South Korean authorities have issued a joint advisory warning citizens and businesses about ongoing state-backed cyberattacks employing both phishing and watering hole techniques. The National Intelligence Service, National Police Agency, Korea Internet & Security Agency, and Financial Security Institute collaborated on the alert, which details how attackers are silently compromising systems.
The advisory describes two primary phishing methods. In one scenario, attackers pose as job applicants, sending emails with links to attacker-controlled blogs or GitHub pages instead of direct attachments. The second method involves impersonating legitimate recruiters, sometimes by hijacking their email accounts, and sending password-protected ZIP files labeled as job offers. These files contain malware that infects a machine upon opening.
More concerning for general users are the watering hole attacks. Threat actors are compromising legitimate and trusted websites, including news portals, hospital sites, and other platforms with weaker security, to serve as infection points. The danger lies in the fact that merely visiting these compromised sites can trigger an infection without any user interaction. This is achieved by exploiting unpatched vulnerabilities in security software commonly required for accessing Korean banking and government services. The malicious code operates silently in the background, with no visible prompts or warnings to the user.
This aligns with findings from a separate technical report by AhnLab, titled "Operation Double Barrel," which the joint advisory directly references. AhnLab documented 15 compromised Korean websites, including media outlets, hospitals, and manufacturers, between 2025 and mid-2026, all using this watering hole technique. The attackers exploited flaws in two specific pieces of Korean financial security software to inject backdoors into legitimate Microsoft processes. In one instance, the malicious code was observed to activate only when visitors used Naver's Whale browser, indicating a targeted approach.
Once a system is infected, attackers can siphon off saved browser passwords and manually entered credentials, extract documents and photos, and use the compromised computer as a pivot point to infect other devices on the same network. For businesses, the advisory specifically notes that stolen source code and customer data can be used for extortion, with threats of publication or distribution if demands are not met.
The recommended mitigations are straightforward. Individuals are advised to update all security software, particularly older electronic-signature and authentication tools, enable two-factor authentication, avoid saving passwords in browsers, and verify the legitimacy of any attachments or links from unfamiliar senders through official channels before opening them. Organizations are given a more extensive list of recommendations, including network segmentation for critical servers, mandatory multi-factor authentication, regular phishing awareness training, and immediate reporting of suspicious activity to the relevant authorities.






