South Korea agencies (The National Intelligence Service, the National Police Agency, the Korea Internet & Security Agency, and the Financial Security Institute) jointly published an advisory warning that a state-backed hacking group is actively targeting South Korean citizens and businesses. The warning names two attack techniques: phishing emails and watering hole attacks, and it doesn’t sugarcoat how little a victim has to do wrong.
The phishing side runs on two tricks. In one version, attackers disguise themselves as job applicants and send a resume email with a link instead of an attachment, pointing to a blog or GitHub page the attacker controls. In the other, they impersonate an actual recruiter, sometimes hijacking a real headhunter’s email account, and attach a password-protected ZIP file labeled as a job offer that infects the machine the moment it’s opened.
The watering hole method is the part that should worry ordinary readers more. Attackers compromise legitimate sites people already trust, news portals and hospital websites among them, along with smaller sites that simply have weak security, and use them as launch points. As the advisory puts it, the danger is that “visiting the site alone can be enough to trigger an infection.”
That’s possible because the malicious code doesn’t rely on tricking the user into clicking “install.” It pairs the compromised website with an old, unpatched vulnerability sitting in security software already installed on the visitor’s PC, the kind of software Korean banking and government sites require. No prompt appears, no warning shows up, the page looks completely normal, and the infection happens silently in the background.
This lines up closely with what AhnLab documented separately in its own technical report, Operation Double Barrel, which the advisory cites directly as a reference. AhnLab traced the same watering hole technique across 15 compromised Korean websites between 2025 and mid-2026, hitting media outlets, hospitals, and manufacturers, and found the attackers exploiting flaws in two specific pieces of Korean financial security software to inject backdoors into legitimate Microsoft processes. In one especially odd case, the malicious code only activated when visitors used Naver’s Whale browser, a level of targeting precision that suggests real reconnaissance rather than a scattergun approach.
Once infected, the advisory lists what’s actually at stake, and it’s not a short list. Saved browser passwords and manually typed credentials get siphoned off, documents and photos get pulled from the machine, and infected computers become a stepping stone to infect every other device on the same office or home network. For businesses specifically, the advisory adds that stolen source code and customer data become leverage: “pay up, or we publish and distribute the data.”
None of the fixes here are exotic. The advisory tells individuals to update every piece of security software, especially old electronic-signature and authentication tools that rarely get touched after installation, turn on two-factor authentication, stop saving passwords in the browser, and never open an attachment or link from an unfamiliar sender without verifying it through an official channel first. Organizations get a longer list: network segmentation for critical servers, mandatory multi-factor authentication instead of shared default passwords, regular phishing-awareness training, and immediate reporting to the relevant agency the moment something looks off.
It’s a strange kind of milestone when a national intelligence service has to remind an entire country that clicking a news headline isn’t automatically safe anymore. But that’s effectively where things stand: the browser tab you already trust might be doing more than loading a page.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, South Korea)