation of threats. The next 3 to 5 years are likely to be characterized by a phase of multilateral checks alongside the expansion of North Korean capabilities, necessitating a focus on delaying funding and reducing attack surfaces rather than fundamental deterrence. Businesses and governments must manage the risks of disguised employment and AI-based targeted attacks through separate systems, and a cyber defense budget distinct from missile defense funding is required.
I. Issue Situation Analysis
Coercive Diplomacy through the Expansion of North Korea's Cyber and Space Capabilities: Situation Analysis
1. Background and Progress of the Issue
The establishment of North Korea's cyber capabilities dates back to the early years of Kim Jong-un's rule. Jin Lee, a senior researcher at the Wilson Center, explains that Kim Jong-un has systematically trained so-called 'cyber warrior' hacker units since the beginning of his governance. The purpose of this unit is clear: to cultivate a small elite group of hackers in a country where the majority of residents are blocked from the internet, thereby circumventing the international sanctions regime on missile and weapons of mass destruction programs.
This cyber strategy cannot be viewed separately from North Korea's nuclear force enhancement trajectory. Following the declaration of a frontal breakthrough strategy centered on self-reliance and nuclear enhancement at the Workers' Party plenary meeting in December 2019, North Korea has carried it out unwaveringly. In just 2022, it conducted over 70 missile provocations, including eight intercontinental ballistic missiles, and continued the development of the Hwasong-18 solid-fuel ICBM. The issue lies in the funding for these weapon programs. In a situation where North Korea's imports and exports are severely restricted, one of the pathways through which it has secured its weapons development budget is cybercrime, including cryptocurrency theft, which is a common assessment in the international community.
The expansion of space and counter-space capabilities has recently emerged as a separate axis that aligns with this cyber strategy. An academic journal published by the Korean Association of International Studies analyzes that North Korea is simultaneously expanding its cyber and counter-space capabilities in the information age, thereby strengthening its coercive leverage. This suggests that North Korea is employing a multi-layered strategy to offset its conventional military power deficit not only through nuclear capabilities but also in the emerging security domain of asymmetry.
2. Current Situation
In July 2026, 11 countries, including South Korea, the United States, Japan, Australia, Canada, France, Germany, Italy, the Netherlands, New Zealand, and the United Kingdom, issued the first joint alert regarding North Korean IT worker schemes through a multilateral initiative monitoring the implementation of sanctions against North Korea. This alert specified that North Korean IT personnel are disguising their identities to secure overseas remote work positions, thereby funding nuclear and missile programs, and that this structure is still operating extensively. The scale of participation by 11 countries and the very nature of it being 'the first of its kind' reflect the local practical judgment that existing individual country sanctions enforcement has been insufficient to block this scheme.
The sophistication of cyber attack methods is also progressing. The South Korean security firm, Jinus, reported that the Kimsuky organization, which is linked to North Korea and has been sanctioned by the U.S. Treasury, has been detected attempting to automate the attack process by establishing its own local language model and generative AI environment. Notably, the tools are designed to enhance the efficiency of attack operators without transmitting confidential information externally during document processing.
In the military and security domain, the deepening cooperation between North Korea and Russia has emerged as a new variable. The Japanese Ministry of Defense assessed in its 2026 white paper that while there is no evidence that Russian support has directly strengthened North Korean forces, the rapid expansion of cooperation between the two countries could enhance North Korean military capabilities in the medium to long term. The Ministry of Defense characterized North Korea's military threat as "more serious and imminent than ever" for Japan's national security.
Regional tensions are also expressed through North Korea's backlash against military buildup movements by both South Korea and Japan. Kim Yo-jong, Deputy Director of the Workers' Party, criticized Japan's first test launch of the Tomahawk cruise missile and participation in the Balikatan exercise, claiming that Japan is transforming into a 'war state.' North Korea has also warned that South Korea's expansion of the Cheongung-II missile defense system and plans to introduce nuclear submarines could trigger an arms race. U.S. experts have assessed that within this symmetrical framework, U.S. military bases in the Pacific region, including South Korea and Japan, are "highly vulnerable" to missile and drone threats from North Korea and China.
3. Key Actors and Positions
North Korean Leadershipis operating cyber and space capabilities as tools of coercive diplomacy combined with nuclear power. Through the 9th Congress of the Workers' Party, North Korea has solidified its status as a nuclear-armed state as an irreversible national reality and has redefined South Korea not as an internal ethnic counterpart but as an adversarial state-to-state relationship. This indicates that the expansion of capabilities in the cyber and space domains is not merely a technical issue but part of a long-term strategy intertwined with North Korea's perception of the international situation, which involves the weakening of the U.S.-centered international order and the emergence of multipolarity.
