DarkSeoul is the name commonly used for destructive malware and related attack activity associated with North Korean operations targeting South Korea in 2013. It is best known for the March 20, 2013 attacks against South Korean broadcasters, financial institutions, and an internet service provider, where the malware functioned as a wiper by overwriting hard drives and rendering large numbers of systems inoperable. Reporting on the campaign links it to broader North Korea-aligned activity, including operations attributed to the Lazarus ecosystem and entities associated with the Reconnaissance General Bureau. DarkSeoul has also been referenced in connection with subsequent June 2013 disruptive activity affecting South Korean government-related targets.
The malware’s defining behavior is destructive disk wiping rather than espionage or monetization. It was used to damage endpoints and servers at media and banking organizations, causing widespread operational disruption. Comparative reporting has noted similarities between DarkSeoul and other wipers such as Shamoon, including abuse of a raw-disk access driver to obtain low-level disk functionality for destructive actions. The campaign targeted South Korean media, finance, and government-linked sectors during a period of heightened inter-Korean tension, indicating an intent to disrupt services and create psychological and economic impact rather than to establish persistent covert access.
DarkSeoul is therefore characterized primarily as a politically motivated wiper used in disruptive attacks against South Korean organizations. High-confidence reporting supports its association with North Korean threat activity and its role in destructive operations against banks, broadcasters, and other institutions in South Korea.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The attacks continued on March 20, 2013, with DarkSeoul, a wiper attack that targeted three South Korean broadcast companies, financial institutes, and an ISP.
"...with DarkSeoul, a wiper attack that targeted three South Korean broadcast companies, financial institutes, and an ISP."
1 distinct technique documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a comparative example of a wiper that abused a disk access driver for destructive operations.
Wiper malware used in destructive attacks against South Korean broadcast companies, financial institutions, and an ISP.
Malware/toolset associated with 2013 South Korea incidents; used for destructive impact (hard drive overwrites/wiping) and also linked to DDoS activity against government websites.
Referenced in bibliography in connection with cyberattacks against South Korea; the main content discusses similar 2013 destructive attacks but does not center on this malware family by name.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.