↓Skip to main content
Alemasone

Red Star OS: Inside North Korea's Operating System

Discover how North Korea's OS works, from its macOS-inspired look to hidden file watermarking and digital surveillance mechanisms.

6 min read Updated on
A computer screen displaying an operating system interface with a macOS-like appearance
On this page
Red Star OS is North Korea’s operating system, a Linux distribution developed for internal use. Among security researchers, it is famous not for its appearance, which mimics macOS, but for a silent mechanism: it watermarks every file that passes through the computer with an identifier linked to the machine, allowing the tracking of how documents move from one person to another.

Studying it is interesting for a specific reason: it explicitly shows how an operating system can be built around control rather than around its users. Many of the techniques it uses exist elsewhere, albeit in a more discreet form.

What is #

It is a Linux-based distribution developed by the Korea Computer Center in Pyongyang starting in the early 2000s to replace the copies of Windows circulating in the country. Choosing Linux was both a practical and political decision: open source allows for building a system without depending on foreign vendors and enables deep customization.

Red Star OS boot screen with a red star on a blue background
The red star appears right at startup, even before login

Few versions are known outside the country. The first ones, version 1.0 in 2008 and 2.0, took on the look of Windows XP. The most studied is 3.0, from 2013, which emerged from the country around 2014-2015: it has an interface that closely resembles macOS, featuring a top menu bar and a dock. In subsequent years, news and images of a version 4.0 have circulated, though it has been analyzed much less frequently.

Red Star OS desktop with a top menu bar and bottom dock, very similar to macOS
Top bar, dock, and rounded icons: the resemblance to macOS is deliberate

The copies that reached foreign shores have been analyzed by independent researchers, and almost everything we know comes from there. The most cited analysis was presented by Florian Grunow and Niklaus Schiess at the Chaos Communication Congress in late 2015.

File watermarking #

This is the most technically remarkable part. When you open or copy a document, image, or video onto the system, it adds an identifier derived from the computer’s hardware.

The consequence is precise: if a file changes hands via USB flash drives—which is how foreign movies and series circulate in North Korea—every computer that touches it adds its own trace. Anyone who recovers that file can reconstruct the chain of machines it has passed through.

No internet connection is required for this to work, and that is exactly the point: it is a tracking method designed for a country where, for almost everyone, the web does not exist.

This is not exclusive to North Korea. For decades, many color laser printers have printed nearly invisible yellow dots to identify the device, and corporate data protection systems add labels to documents. Here, however, the purpose changes, as well as the fact that the computer user can neither know about it nor disable it.

Other control mechanisms #

Monitored system integrity. A constantly active component checks that system files are not altered. If it detects a modification, it restarts the computer: this makes permanent changes impossible.

An inverted antivirus. The program presented as an antivirus has signatures that, according to published analyses, are also used to find and delete content deemed “undesirable,” not just malicious programs.

An intranet instead of the internet. Computers do not connect to the global network but to Kwangmyong, the closed national intranet containing only state-approved sites, via the Naenara browser, a modified version of Firefox. Real internet access is reserved for a very small number of people.

No free administration. Normal operations on any Linux system, such as becoming root, installing packages from external sources, or changing the boot configuration, are blocked or undone. However, everyday programs are still available: a text editor, a media player, and an office suite.

Why it interests researchers #

Setting aside the context, Red Star OS is a rare case study: a complete operating system explicitly designed with surveillance as a requirement, not as an add-on.

Three lessons emerge from this that are valid everywhere:

Open source does not guarantee freedom. Linux allows you to look inside and modify things, but if the machine is configured to prevent it, the software license changes nothing for the user.

Control does not need a network. Watermarking works on isolated computers; the idea that being offline keeps you safe is an illusion.

A familiar interface lowers your guard. A system that looks like macOS feels like a normal computer, making it less likely that someone will look into what is happening under the hood.

Is trying it out a good idea? #

ISO images of version 3.0 circulate online and have been used for technical demonstrations in virtual machines. Before you try it, however, consider three things.

The first is practical: these are copies of uncertain origin from unreliable sites, of a system designed to monitor its users. If you must, run it in an isolated virtual machine without network access or shared folders with your actual computer.

The second concerns the depth of information: researcher analyses tell you much more than what you will discover by browsing the interface, and they are public, including the video from the Chaos Communication Congress presentation.

The third is utility: as an operating system, it is outdated, in Korean, and has no practical use outside its specific context.

FAQ #

Is Red Star OS still in use? #

Information coming from outside is fragmentary, and more recent versions have not been publicly analyzed. Available reports suggest the country continues to develop its own system software, but there is no up-to-date, independently verifiable overview.

Does the system work without an internet connection? #

Yes, and it is designed specifically for that environment. The file tracking mechanisms operate locally and require no connection: they are meant to track the circulation of documents on physical media, not online.

Can you remove the watermark from files? #

Researchers have described how it works and what the added information looks like, but for those living outside that country, the question is theoretical. The interesting point is different: the marking occurs without any warning and without the possibility of opting out.

Since it’s based on Linux, is it open source? #

It is derived from open-source components, but that doesn’t mean the complete system is freely available or that the user can modify it. The base software licenses would impose obligations that, in practice, do not translate into any freedom for the user.

Why does the interface mimic macOS? #

There is no official explanation. The most cited hypothesis is an aesthetic choice inspired by Apple products, which were symbols of modernity even in countries with limited access to foreign technology during those years.

Read next