← Back · ← Home · ← Back to list

North Korea's Expansion of Cyber and Counter-Space Capabilities and Its Coercive Leverage Strategy: An Assessment and Policy Recommendations

Category
Current Watch
Published
August 24, 2026
Illustration

Executive Summary

To offset its inferiority in conventional military and economic power, North Korea is simultaneously expanding its cyber and counter-space capabilities as a subordinate component of its policy to advance its nuclear forces. The use of IT workers with false identities and the theft of cryptocurrency have moved beyond sanctions evasion to become a permanent source of revenue integrated into the state's finances. The automation of attacks by hacking groups like Kimsuky using AI demonstrates a qualitative advancement of the threat. Military cooperation with Russia provides Kim Jong Un with a different negotiating position than he had in 2019, making it difficult to reverse this trend with pressure on North Korea alone. The most likely scenario for the next three to five years is a phase in which multilateral containment efforts and North Korea's capability expansion proceed in parallel. It is more realistic to set policy goals aimed at delaying North Korea's fundraising and reducing the attack surface, rather than achieving fundamental deterrence. To this end, it is necessary to incrementally pursue establishing a separate budget for cyber defense, managing the risks from disguised IT workers and AI-powered targeted attacks separately, and institutionalizing the joint advisory system on the IT worker scheme as a permanent consultative body.

Diagram

I. Situational Analysis

North Korea's Pursuit of Coercive Leverage Through the Expansion of Cyber and Counter-Space Capabilities: A Situational Analysis

1. Background and Developments

North Korea's development of its cyber capabilities dates back to the early days of Kim Jong Un's rule. Jean Lee, a senior fellow at the Wilson Center, explains that Kim has systematically cultivated so-called "cyber-warrior" hacker units since the beginning of his reign[5]. The purpose of these units is clear. In a country where the vast majority of the population is cut off from the internet, a small elite group of hackers is trained. Their mission is to circumvent the international sanctions regime targeting its missile and weapons of mass destruction (WMD) programs[5][2].

This cyber strategy cannot be seen in isolation from North Korea's policy of advancing its nuclear forces. At a plenary meeting of the Workers' Party in December 2019, North Korea declared a "frontal breakthrough" campaign centered on self-reliance and nuclear advancement[2][6]. It has pursued this path without wavering ever since. In 2022 alone, it conducted over 70 missile provocations, including eight intercontinental ballistic missiles (ICBMs)[2][8]. The development of the Hwasong-18 solid-fuel ICBM also proceeded during this period[2].

Cyber and space capabilities are positioned as subordinate instruments in this "frontal breakthrough" campaign. An EAI analysis notes that "North Korea is simultaneously expanding its cyber and space capabilities as a subordinate component of its policy to advance its nuclear forces"[2]. This is driven by a structural motive: a calculation aimed at "offsetting its inferiority in conventional military and economic power with asymmetric leverage"[2]. In essence, physical means of coercion like nuclear weapons and missiles are linked with non-physical means of coercion like cyber and counter-space capabilities along a single strategic axis.

2. Current Situation

As of August 2025, the security situation on the Korean Peninsula has re-entered a phase of tension. South Korea and the United States conducted the Ulchi Freedom Shield (UFS) combined military exercises from August 17 to 27[11][7]. This year's exercises are notable for including scenarios that reflect lessons learned from the war in Ukraine[11]. At a press conference for foreign correspondents in Seoul, the deputy commander of the United Nations Command (UNC) warned that the experience gained by North Korean forces on the battlefields of Russia and Ukraine is changing the security calculus on the Korean Peninsula itself[1].

North Korea's reaction is harsher than in previous years. In a commentary, the Korean Central News Agency (KCNA) described the exercises as a provocation conducted in "all domains of actual wartime operations, including land, sea, air, space, cyber, and psychological information"[14]. A statement issued in the name of a Foreign Ministry spokesperson warned that Pyongyang would respond with a "new level of deterrence"[7][15]. North Korean media are also employing the frame that U.S.-Japan-ROK military cooperation is transforming into a "nuclear alliance"[15]. Just before the exercises, 12 short-range missiles were launched from Pyongyang[18].

Closer ties with Russia are emerging as a new variable in this situation. Chile's *El Mercurio* analyzed that Moscow's support has provided Pyongyang with funds, weapons, and military experience[17]. This is assessed to have put Kim Jong Un in a more advantageous negotiating position than in 2019 when responding to the Trump administration's attempts to resume dialogue[17]. In South Korea, the Ministry of National Defense, in a briefing to the National Assembly's National Defense Committee, projected that North Korea would complete construction work to "harden the border" along the Military Demarcation Line around 2028[4]. New weapon systems, including new 240mm and 600mm multiple rocket launchers, self-propelled artillery, and tactical missiles, are also being deployed in parallel along the border region[4]. This creates a dynamic where physical military buildup and the diversification of threats in non-traditional security domains are proceeding simultaneously.

