Go back

He hacked back — and took down North Korea’s internet

24m 56s

He hacked back — and took down North Korea’s internet

A significant shift in cybersecurity policy emerged when President Trump signed a memo permitting private companies to legally "hack back" against cyberattacks, a move that challenges longstanding principles of non-retaliation. This development is highlighted through the story of Alejandro Casadez, a cybersecurity expert who, after being targeted by North Korean hackers through a deceptive online interaction, decided to retaliate. Initially concerned about the implications of state-sponsored attacks on private individuals, Casadez eventually launched a covert offensive against North Korea’s internet infrastructure. Using a denial-of-service attack, he targeted two critical routers that served as the backbone of the country’s internet, effectively disrupting government and state websites for nearly a week. The attack, which went undetected by North Korea and remained unattributed globally, demonstrated the vulnerability of North Korea’s limited and centralized internet network. While the U.S. government expressed curiosity about the operation, senior cyber officials remained cautious, citing legal and ethical concerns—particularly around attacking civilian infrastructure, which may constitute war crimes. Experts argue that cyber operations differ fundamentally from traditional warfare, as networks are dynamic and constantly evolving, making such attacks unstable and unpredictable. Casadez’s actions, while not officially sanctioned, reflect a growing debate over whether offensive cyber operations should be more widely authorized, especially when foreign actors target private citizens. The episode underscores the complex intersection of technology, ethics, and national security in a world where digital attacks can have real-world consequences.

