On March 20, 2013, at 2:00 PM Korean time, the networks of three South Korean banks and three media companies went dark simultaneously. Screens displayed a skull, systems stopped responding, and administrators found that workstations across their organizations had had their master boot records overwritten with a wiper that had been silently staged inside their networks for weeks. An estimated 32,000 computers were destroyed. ATMs and banking systems went offline. South Korea's financial and media infrastructure was partially paralyzed.
The attack, known as Operation Dark Seoul or the "3.20 Cyber Attack" in South Korea, was attributed to North Korea's Lazarus Group - the same organization responsible for the Bangladesh Bank heist, the Sony Pictures attack, and the Ronin bridge cryptocurrency theft. Dark Seoul was Lazarus's first major destructive attack against a nation-state target, conducted years before Western cybersecurity audiences became familiar with Lazarus's capabilities. For South Korea, it was not a surprise - a prior campaign in 2009 (Operation Trojan Horse) had attacked government websites with DDoS. But Dark Seoul's use of destructive wipers rather than website defacement or DDoS marked a qualitative escalation in the threat.
The Wiper Campaign
Dark Seoul's wiper malware (analyzed under various names including MBR Killer, DarkSeoul, and WhiskeyAlfa/Charlie) was deployed through a supply chain compromise. The attackers had compromised the patch distribution system of a South Korean security software vendor - specifically, an enterprise security management tool that many South Korean organizations used to distribute software patches to networked computers. By inserting their wiper malware into the software distribution system, they could deploy it silently to every endpoint registered with that system across multiple unrelated organizations simultaneously.
The supply chain approach explained the simultaneous nature of the attack: at a scheduled time, the wiper activated on all infected machines at once, overwriting MBRs and making systems unbootable. The simultaneously timing was deliberate - it prevented IT staff at one organization from warning others and created maximum disruption across all targets before remediation could begin.
Attribution to Lazarus Group
South Korea's Korea Internet and Security Agency (KISA) and intelligence services attributed Dark Seoul to North Korea within days of the attack. The evidence was analyzed over subsequent months and included: malware code similarities to prior North Korean operations; Chinese IP addresses used in the attack that were also associated with prior North Korean cyber operations (North Korea uses Chinese infrastructure as C2 proxies); Korean-language strings in the malware code written with North Korean vocabulary differences from South Korean Korean; and operational patterns consistent with North Korean working hours and targeting priorities.
In 2016, the Obama administration's Cyber Command formally attributed the Dark Seoul attacks to North Korea as part of broader attribution disclosures. The Lazarus Group attribution was reinforced by code overlaps with the tools used in the subsequent Sony Pictures attack (November 2014) - Lazarus reused code across operations in ways that allowed forensic researchers to build a picture of the group's toolkit over time.
South Korea's Cyber Resilience Response
South Korea had already been developing significant cyber defense capabilities following the 2009 DDoS attacks - the attacks had led to the establishment of KISA's cyber emergency response center and increased investment in national cyber defense. Dark Seoul accelerated this investment. South Korea established its Cyber Command as a formal military unit, increased funding for civilian critical infrastructure protection, and developed more sophisticated threat intelligence sharing between private sector organizations and government agencies.
The simultaneous targeting of both financial institutions and media organizations was significant for the response: media companies might not have expected to be alongside banks as priority targets of a sophisticated state adversary. The inclusion of media targets reflected North Korean doctrine of information operations alongside destructive cyber attacks - shutting down media organizations while attacking financial infrastructure prevented public reporting during the crisis period and contributed to confusion and panic.