South Korea Warns of State-Backed Watering Hole Attacks
South Korea warned that nation-state actors are using phishing and compromised websites to silently infect citizens and businesses. South Korea agencies (The National Intelligence Service, the National Police Agency, the Korea Internet & Security Agency, and the Financial Security Institute) jointly published an advisory warning that a state-backed hacking group is actively targeting South Korean […]

South Korea agencies (The National Intelligence Service, the National Police Agency, the Korea Internet & Security Agency, and the Financial Security Institute) jointly published an advisory warning that a state-backed hacking group is actively targeting South Korean citizens and businesses. The warning names two attack techniques: phishing emails and watering hole attacks, and it doesn’t sugarcoat how little a victim has to do wrong.
The phishing side runs on two tricks. In one version, attackers disguise themselves as job applicants and send a resume email with a link instead of an attachment, pointing to a blog or GitHub page the attacker controls. In the other, they impersonate an actual recruiter, sometimes hijacking a real headhunter’s email account, and attach a password-protected ZIP file labeled as a job offer that infects the machine the moment it’s opened.
Source: https://securityaffairs.com/196417/apt/south-korea-warns-of-state-backed-watering-hole-attacks.html
Related breach coverage
- US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra Servers2026-07-24
US agencies warn Russian group Laundry Bear is exploiting a patched Zimbra flaw to steal email accounts from organizations running unpatched servers. The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Federal Bureau of Investigation (FBI) and other U.S. government and international partners published a joint advisory to warn that the Russia-linked APT […]
- UK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisations2026-07-23
GCHQ’s National Cyber Security Centre and international partners issue warning as ‘LAUNDRY BEAR’ cyber threat group exposed for targeted phishing campaign
- UK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisations2026-07-23
GCHQ’s National Cyber Security Centre and international partners issue warning as ‘LAUNDRY BEAR’ cyber threat group exposed for targeted phishing campaign
- North Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn2026-07-30
Cyberattack tools and infrastructure used by North Korea’s Lazarus Group appear to have been shared with ransomware criminals targeting South Korean organizations — further evidence of deepening entanglement between Pyongyang-backed hackers and the ransomware ecosystem.