Transcription

4405 Words, 24681 Characters

English
From recorded future news and PRX, this is Click Here. Last month, President Donald Trump signed a memo that could change one of the basic rules of cybersecurity. For years, if someone hacked your company, you could defend yourself. You could call the FBI, but what you generally could not do was hack them back. Now the Trump administration wants to make that possible. President Trump has signed a national security agreement aimed at fighting cybercrime from overseas. The idea is that private companies can now go on the offensive against cybercrime gang with the government's permission and with legal protection, which raises an interesting question. What if the people you're hacking aren't just criminals? What if they're connected to another government? What if they are foreign government? A few years ago, one guy found himself in almost exactly that situation, except he didn't exactly wait for permission. Today, we're going back to an episode we first aired in 2024 about what happened when one guy decided to hack back, take a listen. Everything got a little weird for Alejandro Casadez around three years ago. That's when a friend of his made an introduction to a guy who went by the name James Willie. I kind of knew that the whole James Willie name was fake, but then people in the cyber world used fake names all the time he told himself. So I didn't really think much of it. Alejandro is 38, lives in Florida and is a cybersecurity guy. His online handle is Pax, which he spells P, the number four, and then the letter X. The specialty is writing exploits, the code that takes advantage of vulnerabilities in software. A few years ago, he decided to build his own cybersecurity business, and when you're starting out and building a client list, you tend to be less choosy. You just want to get customers in the door, even if in retrospect, alarm bells are ringing everywhere. And of course, Ron, the shadiest chat messenger that there is was telegram, but that's also not there. So Alejandro and this James Willie start training messages, talking about their cyber experience, the types of projects they've worked on. He asked me, I have what is the start of what I think could be a really good exploit. It is part of what we call a full chain exploit, and that's just where you are attacking a very complex program, and it requires more than one vulnerability to really own the computer. James Willie appeared to have found the motherload. In this case, it was Google Chrome. Everyone uses Google Chrome, right? It's the vulnerability that hackers dream about, because it could compromise so many computers. The problem James Willie said is that he couldn't quite get his exploit to work. Maybe Alejandro, with all his coding skills, could lend a hand. It was very like flattering, but not in an obvious way, you know, like it was just like I think he could do this, you know. James sent him the exploit, so Alejandro could take a look. Now, Alejandro isn't naïve, he doesn't just double click on everything that comes to him. So he opened the exploit in an air gap computer that wasn't connected to his system, and you guessed it. So it turns out that the project that he sent me was back doored, and it was the downest back door I've ever been owned by. Alejandro had been hacked, at least technically, because he'd been careful about where he'd opened the exploit, he was able to contain the damage. At first he was mad, and then he was a little insulted. This was a super obvious fishing attack, and a really basic back door that was super easy to find. I wish I could say it was some super hacker technique or something like that, but the frank truth of it is that he just knew the exact right character that he'd been going front of me. And for months, Alejandro didn't give it much thought, until one day he was reading a blog post by Google Tag, a threat analysis group, and one of their warnings caught his eye. Apparently, North Korean hackers were targeting cyber security researchers, and then Alejandro gasped. It gave aliases that they used, and the shirt knocked one of the most James Willie. James Willie, just like the name of the guy he'd been chatting with on Telegram. What did you think when you read that? I mean, like, did your heart sink, or did you like slap yourself on the side of the head? What was your reaction? I think my first reaction was just like shock, like holy shit, like I was just targeted by a nation state. The show about how technology is changing everything. I'm Deena Temple Rastin. And today, the story of Alejandro Cusades, an American who got hacked by North Korea, and then responded by doing something no one was expected. He hacked them right back. What exactly did you take down? The answer is everything. Stay with us. Support for click here comes from Serval. Your IT team could be building infrastructure, solving real problems. Instead, they're stuck resetting passwords and approving access requests. Running the same support playbook over and over again. And that's not a capability problem. That's a work design problem. Serval fixes it. You simply describe what needs automating. In plain English, no technical jargon needed, and Serval builds the automation for you. No drag and drop builders to wrestle with, no consultant fees, eating your budget. No waiting months for implementation. The result, IT stops being a bottleneck and becomes the operational engine that moves the business forward. And Serval backs this up with a guarantee that half of your IT tickets will be fully automated. Test it for yourself. Learn more or start a free four week pilot at Serval.com/click here. That's S-E-R-V-A-L.com/click here. Support for Click Here comes from Nord Security. Here's the challenge. IT teams need to see what's happening in browsers, but they can't slow anyone down or disrupt their workflow. Nord layer browser solves this. It gives IT teams full visibility and control over browser activity, while keeping everything familiar and fast for employees. Two products work together. Nord layer provides the Secured Network Foundation, then Nord