Skip to content
live markets
S&P 5007,785.76▲ 3.21%NASDAQ26,729.16▲ 2.38%DOW53,732.41▲ 2.33%GOLD4,437.30▲ 11.33%WTI82.40▲ 4.37%BRENT88.52▲ 5.09%EUR/USD1.1573▲ 1.66%USD/JPY159.31▼ 1.92%DXY99.64▼ 1.09%BTC$63,101▲ 0.10%ETH$1,884▲ 0.00%SOL$75.22▼ 0.30%TOTAL CRYPTO$2.25T▲ 0.04%
pulseofnations.
UTC --:--NYC --:--LON --:--WAW --:-- telegram ↗ bluesky ↗ Join the wire

State Cyber Threats From North Korea, China, Russia Up 7.5%

State-sponsored hacking incidents rose 7.5% in H1 2026 as North Korea led with 99 attacks, Russia surged 30%, and China shifted to stealthier long-term espionage.

Partner Surfshark VPN

State-sponsored cyberattacks from North Korea, China, and Russia increased by 7.5 percent in the first half of 2026, driven by a sharp surge in early-year activity from Pyongyang and Moscow, according to a new threat intelligence report.

Cybersecurity firm S2W documented 158 global Advanced Persistent Threat (APT) incidents between January and June, up from 147 in the preceding six months. The escalation was overwhelmingly concentrated in the first quarter, reflecting intensified digital offensives across Asia, Europe, and the Middle East.

North Korea Leads With 99 Incidents

North Korea remained the world’s most active state-backed threat actor, accounting for 99 incidents, a 13.8 percent jump from the previous six-month period. Pyongyang disproportionately targeted South Korea with 19 recorded attacks, followed by eight against the United States.

To breach defenses, North Korean actors increasingly weaponized cutting-edge tools, leveraging generative artificial intelligence, deepfakes, compromised code repositories, and fraudulent job recruitment schemes. These sophisticated tactics focused heavily on infiltrating cryptocurrency markets, IT service providers, and software development ecosystems.

Russia Surges, China Goes Stealth

Russian-backed cyberoperations surged 30 percent to 26 incidents, widening their geographic footprint beyond Ukraine. While Ukraine absorbed 10 attacks, Kremlin-linked operatives expanded into Eastern European nations like Poland and Romania. Moscow blended traditional intelligence gathering with destructive, operational-disruption attacks designed to cripple energy grids, government networks, and military systems.

In contrast, Chinese state-sponsored activity declined 17.5 percent to 33 incidents. Rather than scaling back, Beijing-linked groups shifted toward stealthy, long-term espionage. Chinese actors maintained a relentless focus on the telecommunications sector while expanding operations into Southeast Asia and the Middle East, extensively exploiting legitimate cloud APIs, virtual private networks, and edge network devices.

“Threats to software supply chains, critical infrastructure and developer ecosystems will likely intensify through the second half of the year,” S2W analysts warned.

Across all three regimes, common intrusion vectors included phishing campaigns, unpatched public server vulnerabilities, and the abuse of proxy networks and cloud services. Analysts strongly advise organizations to move beyond basic email filtering toward comprehensive, zero-trust security frameworks that safeguard cloud infrastructure, open-source repositories, and AI integration platforms.

Sources: Korea Times; S2W threat intelligence report; SBS News

React to this dispatch
Share this dispatch Telegram X WhatsApp Report an error

discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Next dispatch Qilin Ransomware Claims 104 Victims in August, Tops Global List Read →