State-Sponsored Cyber Operations in East Asia: A 2026 Assessment
An analysis of recent state-sponsored cyber activities in East Asia, focusing on Chinese and North Korean operations targeting critical infrastructure and geopolitical interests.
Executive Takeaway — TL;DR
- Category:
- State Cyber Warfare
- Severity:
- High
- Actor Type:
- Cybercriminal
- Geography:
- East Asia
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
As of April 2026, East Asia remains a focal point for state-sponsored cyber operations, with China and North Korea continuing to employ cyber capabilities to advance their geopolitical and strategic objectives.
Chinese Cyber Operations
China has been implicated in a series of cyber espionage campaigns targeting critical sectors across East Asia. Notably, the Chinese state-sponsored group known as Lotus Blossom (also referred to as APT31) has been active since at least 2012, conducting cyber-espionage campaigns against key Chinese units and departments such as government, national defense, science and technology, education, and maritime agencies. These operations have primarily focused on the defense industry, particularly concerning strategic issues such as Chinese-US relations, Cross-Strait relations, and maritime-related issues. (cds.thalesgroup.com)
In June 2025, a significant supply chain attack was attributed to Chinese state-sponsored actors. The campaign involved the interception and redirection of update traffic from the official notepad-plus-plus.org domain to attacker-controlled servers. This operation demonstrated highly selective targeting, primarily against organizations in the telecommunications and financial sectors across East Asia, as well as government entities in the Philippines and Vietnam. (en.wikipedia.org)
North Korean Cyber Operations
North Korea's cyber activities have also been a significant concern. The group known as APT34 has been linked to cyber espionage campaigns targeting government entities, chemical, energy, financial, and telecommunications sectors in the Middle East, Europe, North America, and parts of Asia. These campaigns are characterized by long-term access and data collection rather than short-term disruptions. (asisonline.org)
In February 2026, Group-IB disclosed "Operation Olalampo," attributed to North Korean state-sponsored group MuddyWater. The campaign targeted multiple organizations and individuals primarily in the Middle East and North Africa, utilizing new malware families, including CHAR, GhostFetch, HTTP_VIP, and GhostBackDoor. One variant communicated through a Telegram bot used for command and control. (en.wikipedia.org)
Implications for East Asia
The persistence and sophistication of state-sponsored cyber operations in East Asia underscore the region's critical need for enhanced cybersecurity measures. The targeting of critical infrastructure, including telecommunications and financial sectors, poses significant risks to national security and economic stability. The geopolitical tensions in the region further complicate the cyber threat landscape, as state-sponsored actors leverage cyber capabilities to advance strategic interests.
In response, nations within East Asia are increasingly prioritizing cyber defense initiatives. For instance, South Korea's Cyber Operations Command has initiated the deployment of AI-based defense platforms, though officials acknowledge that gaps in cyber infrastructure and workforce readiness still hinder full-scale mitigation. (cyberproof.com)
In conclusion, the state-sponsored cyber threat landscape in East Asia as of April 2026 is characterized by persistent and evolving activities from China and North Korea. These operations target critical infrastructure and exploit geopolitical tensions, necessitating a coordinated and robust response to safeguard regional security and stability.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

China-Aligned APTs Pivot to AI and Robotics Espionage in South Korea and Gulf States

China-Aligned APTs Intensify Strategic Espionage Targeting AI Robotics and Maritime Infrastructure

