…
Three of the world’s most active state-sponsored hacking programs — North Korea, Russia, and China — collectively carried out 158 documented cyberattack incidents in the first half of 2026, a 7.5% rise over the 147 recorded in the prior six months, according to the S2W TALON H1 2026 APT report published August 12 by South Korean cybersecurity intelligence firm S2W. The aggregate number, modest on its face, conceals three radically different strategic stories — and one counterintuitive finding that may be the most important for enterprise defenders: China’s 17.5% decline in attributed incidents does not reflect reduced threat. It reflects a backdoor that conventional firewalls and network scanners physically cannot detect.
…
No state matched North Korea’s volume. Pyongyang-linked groups were attributed 99 incidents over the six months — up 13.8% from 87 in the prior period, according to the same S2W report. South Korea absorbed 19 of those attacks, nearly double the eight recorded against the United States. Those are the headline numbers. The mechanism behind them is what should recalibrate how defenders think about social engineering.
…
Russia’s 30% surge is the steepest percentage increase among all three state actors and the finding most directly relevant to enterprise organizations with European operations. Russian-linked APT groups recorded 26 incidents in H1 2026, up from 20 in the prior period.
Ukraine remained the primary target, absorbing 10 of those 26 attacks as Moscow’s cyber operations continue to function as a force multiplier in the ongoing conflict. But the geographic footprint is expanding. Poland and Romania each recorded two confirmed Russian-attributed incidents — marking a systematic shift toward NATO’s eastern flank that mirrors the broader hybrid warfare escalation Russia has conducted against both countries.
…
China’s attribution count fell 17.5%, from 40 incidents in H2 2025 to 33 in H1 2026. That decline is not evidence of reduced threat. It is the product of a specific technical mechanism that makes Chinese APT activity structurally harder to detect than any other state actor’s operations.
The mechanism is BPFDoor. The backdoor — attributed to Chinese APT cluster Red Menshen (also tracked as Earth Bluecrow and DecisiveArchitect) — operates at the Linux kernel level, embedding itself into the Berkeley Packet Filter (BPF) subsystem, a decades-old networking feature originally designed for efficient traffic analysis. BPFDoor does not open any listening ports. It does not maintain an outbound connection to a command-and-control server. It does not register as a suspicious process in standard system monitoring. It remains completely dormant, passively inspecting incoming network traffic in kernel space — below the layer where firewalls and network scanners operate — until a specially crafted “magic packet” arrives.
…