In the cyber domain, methods for securing funds are becoming more sophisticated. An EAI analysis cites "the joint advisory on the IT worker scheme issued by 11 countries and evidence of the Kimsuky group's use of AI to automate attacks," assessing that this simultaneously demonstrates "gaps in the sanctions regime and the growing sophistication of the threat"[2]. Senior Fellow Jean Lee also points out that despite being a country with "very limited imports and exports," North Korea has sustained its weapons programs by stealing virtual currency through cybercrime[5].

3. Key Actors and Positions

North Koreadefines its cyber and counter-space capabilities as asymmetric leverage to compensate for its inferiority in conventional forces. For the Kim Jong Un regime, cyber-enabled fundraising is a means of survival, replacing foreign currency acquisition channels blocked by sanctions[5][2]. A KCNA commentary frames the ROK-U.S. combined exercises as a "military threat from hostile forces" and justifies its response as the "exercise of the right to self-defense"[14]. This can be read as a domestic and international propaganda strategy aimed at subsuming its provocations in the cyber and space domains within a defensive narrative related to conventional forces.

The ROK-U.S. Allianceincorporated lessons from the war in Ukraine into the recent UFS exercises. This signifies a redefinition of the North Korean threat as a hybrid one, combining conventional and non-traditional elements[11]. The warning from the UNC deputy commander reveals the U.S. perception that the accumulation of combat experience by the North Korean military is changing the security calculus for managing the armistice system itself[1].

Russiahas emerged as a patron providing North Korea with funds, weapons, and military experience[17]. This relationship erodes the effectiveness of the sanctions regime against North Korea while also strengthening the leverage North Korea can use in future negotiations with the United States[17].

The South Korean Governmentthrough a Ministry of National Defense briefing, reported physical threat factors to the National Assembly, such as the buildup of weapon systems in the border region and the border hardening construction[4]. However, mentions of a separate response system for the cyber and counter-space domains have been relatively limited.South Korean Research Institutions, including EAI,have raised the need to manage the North Korean cyber threat by distinguishing between the "risk from disguised IT workers" and the "risk from AI-powered targeted attacks." They are calling for the creation of a separate cyber defense budget, distinct from the missile defense budget[2].

4. Key Issues

The first issue is the existence of gaps in the sanctions regime against North Korea. The use of disguised IT workers and evidence of AI-automated attacks demonstrate that the existing sanctions network is failing to keep pace with new methods[2]. The second issue is the Russia factor. The possibility is raised that closer North Korea-Russia ties could serve as a channel for transferring the technology and resources needed to advance its cyber and space capabilities[17]. The third issue is the priority of policy responses. The EAI analysis suggests that the goal of the response should be focused on "delaying fundraising and reducing the attack surface" rather than on fundamental deterrence[2]. This reflects a perception that cyber and counter-space threats, unlike nuclear and missile threats, should be approached as manageable risks rather than threats to be completely deterred.

II. In-Depth Analysis

North Korea's Pursuit of Coercive Leverage Through the Expansion of Cyber and Counter-Space Capabilities: An In-Depth Analysis

1. Analysis of Root Causes

North Korea's expansion of its cyber and counter-space capabilities stems from the fundamental constraint of its inferiority in conventional military power. An EAI analysis defines this as a "structural motive to offset its inferiority in conventional military and economic power with asymmetric leverage"[2]. It has no way to gain an upper hand in a conventional military confrontation with South Korea and the United States. North Korea had to find alternative means to bridge this gap.

Its cyber capabilities initially began for the purpose of fundraising. According to Jean Lee, a senior fellow at the Wilson Center, Kim Jong Un has cultivated hacker units since the early days of his rule[5]. The goal was to circumvent the "strong U.S. and UN sanctions on its missile and weapons of mass destruction programs"[5]. In a country where trade, both imports and exports, is almost completely blocked, the theft of virtual currency became a practical channel for securing foreign currency[5]. The fact that cyber attacks originated not from purely military objectives but from the economic necessity of sanctions evasion has shaped the subsequent direction of its strategy.

With the consolidation of its nuclear weapons policy, its cyber and space capabilities were repositioned as subordinate instruments. The "frontal breakthrough" campaign declared at the December 2019 plenary meeting of the Workers' Party was centered on "self-reliance, ideological struggle, nuclear advancement, and a long-term struggle"[8]. Under this policy, the role of cyber attacks expanded to include not only fundraising but also disrupting information warfare. Its space capabilities also became linked to its missile advancement program through the development of reconnaissance satellites.

2. Structural Context

In the political structure, the Kim Jong Un regime's expansion of cyber and counter-space capabilities is intertwined with the regime's internal logic. EAI explains North Korea's nuclear "theory of victory" as a three-stage structure of "exaggerating its nuclear capabilities and willingness to use them to influence the adversary's psychological decision-making, thereby compelling the adversary to exercise caution on its own"[10]. In this coercive structure, cyber and counter-space attacks function as a low-cost, low-risk tool. While leaving room for disputes over attribution, unlike physical provocations, they can inflict damage on an adversary's social infrastructure and psychology.