layer browser extends that into the workflow, managing web apps, sessions, and data. The payoff, every browser's session becomes visible, controlled, and secure. Company data stays protected, access to sensitive resources is managed. Accidental data leaks are prevented. And it works for all kinds of teams, remote workers, contractors, people using their own devices, all secured without the complex setup or device management. Go to nordlayer.com/browser/click here, and unlock your 10% discount on Nord layer browser with coupon code "click here 10". That's nordlayer.com/browser/click here, and enter coupon code "click here 10" at checkout. When our Alejandro Cásadas was a kid, his dad didn't just bring him home a personal computer. He actually built him one. My dad's a really smart guy. He's a PICU doctor, but somehow knows a lot about technology. He would build his own computers. And they weren't like the Commodore 64 computers that other kids had. They were just sort of Frankenstein's, and he just loved doing that. And I would use them and mess them up sometimes, and just do stupid stuff with them. So, that's kind of where my first computer came from. When Alejandro was around 13, he began logging onto that family computer, entering AOL chat rooms, and doing what budding hackers often do. I started to get into what we would call now denial of service attacks. DDoS attacks. There was this little program, sir. You would flood people with messages, or you would use some funky tricks. Funky tricks like adjusting the font size. Like, for example, you increase the font a ridiculous amount. Not just 14 point type, but like a thousand point type. You send it, and it kicks them off line immediately, so I just, I enjoyed it, and I don't, I honestly cannot describe why besides the fact that I was. just a little jerk. - Or you could say like just about any other computer that we're a kid, he was trying to test the limits of the internet. - So in those days, there was the tools like back or office, right? Those are, they were basically like you send a Trojan. - A Trojan is a type of malware disguised as legitimate software. - That's binded with a game or something like that. And you could just send it to your target. - Kind of the early version of what those North Korean hackers seem to do to him. - My first proper hack, it was a friend of mine. He, I sent them this like really, really dumb game. And I told them this game is amazing. You have to play it and he opened it. - And suddenly Alejandro had access to his friend's computer. But if he wanted to take actual control of it, he needed the IP address. - In those days, when you sent an email, your IP address was actually right there. So I told him, hey man, I'm having some problems with my email. If you could please send me a test email, just I really wanna make sure that this is working. He sent me a test email. And then I connected to his computer. - Then Alejandro started to have a little more fun. He started sending his friend fake error messages and then randomly opening and closing the CD tray. - Remember those? - So did he think like his computer was possessed? - Yeah, that was kind of my goal. - And you think that Alejandro kind of saw the writing on the wall back then that this computer stuff was his calling, but he didn't. Instead, he went to Duke and double majored in physics and math. - I wanted to be a professor and just research and study and do physics for the rest of my life. And that might have been the end of it and we might never have met him. Had he not started working with supercomputers to finish his thesis? - My thesis was on heavy ion collisions and simulations of them. So I got to work with like a supercomputer that they had there and that's where I kind of learned Linux and also got an understanding of things like, what is remote access? How do you use it? Why do you use it? How does it work? - Something kind of clicked in my mind and I was like, oh, so there's remote protocols. People set them up like idiots and then somebody breaks in and that would be a hack. It was like a light bulb moment. - And it changed everything? - I'm a hacker and that's how I always describe myself. - His official title is more like offensive security researcher which means he doesn't just sit back and defend networks. - I don't focus on the security card. I'm like, I'm an offensive, offensive researcher. - An offensive, offensive researcher. He's more interested in finding vulnerabilities that help you go on the attack. Which may explain why for the past decade or so, Alhandro has applied for and landed a bunch of contracts that he can't talk about with a roster of lettered agencies and places like the Department of Defense and DARPA, which means one of two things. That hacker James Willie either had no idea who he was dealing with or knew exactly who he was dealing with. - What do you think they really wanted? - They did hit a couple of other exploit writers, and so I know that they were looking for zero days. - Zero days, those are vulnerabilities and software that no one knows about. - Was there a moment when you thought, hey, the North Korean shouldn't get away with this? - Yeah, that's exactly right. And I saw that they were going to, they were, they absolutely were going to get away with it. - In the weeks that followed, Alhandro talked to people he knew, FBI agents, other law enforcement, to see if maybe they'd step in and help it. Certainly they didn't think it was okay for North Koreans to attack Americans, he thought. But as the week stretched into months, it was obvious that no one was going to step in. He was positive North Korea had hacked him and that they were hoping to steal exploits he had written. They actually put a back door on his computer and there'd be no consequences for that. - So was there sort of this moment where you went, that's it, I'm gonna get back at him myself. - Yeah, actually, that was kind of my first thought. - Let's hack North Korea, like the whole country. - The thought of bringing a country was not really, I never really planned much except for, let's let's see what I can do. (upbeat