North Korean Hackers Target South Korea Most Frequently with 19 Attacks, Leveraging AI and Deepfakes — BigGo Finance | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


North Korean state-sponsored hacking groups concentrated their attacks on South Korea more than any other country in the first half of this year, according to new research. The threat actors significantly escalated operations targeting cryptocurrency and software development ecosystems, employing generative artificial intelligence (AI), deepfakes, and fake job postings.

According to the “2026 H1 State-Sponsored Advanced Persistent Threat (APT) Group Threat Trends Report” released by cybersecurity firm S2W on August 16, APT attacks attributed to North Korean, Chinese, and Russian hacking organizations totaled 158 incidents in the first half of the year. This represents an increase of 11 incidents (7.5%) from 147 in the second half of last year. The growth was primarily driven by heightened activity from North Korean and Russian groups during the first quarter.

By country of origin, North Korea-linked organizations were associated with the highest number of incidents at 99, followed by China at 33 and Russia at 26. North Korea-linked threats surged 13.8% compared to the previous six-month period.

North Korea primarily targeted the cryptocurrency, information technology (IT), and software industries, along with individual developers. The groups actively leveraged fake job postings, code repository and open-source package infiltration, generative AI, and deepfake technology. Deepfakes refer to AI-generated manipulation or synthesis of a person’s face, voice, or behavior.

By target country, South Korea was overwhelmingly the top target of North Korean operations with 19 attacks, followed by the United States with 8.

Russia Intensifies Destructive Attacks, China Focuses on Long-Term Espionage

Activity attributed to Russian state-sponsored groups increased 30%, from 20 incidents in the previous half to 26. Russia targeted Ukraine most heavily with 10 attacks, while also striking Eastern Europe, Poland, and Romania twice each, expanding its hacking targets to include government and military organizations across Europe.

Russian groups demonstrated a pattern of combining intelligence collection with destructive attacks aimed at system disruption and operational shutdown.

Chinese state-sponsored attacks declined 17.5%, from 40 to 33 incidents. Chinese groups maintained their existing focus on the telecommunications sector while expanding their operational footprint into Southeast Asia (8 incidents) and the Middle East (4 incidents). A defining characteristic was their emphasis on long-term espionage using legitimate cloud application programming interfaces (APIs), virtual private networks (VPNs), network tunnels, and malware.

Distinct Vulnerability Exploitation Patterns by Country

S2W’s vulnerability analysis revealed that the three countries exploited 15 unique CVEs (publicly disclosed security vulnerabilities) across 19 separate instances during the first half.

North Korea primarily relied on social engineering techniques and user-execution lures. China focused on vulnerabilities in public-facing servers and perimeter network equipment, while Russia concentrated on document-based malware, webmail, and network device vulnerabilities. Phishing, exploitation of public server vulnerabilities, and abuse of proxy and cloud services were identified as common attack techniques across all three countries.

CountryAttack CountChange vs. Prior HalfPrimary Targets
North Korea99+13.8%South Korea (19), United States (8)
China33-17.5%Southeast Asia (8), Middle East (4)
Russia26+30%Ukraine (10), Eastern Europe/Poland/Romania (2 each)

Note: Attack counts are based on S2W’s tracking of incidents related to state-sponsored APT organizations.

Middle East Supply Chain Threats Loom as Second-Half Wildcard

The report projects that development ecosystem infiltration, long-term access to telecommunications and infrastructure, and destructive operations tied to geopolitical conflicts will continue into the second half of the year.

Notably, the report highlights Iran-backed and affiliated groups as a key threat to watch, warning they could inflict indirect damage on South Korean manufacturing, aviation, and energy companies through Middle East-based supply chain attacks. Middle East-originated supply chain attacks could serve as an entry vector, penetrating headquarters systems via overseas business sites or partner companies of South Korean firms.

Security experts advised: “Organizations must move beyond fragmented, reactive measures focused on email and malware blocking, and instead establish an integrated defense framework encompassing development environments, supply chains, internet-exposed assets, cloud infrastructure, and AI environments.” They added, “Alongside strengthening intrusion detection capabilities, immediate rotation of account credentials, implementation of immutable backups, and restoration of recovery systems are urgently needed.”



Click Here For The Original Source.

——————————————————–

..........

.

.