In the economic structure, the prolonged nature of sanctions against North Korea provides the backdrop for its increased reliance on cyber capabilities. North Korea must maintain its state finances while normal trade and foreign investment are blocked. An EAI report mentions "the joint advisory on the IT worker scheme issued by 11 countries and evidence of the Kimsuky group's use of AI to automate attacks," diagnosing that this simultaneously demonstrates "gaps in the sanctions regime and the growing sophistication of the threat"[2]. The use of disguised IT workers and the theft of cryptocurrency have now solidified into a permanent source of revenue integrated into the state budget, rather than being one-off incidents.

In the security structure, North Korea's learning about the informationized battlefield is accelerating through the war in Ukraine. The deputy commander of the United Nations Command warned at a press conference in Seoul that the battlefield experience in Russia and Ukraine is "changing the security calculus on the Korean Peninsula itself"[1]. The inclusion of scenarios reflecting lessons from the war in Ukraine in this year's Ulchi Freedom Shield exercises is a product of this recognition[11]. The observation that North Korean forces have directly acquired know-how in drone, electronic, and information warfare through their deployment with Russia was reflected in the exercise design.

Closer ties with Russia add a resource variable to this structure. Chile's *El Mercurio* analyzed that Moscow's support has provided Pyongyang with "funds, weapons, and military experience"[17]. This support is cited as the reason Kim Jong Un is now in a more advantageous position than in 2019 for future negotiations with the United States[17]. The possibility that technology transfers or the sharing of know-how needed to expand cyber and counter-space capabilities could occur through this close relationship cannot be ruled out.

3. Historical Precedents and Comparative Cases

North Korea's cyber strategy has followed a path of gradual sophistication through incidents such as the Sony Pictures hack (2014), the attempted heist from Bangladesh's central bank (2016), and the WannaCry ransomware attack (2017). Initially, these acts were strongly characterized as political retaliation or one-off financial crimes. Subsequently, as methods shifted to attacking cryptocurrency exchanges and using disguised IT workers, it has become established as a permanent system that contributes to state finances. The "use of AI to automate attacks" noted by EAI[2] represents the latest stage in this evolution, corresponding to a phase of increasing efficiency, aimed at expanding the scale of attacks relative to the manpower invested.

In terms of counter-space capabilities, North Korea's approach partially overlaps with the anti-satellite weapon development paths of Russia and China. However, North Korea is understood to prioritize relatively low-cost, non-kinetic means such as GPS jamming and electronic warfare interference over direct-ascent anti-satellite capabilities. This can be seen as an extension of North Korea's asymmetric strategy of seeking maximum effect under resource constraints.

The use of cyber and counter-space capabilities as a tool of coercive diplomacy offers points of comparison with the Soviet Union's asymmetric strategies during the Cold War. The method of an actor with inferior conventional and nuclear forces exploiting the vulnerabilities of an adversary's society is not new. However, the unique aspect of the North Korean case lies in the fact that these asymmetric means are directly linked to the regime's finances. In that cyber attacks function as an economic substructure for regime survival, beyond being a simple tool for military disruption, it is distinct from the general pattern of state-sponsored hacking.

4. Key Variables Shaping Future Developments

The first variable is the effectiveness of multilateral sanctions coordination. The fact that 11 countries issued a joint advisory on the IT worker scheme[2] shows that the international community is raising its level of response. However, whether this coordination will lead to an actual cutoff of funding is a separate issue. It is possible that the pace at which cryptocurrency theft routes diversify will outstrip the pace of sanctions coordination.

The second variable is the persistence and depth of Russia-North Korea military cooperation. Whether this cooperation extends to the transfer of cyber and space technology will determine whether North Korea's capabilities make a qualitative leap in the next three to five years. The acquisition of combat experience on the battlefields of Ukraine is already an ongoing variable[1][11], but if this is combined with Russia's satellite and electronic warfare technology, the nature of the threat itself will change.

The third variable is a shift in the U.S. policy stance toward North Korea. The Wall Street Journal criticized the Trump administration's decision to "substantially scale back" ROK-U.S. combined military exercises, calling it a move that underestimated the North Korean threat[13]. The U.S. Department of Defense's 2026 National Security Strategy has already acknowledged that North Korea's nuclear forces are "increasingly capable of threatening the U.S. homeland"[13]. If Washington's approach shifts toward prioritizing dialogue, there is a risk that the incentive to deter North Korea's expansion of cyber and counter-space capabilities could be weakened.

The fourth variable is the international trend of outsourcing cyber warfare to the private sector. The fact that the United States is shifting its policy toward allowing authorized private companies to conduct offensive cyber operations[16] complicates the calculus of state-to-state cyber response. The effectiveness of deterrence against North Korea could change depending on how this trend is reflected in the ROK-U.S. cyber defense system.

3 credits are required from here

The body beyond the scenario analysis is available with credits.

Sign in to continue reading

*This text is an AI translation of an original written in Korean. Some translations or nuances may be inaccurate.

This report is an in-depth analysis planned by an EAI researcher, grounded in sophisticated AI-assisted research, and finalized by the EAI researcher.

← Back · ← Home · ← Back to list