DistantNews
Support us
North Korea tops list of state-backed hacking incidents in first half of year
๐Ÿ‡ฐ๐Ÿ‡ท South Korea /Technology

North Korea tops list of state-backed hacking incidents in first half of year

From Dong-A Ilbo · () Korean

Translated from Korean, summarized and contextualized by DistantNews.

At a glance

News Documents & data Context piece
  • Cyberattacks attributed to North Korea, China, and Russia increased by 7.5% in the first half of the year compared to the latter half of 2023.
  • North Korean-backed attacks, primarily targeting South Korea, rose 13.8%, employing tactics like fake job offers and malicious code in repositories, even using AI and deepfakes.
  • China's attacks decreased but expanded geographically, while Russia's attacks surged 30%, focusing on Ukraine and European infrastructure, with both nations also exploiting system vulnerabilities.

Cyberattacks orchestrated by state-backed hacking groups from North Korea, China, and Russia saw a notable increase in the first half of this year, with a 7.5% rise in reported incidents compared to the previous six months. A report by S2W analyzing 158 incidents related to these APT (Advanced Persistent Threat) groups highlights evolving tactics and expanding targets, raising concerns for businesses and infrastructure worldwide.

The increase in attacks was mainly concentrated in the first quarter, driven by the activities of North Korean and Russian-backed organizations.

โ€” S2WExplaining the timing and primary drivers of the observed increase in cyberattacks.

North Korea emerged as the most prolific actor, accounting for 99 incidents, a 13.8% increase from the previous period. These attacks frequently targeted developers and the IT and software sectors through deceptive job offers and the embedding of malicious code within code repositories and npm packages. Notably, these groups have also begun leveraging generative AI and deepfake technology in their operations. South Korea remained the primary target for North Korean cyber activity, with 19 reported instances, followed by the United States with eight.

While Chinese-backed attacks decreased by 17.5% to 33 incidents, their scope broadened. China's threat actors continued to focus on telecommunications infrastructure while extending their reach into energy, military organizations, and Southeast and Middle Eastern regions. They employed sophisticated methods, including the use of legitimate cloud APIs, VPNs, and tunneling tools, alongside the persistent backdoor malware 'BPFDoor' for long-term information gathering.

North Korean-backed organizations repeatedly used tactics such as sending fake recruitment offers targeting the cryptocurrency, IT, and software industries and developers, or hiding malicious code in code repositories and npm packages. Cases of using artificial intelligence (AI) and deepfakes in attacks were also confirmed.

โ€” S2WDetailing the specific methods employed by North Korean hacking groups.

Russia-backed cyber operations experienced the most significant growth, increasing by 30% to 26 incidents. Their focus remained on Ukraine, but they also targeted government and military organizations and infrastructure across Europe. These attacks aimed not only at information theft but also at system destruction and service disruption. Fifteen different security vulnerabilities were exploited across all three nations' attacks, with North Korea favoring social engineering, China targeting network perimeter devices, and Russia exploiting vulnerabilities in documents, webmail, and network equipment.

China continued its concentrated attacks on the telecommunications sector, while expanding its activities to the energy and military sectors, and to Southeast Asia and the Middle East.

โ€” S2WDescribing the evolving targets and geographical expansion of Chinese cyber threats.

Looking ahead, S2W predicts a continuation of these trends, including infiltration of development ecosystems and long-term access to critical infrastructure. The report also flags potential threats from Iran-backed actors, particularly in light of geopolitical tensions in the Middle East, warning that these activities could indirectly impact manufacturing, aviation, and energy companies globally through supply chain disruptions. The analysis underscores the need for integrated defense strategies that extend beyond traditional email and malware defenses to encompass development environments, supply chains, cloud services, and AI analysis platforms.

Russia-backed organizations focused their attacks on Ukraine, while expanding their targets to government and military organizations and infrastructure in Europe. They conducted attacks aimed not only at information gathering but also at system destruction and service operation disruption.

โ€” S2WOutlining the focus and objectives of Russian-backed cyber operations.
DistantNews Editorial

Originally published by Dong-A Ilbo in Korean. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.