North Korea leverages AI and deepfakes to lead global state-sponsored cyberattacks

North Korean hackers integrate artificial intelligence to automate cyberattacks

North Korean state-sponsored cyber units launched 99 cyberattacks in the first half of 2026, positioning Pyongyang as the most active state-backed threat actor globally. South Korea absorbed the highest proportion of these strikes with 19 incidents, followed by the United States with eight. The total volume of North Korean operations rose by 13.8 percent compared to the previous six months, outpacing campaign numbers from both China and Russia.

Pyongyang-linked operators focused primarily on cryptocurrency, IT, and software development sectors by integrating generative AI, deepfakes, fake job postings, and code repository infiltrations to secure unauthorized network entry. According to The Defence Blog, state-aligned actors increasingly rely on malicious LNK and CHM file attachments to deploy backdoors and infostealers. While Chinese groups emphasized edge-device vulnerability exploitation and Russian actors expanded destructive operations across Eastern Europe, North Korean units centered their operational strategy on AI-enhanced social engineering.

Industry analysts emphasize that defending against evolving state-sponsored vectors requires shifting from fragmented email security toward integrated frameworks covering cloud platforms, development environments, and supply chains. Modern counter-intrusion protocols mandate real-time anomaly detection, rapid credential rotation, and immutable backup systems to mitigate long-term network exploitation.