music) - Stay with us. - Support for Click Here comes from Odoo. Business software is expensive and when you buy it from lots of different companies, it also gets confusing and slow and hard to integrate. Odoo solves that because all their software is connected on a single affordable platform. So you can save money without missing out on the features you need. Odoo has no hidden cost and no limit on features or data. It has over 60 apps available for any needs your business might have. Everything from websites to sales to inventory and accounting, all linked and talking to each other for no additional charge. Check out Odoo at odoo.com. That's odoo.com. That's odoo.com. - I think if this technology goes wrong, it can go quite wrong. - We've been imagining the end of the world forever. - It speaks to both our desire to live and our fear of our own capacity to destroy ourselves. - I've spent the last two years asking the world's top experts if AI will kill us all. - The world where everything goes right looks identical to the world that goes very wrong up until the exact moment that it goes wrong. - Suspicious minds, AI in the apocalypse. Season two is available now. (upbeat music) - In his public life as a security researcher, Alhunder runs a cybersecurity company called Hyperion Grey. He's kind of infamous for creating a controversial scanning tool called Punk Spider. - I'm also under the Punk Spider Project. Does anybody here heard of the Punk Spider Project? - He unveiled it at the Defcon Hacker Conference in 2021. - Oh, sweet. More than like five people. It's more than expected. Awesome. - So he's the kind of hacker who actually could launch a kind of revenge tour on North Korea. And he spent more than a year planning it and it began with James Willie. - So you were really looking for him. - At first, I definitely was. After that, I kind of realized that's not really gonna be fruitful. - James Willie was a fake name and he probably wasn't online anyway. So Alhunder decided he would go bigger to see what he could find in North Korea's networks that were worth hacking. That would send a message. - I know they're internet is extremely limited. She in terms of access. - And when he says limited access, he means really limited. Of the 26 million people who live in North Korea, only a few thousand get to actually use the internet the rest of the world sees. You actually need special approval to even get on to the internet. And then minders sit next to people while they browse and have to approve their activities. There's an hour time limit to factors say. And then you have to apply again for permission to do more searches. So in other words, the odds that Alhunder's nemesis was online and searchable was pretty unlikely. And he started the way most hackers do by running some scans of their infrastructure. - I knew that they weren't extremely sophisticated in their infrastructure. Maybe I will do some port scans and do some manual analysis and find something to break into. - So Alhunder thought maybe he could hack into some critical infrastructure in North Korea and send a message that way. But that wasn't working out very well either. - It's not like I could find the IP range for whatever their dictatorial policies over there. You can't find Kim's private computer. - That's exactly right. Yeah, I mean, hopefully one day I'll be able to break in and it'll say like, you know, Kim Jong Un's personal computer, maybe as multiple like Kim Jong Un's personal, Kim Jong Un's porn computer, Kim Jong Un's official, yeah. So maybe someday. - And we should say here that Alhunder's hack as we're about to describe it, was first reported by Andy Greenberg at Wired Magazine. Where Alhunder's first broadcast interview in, we got a few new details. At its most basic level, Alhunder decided to launch an attack that would just overwhelm their internet systems. - The machine runs out of memory and they have like denial of service conditions, right? I found a bunch of vulnerabilities to those. And so I wrote a few little end days as they call them. And days, known vulnerabilities that no one's used yet. This was-- child's play, Alejandro thought as he moved through their systems, their internet infrastructure was pretty rickety. Wow, like they have. This has made out like sticks and glue. Then he began to wonder whether there was a better internet buried somewhere else, somewhere he couldn't see. So I thought, you know, I'll go rent a sort of rent in China. I don't care if they're watching, I will, you know, just do it completely anonymously, it's, you know, we offer ways and I will do a scam from there. And I did a scam and it looked exactly the same and almost like, wait, okay, and I was like, so it doesn't seem to be any kind of like special routing or anything like that. And as he traced the North Korean infrastructure, he found this even crazier thing. I started to notice and like the same two IP addresses just kept going out and like wait a minute. That's interesting, like usually when you have an entire country, it's a ton of them. A ton of IP addresses and he thought that couldn't be right, there must be more than two routers. He thought maybe there was an internet in North Korea that couldn't be accessed from the West. So. Basically made a big circle around North Korea. So I just rented like, I don't know, like 20, 30 servers and they're literally circling North Korea. And sure enough, so it's two routers North Korea was running its connection to the rest of the world's internet through just two machines, both of which Alejandro decided to hack. I was just like, that's incredible, I've never seen that, let's see what I can do. And it turns out while the routers were bigger than something you might have at home, they weren't all that complicated. So he just did a kind of denial of service attack on those two vulnerable routers. And just like that, he literally took down the web in the Hermit Kingdom, everything from their government portal to the state news services to the booking site for North Korea's flagship airline, Eric Koryo. And what would they have seen on their end? Yeah, on