Security News

Cybersecurity news aggregator

MEDIUM Attacks SC Media

South Korea warns of nation-state actors using phishing and compromised websites

  • What: Nation-state actors use phishing and compromised websites
  • Impact: Citizens and businesses in South Korea are targeted
Read Full Article →

Phishing South Korea warns of nation-state actors using phishing and compromised websites August 3, 2026 Share By SC Staff (Adobe Stock) As reported by Security Affairs, South Korea has issued a joint advisory from its National Intelligence Service, National Police Agency, Korea Internet & Security Agency, and Financial Security Institute, warning of a state-backed hacking group actively targeting citizens and businesses. The advisory highlights two primary attack vectors: phishing emails and watering hole attacks, emphasizing the minimal effort required from victims to be compromised. The phishing attacks involve disguised job applicants sending resumes with malicious links or impersonating recruiters with password-protected ZIP files containing malware. More concerning are the watering hole attacks, where threat actors compromise legitimate websites, including news portals and hospital sites, turning them into infection launch points. Visiting these sites alone can trigger an infection by exploiting unpatched vulnerabilities in existing security software without user interaction. This aligns with AhnLab's "Operation Double Barrel," which documented similar techniques across 15 compromised Korean websites between 2025 and mid-2026, targeting media, hospitals, and manufacturers. Attackers exploited flaws in Korean financial security software to inject backdoors. Once infected, systems risk credential theft, data exfiltration (documents, photos), and lateral movement within networks. For businesses, stolen source code and customer data are used for extortion. Recommended mitigations include updating all security software, enabling two-factor authentication, avoiding saving passwords in browsers, and verifying senders before opening links or attachments. Organizations are advised to implement network segmentation, mandatory multi-factor authentication, regular phishing training, and prompt reporting of suspicious activity. Source: Security Affairs SC Staff Related Phishing Fraud campaign impersonates Russian companies to steal funds SC Staff July 29, 2026 The attackers meticulously clone legitimate websites of Russian firms across various sectors, including manufacturing, logistics, and banking. Phishing Gen Z shows low cybersecurity awareness, Kaspersky study finds SC Staff July 29, 2026 A Kaspersky study of 7,200 respondents across 18 countries highlights that only 27% of Gen Z use mobile antivirus software, and a mere 28% regularly back up their phone data. Ransomware Steam forums used for ClickFix cryptominer attacks SC Staff July 27, 2026 In a report by Bleeping Computer, threat actors are exploiting Steam discussion forums to distribute cryptominers through a social engineering tactic known as ClickFix. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe You can skip this ad in 5 seconds

Share this article