The trilateral cooperation of South Korea, the U.S., and Japan, along with Western partner countries, is raising its response level by moving towards a multilateral monitoring system for the enforcement of sanctions against North Korea. The issuance of the joint alert by 11 countries can be seen as a practical response recognizing the limitations of individual country sanctions enforcement. Japan has raised its alert level by specifying North Korea-Russia military cooperation as a separate threat factor in its defense white paper.is raising its response level by multilateralizing the monitoring system for North Korean sanctions. The joint alert issued by 11 countries [1] can be seen as a practical response recognizing the limitations of sanctions enforcement at the individual country level. Japan, through its Defense White Paper, has raised its alert level by explicitly identifying North Korea-Russia military cooperation as a separate threat factor [5].
Russiais an actor expanding military cooperation with North Korea, and while there is currently insufficient evidence that this has led to direct strengthening of North Korean military power, it raises concerns about medium- to long-term repercussions. There are also indications that the authoritarian axis among China, Russia, and North Korea is casting a shadow over security in the Indo-Pacific region, intertwined with the war situations in Ukraine and Iran.
South Korean Security Industry and Governmentare at the forefront of practical responses to North Korean cyber threats. Private security firms like Jinus are directly capturing and publicizing the AI utilization by organizations such as Kimsuky, thus playing a role in the production of threat intelligence. Researcher Jin Lee suggests that given South Korea's rich experience in responding to North Korean cyber attacks and its position at the forefront of cryptocurrency technology, it should simultaneously strengthen cyber security capabilities at the level of the South Korea-U.S. alliance and establish regulatory policies for cryptocurrencies.
4. Core Issues
The first issue is the sustainability of cyber capabilities as a means of circumventing sanctions. The IT worker scheme has already become widely known to the extent that it is the subject of a joint alert from 11 countries. Nevertheless, the reason this scheme continues to operate is that it exploits the global labor market structure characterized by the spread of remote work. To enhance the effectiveness of enforcement, individual companies must also strengthen their identity verification systems.
The second issue is that AI technology is lowering the entry barriers for cyber attacks. The utilization of local language models by Kimsuky suggests that North Korean hacker organizations may transition from a small elite to an automated mass attack system. This signifies a change in threat patterns that existing signature-based detection systems may struggle to address.
The third issue is the possibility that North Korea-Russia cooperation could extend into the cyber and space domains. If the 'medium- to long-term power enhancement potential' pointed out in the Japanese defense white paper materializes through technologies such as satellite launch vehicles or support for cyber infrastructure, the very effectiveness of the existing sanctions regime against North Korea could be fundamentally shaken.
The fourth issue is the interaction between the intensification of arms competition in the Korean Peninsula and emerging security threats. North Korea has repeatedly responded to South Korea's expansion of missile defense systems and plans for nuclear submarines with coercive rhetoric. With the addition of asymmetric leverage in the form of cyber and space capabilities, a complex deterrence structure is forming where conventional, nuclear, and emerging security threats overlap.
II. In-Depth Issue Analysis
Coercive Diplomacy through the Expansion of North Korea's Cyber and Space Capabilities: In-Depth Analysis
1. Fundamental Cause Analysis
The expansion of North Korea's cyber and space capabilities does not stem from a single motivation. The starting point is the structural condition of absolute disadvantage in conventional military power and economic strength. North Korea lacks funding channels through regular trade or foreign investment in a closed economic structure where exports and imports are extremely restricted. In this context, Kim Jong-un chose to cultivate a small elite of hackers at the national level from the early years of his rule. The paradox of being able to nurture elite cyber forces in a society where the internet is blocked is that this personnel was isolated and trained not for internal information dissemination but for external infiltration and fund theft.
The second fundamental cause lies in the characteristics of the sanctions regime against North Korea. UN Security Council sanctions have been effective in blocking arms exports and financial transactions, but there have been no institutional means to control identity concealment or virtual asset theft in cyberspace from the outset. Senior researcher Jin Lee at the Wilson Center points out that North Korea is exploiting these gaps in sanctions to circumvent international sanctions through cryptocurrency theft. The background for the issuance of the joint alert regarding North Korean IT worker schemes by 11 countries is also rooted in this issue. The accumulation of practical limitations indicates that individual country sanctions enforcement alone has been insufficient to filter out remote workers disguising their identities.
The third reason is the utility of coercive diplomacy. EAI commentary summarizes North Korea's nuclear strategy's theory of victory in three stages: "North Korea exaggerates the level of its nuclear capability and its actual willingness to use it vividly and realistically, thereby psychologically and cognitively influencing the decision-making of the opposing leadership, leading them to either act cautiously towards North Korea, behave as North Korea desires, or accept the conditions North Korea demands." Cyber and counter-space capabilities function as a subsystem of this nuclear strategy. In that they serve as an asymmetric lever that burdens the policy decisions of the opposing country without actual full-scale war, they share the same logical structure as nuclear capabilities.
2. Structural Context
Political Structure
The 9th Congress of the Workers' Party in 2026 reaffirmed the political coordinates of this issue. According to EAI commentary, North Korea used this congress to solidify its status as a nuclear-armed state as an irreversible national reality and redefined South Korea not as an internal ethnic counterpart but as the most hostile state in a state-to-state relationship. Furthermore, it clearly stated its intention to strengthen the line of self-reliance, independence, and self-defense under the recognition that a weakened U.S.-centered international order and a multipolar world are emerging. The expansion of cyber and space capabilities is an extension of this self-reliance line, aligned with the strategic direction of building asymmetric deterrence independently without external support.