their end they see absolutely nothing, which is the best part. Oh, they're getting like a 404 error message? Oh, oh yeah, in terms of when it actually went down, yeah. And researchers all over the world who monitor that North Korean internet said they saw these mass scale attacks. So this guy was able to run a script and as they were doing their own thing, their American computer was destroying the backbone infrastructure of North Korea's entire country. Literally all North Korean websites were under attack, of which there aren't many by the way. And no one knew who was behind it. North Korea's internet was down for nine days before Alejandro decided to restore it. My goal was really just like do it for about a week, and the idea was I want this to be proportional. I don't think that I don't want it to be like their internet's down forever. Still, even the act of taking down a nation's internet for more than a week is pretty out there. And the US government had watched it happen and was a little curious about how Alejandro pulled it off. Some of his hacker friends who had links to the Pentagon put him in touch with some high level people. And Alejandro says he went and talked to them about joining him in offensive, offensive cyber. I outlined the exact methodology that I used for North Korea and I outlined how it could easily be reproduced with a very, very small budget, like compared to what they have. It's nothing. It's like a penny for that. Alejandro said that the people he met with were intrigued, but a little reticent. They didn't seem to want to engage in these kinds of aggressive offensive cyber operations. And Alejandro is like, hey, on this guy, I have real solutions to your problems. What I have is I have literally one program that can stop every single cyber attack that comes out of North Korea. Alejandro said they said thanks, but no thank you. There are some valid reasons why the Pentagon or US cyber command weren't eager to adopt Alejandro's aggressive stance on hacking back. For one, his take down of the North Korean Internet wasn't really a military target. It was a civilian one. And attacking something like that is usually considered a war crime. That's what Russia is dealing with now is it attacks Ukraine's civilian infrastructure. There was a lot of debate initially. This is Jackie Schneider. She's a fellow at the Hoover Institution at Stanford. And her research focuses on the intersection of technology and national security. Is offensive cyber more like dropping a bomb or more like spine? Because those are actually different authorities spying versus dropping a bomb. She says what he was essentially asking the Pentagon to do is an end run around these rules called authorities, which determine what the government can and can't do in cyberspace. And it's complicated because not only is the US still trying to figure out when offensive cyber is appropriate, but it's also a completely different kind of weapon. Unlike bombs, cyber weapons aren't something you can just stockpile and then pull out and use whenever you want. So at the beginning of cyber operations in the US, we thought about building cyber attacks like we would build those kinds of bombing plans, right? The problem is the network changes all the time. Vulnerables get patched, etc, etc. Exactly. So you can't actually put a cyber attack on the self. By the time that approval action comes through, the vulnerabilities in the network that we're going to be used could be gone, something that worked two hours ago might not work when you go to execute it. Right. Or you're sitting in the network and then all of a sudden the way you got in is no longer open. Exactly. Exactly. So is a hack a bomb or just spying? Jonathan McGrath, a former executive officer at the US Cyber National Mission Force, says no, Hunter is right, there need to be new rules about when it's appropriate to punch back in cyberspace. I know what international waters are. I know if we have a ship off the coast, you know, and it's 20 miles out at the end of the day, we all know the boundaries for international waters. But when it comes to cyber, we somehow let the bullies hang this upside down and shake the change out of our pockets every second of every minute of every day. Jonathan thinks the US should start contracting some of this offensive hacking out to trust firms like they do more traditional weaponry. They could set up some rapid response teams. Where is a nation going to draw its red line, right? Which is exactly what El Hondo says he was doing, drawing a red line. I'm really not at the gig for anything like crazy radical like, like, yeah, let's attack that everybody that attacked us, it's really more just, they're not just attacking government stuff. They are now hitting private citizens and nothing is being done. That is until North Korea targeted the wrong guy and he decided to teach them a lesson by turning off their internet for a little while. This is Click Here. Click Here is a production of recorded future news and PRX. Today's show was written and produced by Megan Dietri, Sean Powers, Erica Gutta, Zach Hirsch, and Maya Fawas. It was edited by Karen Duffin and Sarah Kavado and fact-checked by Darren Anchoram. Original music is by Ben Levingston with additional music from Blue Dot Sessions. Our staff writer is Lucas Riley, our illustrator is Megan Goff, and our sound designers and engineers are Jake Cook and Jesse Naiswanker. I'm Deena Tumble Reston and thanks for listening. Support for this program comes from Recorded Future. In cybersecurity, the biggest risk isn't what can be seen, it's what gets missed. Recorded Future analyzes billions of signals to help organizations stay ahead of threats. Recorded Future. Know what matters? Act first. Looking for more of the cybersecurity and intelligence coverage you get on Click Here? Then check out our sister publication The Record from Recorded Future News. You'll get breaking cyber news from reporters in New York, Washington, London, and Kiev among others. And you'll see for yourself why it attracts hundreds of thousands of page views every month. Go to the record.media

