On April 1, 2024, just nine days before the elections, a series of cyberattacks by North Korea begins to materialize in earnest. Initially, they target the national infrastructure systems with brief assaults before halting, then spread chaos through social media by disseminating fake news using deepfake technology. The recurrence of low-level, sporadic cyberattacks has become a pattern, leading the South Korean public to perceive them less seriously. This trend may signal the beginning of North Korea's genuine cyber offensive. North Korea's cyber warriors, aided by sympathizers within South Korea, coordinate attacks to simultaneously disrupt transportation, communication, broadcasting, and financial systems. The entire region of South Korea, including Seoul, is engulfed in darkness, resulting in traffic chaos as vehicles collide on the roads. Incheon International Airport, hacked and rendered inoperable, ceases all flights, broadcasting South Korea's chaos to the world in real time. A fabricated broadcast depicting an explosion at the presidential office in Yongsan, Seoul, exacerbates the nationwide panic. Amid this turmoil, stock prices plunge, prompting foreign investors to swiftly withdraw their investments. Disgruntled citizens launch protests across cities, urging the president to step down to take responsibility for what happened. This comprehensive national paralysis lasts for nine days, resulting in the election results on April 10 favoring candidates calling for peace with North Korea.

Kwon Ho-cheon
This is a hypothetical scenario about North Korea’s cyberattacks. Can we guarantee that such a scenario will never happen in a real world? Certainly not. Given North Korea's sophisticated cyberattack capabilities, what was described above can actually happen. South Korea has long been a primary target of North Korean cyberattacks, and there have been far more attacks than have been publicly acknowledged. Often, these attacks go unnoticed, and the lack of visible damage has led to an increasing tendency to downplay their significance.
The National Cybersecurity Strategy announced in 2019 marked a significant step in recognizing the importance of cybersecurity. However, given the ongoing threat of North Korean cyberattacks, what was written in the strategy was not effective enough. The new "National Cyber Security Strategy," which was unveiled earlier this year, promises a more proactive and offensive approach.
During the South Korea-U.S. summit held in April last year, the Strategic Cyber Security Cooperation Framework was established, and discussions were initiated to extend the scope of the South Korea-U.S. alliance to include cyberspace. Collaborating with the United States, which is the world’s best in cyberwarfare capabilities, holds significant meaning in South Korea’s cyber defense capabilities. Additionally, South Korea has decided to strengthen cyber cooperation through strategic partnerships with the United Kingdom and Japan. The construction of South Korea's international cybersecurity cooperation network conveys a strong message both domestically and internationally.
North Korea targets South Korea for several reasons. South Korea's advanced network infrastructure makes it become an easy target for North Korea. North Korea would believe South Korea's cyber offense & defense capabilities are inferior to theirs, and North Korea sees South Korea as an enemy that can be coerced into concessions.
International cooperation, is crucial, but often focuses on post-attack international legal responses rather than prevention. South Korea's best strategy is to enhance its own cyberattack and defense capabilities. Nations with superior cyber warfare capabilities, like the U.S., Russia, and China, prioritize offensive abilities.
South Korea must rapidly develop and demonstrate its cyber offensive capabilities to deter North Korean attacks. Despite high ICT-based cyber capabilities, South Korea's use of cyber capabilities for defense and offense has been limited, focusing more on commercial use. This is happening because South Korea has not expanded its approach to new technologies beyond a unidirectional focus.
The government's emphasis on offensive response and cyber resilience in the latest National Cyber Security Strategy is noteworthy. Cyber resilience involves a comprehensive approach to security, including defense, tracking attackers, retaliating based on gathered intelligence, and swiftly restoring compromised systems. Identifying system vulnerabilities and deploying patches to strengthen security against zero-day exploits is the first step toward resilience.
Zero-days refer to vulnerabilities in the software or hardware of network systems, serving as potential entry points for attackers. These flaws are considered among the most lethal and potent tools in a hacker's arsenal.
Physical systems essential to national security should not be connected to the internet, and efforts should be made to remove any back-doors or virtual bombs that could have been installed during previous attacks.
The next phase of cyber resilience entails implementing security settings that not only aim to prevent unauthorized system access but also prioritize rapidly stabilizing the system in the aftermath of an attack. Since no system can be entirely immune to attacks and will always be at a disadvantage against attackers, the best defense strategy is to swiftly normalize the system. Subsequently, identifying the attacker and adopting an aggressive stance becomes the next course of action.
Offensive actions must be backed by substantial attack power. The first method of offensive action, similar to neutralizing a physical threat, is to eliminate the threat of a cyberattack by striking at its origin. However, there are significant challenges in identifying the exact source of an attack and securing evidence that confirms the target, making it difficult to measure the proportionality of damage caused by the strike, which complicates its practical application.
The second method of offensive action involves adopting the perspective of the attacker to pinpoint potential attack vectors and comprehend both the defensive strategies and the objectives of the target. The decisive factor in determining the attack method and point is the efficient achievement of the objective. It's essential to comprehend what the attacker aims to target and their approach. Some things must be seen to be believed, while others must be believed to be seen.
The third method involves South Korea demonstrating its cyberattack capabilities directly to North Korea, aiming at key targets without leaving traces of the attack.
North Korea's cyberattacks have already begun. The methods and damage are not immediately visible. However, believing that North Korea has initiated and is continuing to conduct attacks, with plans to intensify them, allows for a clearer understanding of the reality.
As the National Assembly elections slated for April 10 are approaching, North Korea is expected to launch even more potent cyberattacks, possibly coordinated with offline actions. It's essential to block critical paths, guard against unexpected vulnerabilities, and scrutinize everyday network usage patterns.
Kwon Ho-cheon is the founder, chief executive research director and CEO of Global ICT Lab. He earned his Ph.D. in communications from the State University of New York at Buffalo and bachelor's degree in economics from Ohio University.