Korean Hackers
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actors refer to themselves as “Korean Hackers” and have also used the alias “John wick” in their communications, though public sources note that their alleged Korean origin cannot be confirmed. They presented themselves as a hacking group capable of infiltrating large media platforms and extracting substantial volumes of data. No definitive state or criminal‑group affiliation has been publicly attributed to them beyond their self‑described identity.
Their reported activity focused on the Indian streaming service ZEE5, which serves over 150 million subscribers, and they hinted at possible access to Dish TV, a satellite television brand owned by the same Essel Group conglomerate. The actors claimed to have exfiltrated roughly 150 GB of private data, including subscriber transaction records, email addresses, mobile numbers, passwords, private messages, source code, secret keys embedded in the source, AWS bucket credentials and references to an Atlassian board. They threatened to sell this database and the associated code on criminal markets and demanded a minimum donation of 10 Ethereum in exchange for not releasing the material, indicating a financially motivated extortion motive.
The tactics described by the actors involve the alleged theft of source code and cloud credentials, the posting of partial data samples on a restricted Bitbucket repository to prove possession, and the alleged access to a Dish TV network drive. They used the threat of public disclosure and sale of the stolen assets as leverage, a classic extortion approach that relies on the credibility of the leaked proof points. No specific malware families or exploit chains were detailed in the reporting, with the emphasis placed on the claimed data haul and the ransom demand.
The most prominently cited operation is the alleged breach of ZEE5’s systems, which the actors said they had discussed directly with ZEE5’s technology team while seeking the Ethereum payment; ZEE5 acknowledged reviewing the breach claims but did not confirm the actors’ assertions. No additional campaigns have been publicly linked to this group in the available source material, and the attribution to any Korean entity remains unverified. The actors’ claims remain unverified by independent verification, and the described activity represents the extent of the publicly reported activity associated with this self‑identified group.
Incidents
Attributed incidents are available to members.
4 incidents