Alert in South Korea: State-sponsored phishing and watering hole attacks infect without any click

South Korean agencies warn of state-sponsored zero-click watering hole and phishing attacks exploiting local software to steal data and extort victims.

Alert in South Korea: State-sponsored phishing and watering hole attacks infect without any click
APT

Illustrative image generated with AI

On July 31, 2026, South Korea’s main security agencies – the National Intelligence Service (NIS), the National Police, the Korea Internet & Security Agency (KISA), and the Financial Security Institute – issued a joint advisory on an active offensive campaign attributed to a state-backed hacker group.

The operation, detailed in AhnLab’s report “Operation Double Barrel,” combines two classic techniques made particularly insidious: targeted phishing and watering hole attacks. Between 2025 and mid-2026, at least 15 South Korean websites from critical sectors – media, healthcare, and manufacturing – were compromised to distribute malware in a completely transparent manner.

A silent entry: how the infection happens

In watering hole attacks, no victim interaction is required. The criminals targeted news portals, hospital websites, and industrial platforms with weak defenses, injecting malicious code. When the infected page loads, the browser automatically runs an exploit that leverages old vulnerabilities in local security software. No warnings or alerts appear; the infection is completely silent.

The phishing vector uses well-crafted emails: fake job applicants send resumes with links to blogs or GitHub repositories controlled by the attackers. Alternatively, real recruiter accounts are compromised to send password-protected ZIP files. Once the content is extracted, the malware takes control of the system.

A peculiar detail concerns the Naver Whale browser, used by many Korean users. In one specific case, payload activation was limited exclusively to visitors using that browser, indicating precise profiling and selective targeting.

Electronic signature and authentication software: the weak link

At the heart of the infection chain lie known but unpatched vulnerabilities in two widely used software products in South Korea: digital signature and authentication tools required for banking and government services. The names have not been disclosed, but AhnLab confirms they are applications installed on millions of private and corporate computers.

These programs, often outdated and updated irregularly, represent an ideal target. When a visitor reaches the compromised site, the code exploits a flaw in the security software to execute commands without any click. From that moment, modules for credential theft and local network reconnaissance are launched.

Stolen data and blackmail: consequences for citizens and businesses

The primary goal is information theft: browser-saved passwords, typed credentials, personal documents, and images. At the corporate level, the damage is amplified by the exfiltration of source code and customer databases. In several cases, the attackers then applied extortion tactics, threatening to publish or sell the stolen data.

The ability to move laterally inside a home or corporate network increases the severity: from a single infected endpoint, critical servers can be reached. Attribution to a state actor further raises concerns about the potential geopolitical exploitation of the stolen data.

How to defend: updates and strong authentication

The joint advisory provides specific countermeasures. For individual users:

  • Immediately update all security software, especially old electronic signature and authentication tools;
  • Do not save passwords in browsers and enable two-factor authentication on every supported service;
  • Always verify the sender’s identity and the legitimacy of links and attachments, contacting official channels before opening suspicious files.

For organizations, additional structural measures are recommended:

  • Segment the network to isolate servers containing sensitive data;
  • Mandate multi-factor authentication for access to corporate systems and applications;
  • Conduct regular anti-phishing training for employees;
  • Promptly report abnormal activities to the relevant government agencies.

The combination of interaction-free attacks and institutional vectors makes this campaign particularly dangerous. South Korea’s decision to issue a public alert aims to raise awareness and reduce the number of victims.

Read next

Sources

This article is an original reworking based on the sources below.

Back to home

Latest Cybersecurity News

All cybersecurity news →