The U.S. government has announced a $10 million reward for information leading to the capture of a North Korean hacker.
This individual is accused of launching ransomware attacks on U.S. healthcare institutions and stealing aircraft technology and other sensitive information from U.S. defense industry. Officials warn that the profit from these cybercrimes are being used to fund North Koreaโs โunlawful weapons of mass destruction and ballistic missile programs.โ
The Federal Bureau of Investigation (FBI) announced on July 25 that it has placed North Korean hacker Rim Jong-hyok on its most-wanted list for engaging in โcertain malicious cyber activities against U.S. critical infrastructure in violation of the Computer Fraud and Abuse Act.โ

The FBI said Rim, a member of the Andarier Unit of the North Korean Governmentโs Reconnaissance General Bureau (RGB), allegedly โconspired to use Maui ransomware software to conduct computer intrusion against U.S. hospitals and healthcare companies, extort ransoms, launder the proceeds, and purchase additional internet servers to conduct cyber espionage hacks against government and technology victims in the U.S., South Korea, and China.โ
The U.S. Department of State provided additional details about Rim in a separate press release.
โThe ransomware attacks encrypted victimsโ computers and servers used for medical testing or electronic medical records and disrupted healthcare services,โ the department said. โIn one computer intrusion operation that began in November 2022, the malicious cyber actors hacked a U.S.-based defense contractor from which they extracted more than 30 gigabytes of data, including unclassified technical information regarding material used in military aircraft and satellites, much of which was from 2010 or earlier.โ
According to the department, U.S. law enforcement investigators have documented that Andariel actors victimized five healthcare providers, four U.S.-based defense contractors, two U.S. Air Force bases, and the National Aeronautics and Space Administrationโs Office of Inspector General.
โThis action underscores the United Statesโ continued efforts to address the DPRKโs malicious cyber activity against critical infrastructure as well as prevent and disrupt the DPRKโs ability to generate illicit revenue through malicious cyber activity, which it uses to fund its unlawful weapons of mass destruction and ballistic missile programs.โ
The press release added, โThe U.S. Department of Stateโs Rewards for Justice (RFJ) program, administered by the Diplomatic Security Service, is offering a reward of up to $10 million for information leading to the identification or location of the individual.โ

On the same day, intelligence agencies and law enforcement from the U.S., South Korea, and the United Kingdom, released a joint cybersecurity advisory regarding North Korean cyber activities. Participants of this joint advisory include the U.S. National Security Agency and FBI, South Korean National Intelligence Service and National Police Agency, and UKโs National Cyber Security Centre.
โThe RGB 3rd Bureau includes a DPRK (aka North Korean) state-sponsored cyber group known publicly as Andariel, Onyx Sleet (formerly PLUTONIUM), DarkSeoul, Silent Chollima, and Stonefly/Clasiopa,โ the advisory read. โThe group primarily targets defense, aerospace, nuclear, and engineering entities to obtain sensitive and classified technical information and intellectual property to advance the regimeโs military and nuclear programs and ambitions.โ
The authoring agencies believe the group and the cyber techniques remain an ongoing threat to various industry sectors worldwide, including but not limited to entities in theirย respective countries, as well as in Japan and India.
Meanwhile, the U.S. Justice Department has brought multiple criminal cases related to North Korean hacking in recent years, often alleging a profit-driven motive that differentiates the activity from that of hackers in Russia and China.
In 2021, for instance, the department charged three North Korean computer programmers in a broad range of global hacks, including a destructive attack targeting an American movie studio, and in the attempted theft and extortion of more than $1.3 billion from banks and companies.
BY YOUNGNAM KIM [kim.youngnam@koreadaily.com]



