First of all, they’ve got plenty of computers there. They have their own linux-based OS. Lots of educated people who can be trained.
You don’t need much more than an internet connection and some free courses to learn how to reliably break into your average company’s network, though that “more” is something usually only governments are good at having: millions of dollars
There’s a grey market of zero-day vulnerabilities (publicly unknown bugs in software like OS’s and browsers) where governments and anyone else with deep pockets can buy that knowledge. Finding those vulnerabilities in software is something that requires lots of talent, but the market means DPRK doesn’t need to foster that talent on its own. They can just skip the hardest part with cash.
You can also use publicly known vulns against targets that haven’t patched their systems, but that’s less reliable. Or use any number of social engineering techniques. But $$$ will mostly just solve that part of the problem for you
Latest Answers