
Targeting the cryptocurrency and IT ecosystem through fake recruitment and open source infiltration
In the first half of this year, the number of cyber attacks by hacking organizations behind countries such as North Korea, China, and Russia increased to 158, and it was found that most attacks from North Korea targeted South Korea.
AI-generated summary
Based on the contents of the ‘State-backed Advanced Persistent Threat (APT) Group Threat Trend Report for the first half of 2026’ published by S2W.
99 attacks from North Korea... Korea ranks first with 19 targets by country
Targeting the cryptocurrency and IT ecosystem through fake recruitment and open source infiltration
(Seoul = Yonhap News) Reporter Oh Ji-eun = In the first half of this year, there were 158 cyber attacks by hacking organizations behind countries such as North Korea, China, and Russia, a 7.5% increase from the second half of the previous year.
In particular, it was analyzed that North Korea's behind-the-scenes attacks most often targeted South Korea, and that they expanded the scope of the attack to include cryptocurrency, information technology (IT), and the software development ecosystem by using generative artificial intelligence (AI), deep fakes, and fake recruitment.
Russia has strengthened its destructive attacks targeting infrastructure, especially in Ukraine, while China has focused on intelligence attacks that collect information by infiltrating the telecommunications sector for a long period of time.
◇ North Korea intensively attacks South Korea… Abuse of AI, deepfakes, and even fake recruitment
According to the 'State-backed Advanced Persistent Threat (APT) Group Threat Trend Report for the first half of 2026' published by S2W [488280] (S2W) on the 16th, a total of 158 APT attacks from North Korea, China, and Russia were recorded from January to June of this year.
This is an increase of 11 cases (7.5%) from the 147 cases in the second half of last year, and the increase mainly occurred in the first quarter when attacks from North Korea and Russia were concentrated.
By country, issues related to the organization behind North Korea accounted for the most with 99 cases, followed by China with 33 cases and Russia with 26 cases.
In particular, threats linked to North Korea increased by 13.8% compared to the previous half-year.
North Korea targeted the cryptocurrency, information technology (IT), and software industries and developers and actively used fake recruitment, code repositories, open source infiltration, generative artificial intelligence (AI), and deepfake (technology that manipulates or synthesizes people's faces, voices, and actions using artificial intelligence).
In terms of the number of targets by country by North Korea, South Korea ranked first with 19, followed by the United States with 8.
The activities of the Russian organization increased by 30%, from 20 to 26.
Russia continued its attacks centered on Ukraine (10 cases) and attacked Eastern Europe, Poland, and Romania twice each, expanding the target of hacking to include European governments and military organizations.
They showed a tendency to carry out destructive attacks aimed at not only collecting information but also destroying systems and disrupting operations.
◇ China focuses on ‘long-term intelligence’… Attacks on development ecosystem and infrastructure expected to continue
Chinese-backed attacks decreased by 17.5% from 40 to 33. The Chinese group maintained its existing communications sector attacks and expanded its scope to Southeast Asia (8 cases) and the Middle East (4 cases).
It is characterized by a focus on long-term intelligence collection using normal cloud application program interfaces (APIs), virtual private networks (VPNs), network tunnels, and malware.
As a result of S2W's vulnerability analysis, in the first half of the year, the three countries exploited 15 unique CVEs (security vulnerabilities) 19 times.
North Korea mainly used social engineering techniques and user execution guidance, China mainly targeted vulnerabilities in public servers and perimeter network equipment, and Russia mainly targeted document-type malware, webmail, and network equipment vulnerabilities.
Phishing, exploitation of public server vulnerabilities, and abuse of proxy and cloud services were identified as common attack techniques in the three countries.
The report predicts that sabotage combined with infiltration of development ecosystems, long-term access to communications and infrastructure, and geopolitical conflicts will continue in the second half of the year.
In addition, he urged that close observation is necessary as Iran's behind-the-scenes and linked forces can cause indirect damage to domestic manufacturing, aviation, and energy companies through the Middle East region and supply chain.
A security expert advised, "We need to break away from piecemeal responses that focus on blocking emails and malware and establish an integrated defense system that covers the development environment, supply chain, Internet-exposed assets, cloud, and AI environment," and added, "It is urgent to strengthen intrusion detection capabilities, immediately replace account credentials, and establish an immutable backup and recovery system."
AI outlook — possibilities, not facts
Penetrating development ecosystems and sustaining long-term access to infrastructure
Likely · Within months

South Korean entertainment tech startup Galaxy Corp. officially opened the 16,500-square-meter Galaxy Robot Park in Seoul on Friday, featuring AI humanoid robots performing K-pop songs and interactive robot exhibits.

Galaxy Corp. has officially opened a 16,500-square-meter robot-themed park in Seoul. The venue features AI-powered humanoid robots performing K-pop dances and taekwondo, alongside interactive zones, following a successful pre-opening period with 20,000 visitors.
중국이 주췌-3호 야오-2 운반로켓의 1단 추진체를 지상에 수직 착륙시키는 방식으로 회수하는 데 성공했습니다. 이는 중국의 재사용 로켓 기술 확보를 위한 중요한 진전으로 평가됩니다.

Madison Huang, a senior director at Nvidia and daughter of CEO Jensen Huang, visited LG Electronics' robotics hub in Seoul on Tuesday to discuss expanding their partnership in AI infrastructure and humanoid robotics.

중국 베이징에 문을 연 징둥닷컴 계열의 24시간 무인 로봇카페가 1시간 동안 커피 202잔을 제조해 기네스 세계기록을 달성했다.

일본 혼다가 자동차 안전 기술 개발에 인공지능을 활용해 개발 기간을 40% 단축하겠다는 목표를 세웠다. 중국 자동차 업체의 신차 개발 속도에 대응하기 위한 조처로, 2030년께 신차 출시를 목표로 한다.