News

Hacking Targeting South Korea by Suspected North Korean Groups Rises… Exploiting AI and Deepfakes

Hacking Targeting South Korea by Suspected North Korean Groups Rises… Exploiting AI and Deepfakes
▲ North Korean IT workers hiding their identities

Cyberattacks by state-sponsored hacking organizations presumed to be from North Korea, China, and Russia reached 158 cases in the first half of this year, marking a 7.5% increase compared to the second half of last year.

In particular, attacks attributed to North Korea most frequently targeted South Korea. The analysis showed that they expanded their attack scope to cryptocurrencies, information technology (IT), and software development ecosystems by leveraging generative artificial intelligence (AI), deepfakes, and fake job postings.

Forces suspected to be from Russia intensified destructive attacks targeting infrastructure centered on Ukraine, while China focused on espionage-type attacks, infiltrating the telecommunications sector and other areas over extended periods to gather intelligence.

According to the Threat Trend Report on State-Sponsored Advanced Persistent Threat (APT) Groups in the First Half of 2026 published by S2W, a total of 158 APT attacks originating from North Korea, China, and Russia were recorded between January and June this year.

This is an increase of 11 cases (7.5%) from 147 cases in the second half of last year, with the growth mainly occurring in the first quarter when attacks from North Korea and Russia were concentrated.

By country, issues related to organizations presumed to be backed by North Korea were the most frequent at 99 cases, followed by China with 33 cases and Russia with 26 cases.

In particular, threats linked to North Korea increased by 13.8% compared to the previous half-year.

Forces presumed to be North Korean targeted cryptocurrencies, information technology (IT), software industries, and developers, actively utilizing fake job postings, code repositories, open-source infiltration, generative artificial intelligence (AI), and deepfakes (technology that manipulates or synthesizes human faces, voices, and actions using AI).

The number of targeted attacks by suspected North Korean forces by country showed South Korea in an overwhelming first place with 19 cases, followed by the United States with 8 cases.

Activities by Russia-backed organizations surged by 30% from 20 to 26 cases.

Suspected Russian forces continued their attacks centered on Ukraine (10 cases) and expanded their hacking targets to European governments and military organizations by attacking Eastern Europe, Poland, and Romania twice each.

They showed a pattern of concurrently executing destructive attacks aimed at system destruction and operational disruption, alongside intelligence gathering.

Attacks backed by suspected Chinese forces decreased by 17.5% from 40 to 33 cases.

The groups presumed to be Chinese maintained their existing attacks on the telecommunications sector while expanding their scope to Southeast Asia (8 cases) and the Middle East (4 cases).

They showed a characteristic of focusing on long-term intelligence collection utilizing legitimate cloud application program interfaces (APIs), virtual private networks (VPNs), network tunnels, and malicious code.

According to S2W's vulnerability analysis, the three countries exploited 15 unique CVEs (security vulnerabilities) a total of 19 times during the first half of the year.

Forces presumed to be North Korean mainly used social engineering techniques and induced user execution, while China primarily attacked vulnerabilities in public servers and boundary network equipment, and Russia mainly targeted document-based malware, webmail, and network equipment vulnerabilities.

Phishing, exploiting public server vulnerabilities, and abusing proxy and cloud services were cited as common attack techniques among the three countries.

The report projected that the infiltration of development ecosystems, long-term access to communications and infrastructure, and sabotage combined with geopolitical conflicts will continue in the second half of the year.

In addition, it urged close monitoring as Iran-backed and affiliated forces could cause indirect damage to domestic manufacturing, aviation, and energy companies through the Middle East region and supply chains.

(Photo: Yonhap News)
※ Please note: This article was translated by AI and may contain errors.
Copyright Ⓒ SBS. All rights reserved. 무단 전재, 재배포 및 AI학습 이용 금지

Most Read