Podcast Summary

Key Points:

  1. President Trump signed a national security memo allowing private companies to legally hack back against cyberattacks with government approval, raising concerns about targeting foreign governments.
  2. Alejandro Casadez, a cybersecurity researcher, was targeted by North Korean hackers after a suspicious connection with a fake-identity contact named James Willie, leading him to believe he was targeted by a nation-state.
  3. Casadez, operating under the alias "Pax," launched a deniable, targeted cyberattack on North Korea’s internet infrastructure by exploiting two critical routers, temporarily taking down government and state websites for nine days as a form of retaliation.

Summary:

A significant shift in cybersecurity policy emerged when President Trump signed a memo permitting private companies to legally "hack back" against cyberattacks, a move that challenges longstanding principles of non-retaliation. This development is highlighted through the story of Alejandro Casadez, a cybersecurity expert who, after being targeted by North Korean hackers through a deceptive online interaction, decided to retaliate. Initially concerned about the implications of state-sponsored attacks on private individuals, Casadez eventually launched a covert offensive against North Korea’s internet infrastructure.

Using a denial-of-service attack, he targeted two critical routers that served as the backbone of the country’s internet, effectively disrupting government and state websites for nearly a week. The attack, which went undetected by North Korea and remained unattributed globally, demonstrated the vulnerability of North Korea’s limited and centralized internet network. S.

government expressed curiosity about the operation, senior cyber officials remained cautious, citing legal and ethical concerns—particularly around attacking civilian infrastructure, which may constitute war crimes. Experts argue that cyber operations differ fundamentally from traditional warfare, as networks are dynamic and constantly evolving, making such attacks unstable and unpredictable. Casadez’s actions, while not officially sanctioned, reflect a growing debate over whether offensive cyber operations should be more widely authorized, especially when foreign actors target private citizens.

The episode underscores the complex intersection of technology, ethics, and national security in a world where digital attacks can have real-world consequences.

FAQs

Alejandro Casadez launched a denial-of-service attack on North Korea's internet infrastructure, taking down key government and state services for nine days.

It was a civilian target, as it targeted North Korea's internet infrastructure rather than government military systems, which raises concerns about war crime under international law.

He identified that North Korea relied on just two routers to connect to the global internet and found vulnerabilities in those routers that allowed a denial-of-service attack.

Yes, the U.S. government observed the attack and contacted Alejandro, but high-level officials were cautious and did not support or adopt his offensive cyber strategy.

Cyber vulnerabilities change rapidly—by the time an attack is approved, the target may have been patched, making it ineffective and potentially illegal or unethical.

A red line represents a clear threshold for retaliation; Alejandro's actions were seen as drawing such a line by showing that private citizens could be targeted and retaliated against.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.