Kim Yo-jong's remarks regarding Japan also illustrate this political logic. By characterizing Japan's test launch of the Tomahawk cruise missile and participation in the Balikatan exercise as a transition to a 'war state,' she condemned these military actions as evidence of Japan's moves to possess preemptive strike capabilities. This shows that North Korea maintains a political rhetoric that immediately utilizes the military movements of neighboring countries as justification for its own capability enhancement.
Economic Structure
The closed nature of North Korea's economy makes cybercrime not just a secondary income but a core funding source for regime maintenance. With normal foreign trade channels blocked, the disguised employment of IT personnel for overseas remote work and cryptocurrency theft have become relatively low-risk and high-yield funding methods. As pointed out in the joint alert by 11 countries, this scheme is already close to an institutionalized national industrial structure. This means that it is not merely the deviant activities of individual hackers, but rather a system where the state selects, trains, and deploys personnel and absorbs profits.
Security Structure
In terms of security structure, the deepening cooperation between North Korea and Russia is acting as a new variable. The Japanese Ministry of Defense assessed in its 2026 white paper that while there is no evidence that Russian support has directly strengthened North Korean forces, the pace of cooperation between the two countries is expanding rapidly, raising warnings that North Korean military power could be enhanced in the medium to long term. The white paper characterized North Korea's military threat as "more serious and imminent than ever" for Japan's national security. More broadly, there are indications that the authoritarian axis connecting China, Russia, and North Korea is expanding in conjunction with the war situations in Ukraine and Iran. The sale of missile systems by China to Iran is cited as an example of this trend.
The vulnerability of U.S. forward bases in the Indo-Pacific is also a structural background. An expert cited by Yonhap News assessed that U.S. military bases in the Pacific region, including South Korea and Japan, are "highly vulnerable" to missile and drone attacks from North Korea and China. This assessment highlights the potential risk that if North Korea secures space and counter-space capabilities, it could also gain the ability to disrupt U.S. surveillance, reconnaissance, and communication assets.
3. Historical Precedents and Comparative Cases
North Korea's current trajectory partially overlaps with the concept of asymmetric strategy from the Soviet Union during the Cold War. A recent workshop hosted by the Stockholm International Peace Research Institute (SIPRI) addressed the implications of the space-nuclear nexus for European security and analyzed how uncertainties in the space domain can alter escalation pathways. This reflects the concern that threats to space assets could shake the very structure of nuclear deterrence. North Korea's pursuit of counter-space capabilities follows a similar logic: by instilling uncertainty in the adversary's space-based command and control systems without direct military conflict, it can achieve strategic advantage.
Recent policy demands from the U.S. Space Command also serve as comparative material. The outgoing commander of U.S. Space Command emphasized the urgency of developing 'Counter P-LEO' capabilities in light of China's rapid advancement of space weapon systems. Although this policy discussion primarily targets China rather than North Korea, it demonstrates that asymmetric deterrence competition in the space domain has already begun in earnest between the great powers. North Korea's pursuit of counter-space capabilities can be viewed as a derivative of this great power competition in space, partially referencing the doctrines and technologies established by great powers and adapting them into an asymmetric version suitable for itself.
In the cyber domain, the Kimsuky organization's use of AI is creating a new precedent. Jinus has confirmed that Kimsuky is attempting to automate attacks by building a local language model and integrating generative AI into the attack process. This represents a new type of sanctions evasion method where a state-backed hacking organization attempts to automate attacks even in situations where access to commercial AI services is restricted. The transition from labor-intensive hacking to AI-assisted hacking could serve as a reference model for other sanctioned countries in the future.
4. Key Variables in Issue Development
The first variable is the effectiveness of the joint alert system among the 11 countries. Whether this system leads to actual strengthening of identity verification for IT workers and improvements in corporate hiring practices will determine North Korea's funding capabilities in the future. The second variable is the pace of deepening North Korea-Russia military cooperation. As noted by the Japanese Ministry of Defense, while there is currently no evidence of direct strengthening effects, if the scope of cooperation expands to include space and missile technology transfer, the assessment may change. The third variable is the speed of South Korea's defensive system response. Whether measures such as the expansion of the Cheongung-II missile defense system can provide a practical deterrent effect against North Korea's asymmetric threats is crucial. The fourth variable is the speed of AI technology diffusion. If generative AI becomes a standard tool for hacking organizations, the frequency and sophistication of attacks may outpace the detection capabilities of existing response systems.
3 credits are required from here
The body beyond the scenario analysis is available with credits.
Sign in to continue reading*This text is an AI translation of an original written in Korean. Some translations or nuances may be inaccurate.
This report is an in-depth analysis planned by an EAI researcher, grounded in sophisticated AI-assisted research, and finalized by the EAI researcher.