Subject type: Military intelligence organisation
Jurisdiction: Democratic People’s Republic of Korea
Also known as: RGB, Chongchalchong, 정찰총국
File opened: 4 September 2026
Last updated: 4 September 2026
Origin
The Reconnaissance General Bureau was created around 2009 by consolidating several previously separate intelligence and special operations organs under one command. The reorganisation followed a period in which competing agencies had run overlapping operations abroad with poor coordination and several public failures.
Command
The bureau reports through the military chain to the leadership. It is organised into numbered bureaux with distinct functions covering foreign intelligence collection, special operations, technical reconnaissance and overseas operations.
External naming of its cyber components is inconsistent, and this causes persistent confusion. Threat intelligence vendors assign their own labels to activity clusters, and those labels map imperfectly onto the organisational structure. Lazarus Group, Andariel, Kimsuky and BlueNoroff are vendor designations for observed behaviour, not North Korean unit names, and treating them as an organisational chart produces error.
Capability
Conventional intelligence functions include agent operations against South Korea, collection abroad, and special operations forces tasking.
The capability that has changed the organisation’s significance is cyber. Units associated with the bureau have conducted the destructive attack on Sony Pictures in 2014, the Bangladesh Bank SWIFT theft in 2016, the WannaCry ransomware outbreak in 2017, and a sustained campaign against cryptocurrency exchanges, bridges and individual holders that has produced theft totals in the billions of dollars.
Two operational patterns deserve emphasis. The first is the use of fraudulent IT worker placements, in which North Korean nationals obtain remote employment at Western companies under false identities, generating wages and, in some cases, access. The second is social engineering against developers and finance staff at crypto firms, frequently through fabricated recruitment approaches, which has been the entry vector in several of the largest thefts.
The proceeds fund the state, and by most external estimates cyber theft now exceeds all traditional illicit revenue lines combined.
Funding and ownership
State organ, funded from the military budget, and increasingly a net contributor rather than a cost centre. That inversion is unusual for an intelligence service and changes the incentives inside it.
Restrictions and exposure
Designated by the United States, the European Union and others. Named units and individuals carry separate listings, and the US Justice Department has issued indictments of identified officers. Cryptocurrency addresses and mixing services used to launder proceeds have been designated, with mixed results, since address-level designation is straightforward to route around.
The lapse of the UN Panel of Experts in 2024 removed the principal multilateral reporting mechanism here as well.
Watch items
- Theft totals reported by blockchain analytics firms as a proxy for tempo.
- IT worker placement enforcement actions and employer disclosure.
- Laundering route adaptation after mixer designations.
- Any evidence of tasking shifts toward Russian collection requirements.
Related files
- Office 39: the traditional revenue organ