2026년 4월 국내외 금융권 관련 보안 이슈

2026-05-21 Ahnlab April 2026 Domestic and International Financial Sector Security Issues

https://asec.ahnlab.com/ko/93804

Thumbnail for 2026년 4월 국내외 금융권 관련 보안 이슈

AhnLab's April 2026 financial-sector review links WGear RCE exploitation to DPRK-relevant activity, noting that Andariel has repeatedly abused the vulnerability. In observed cases, the WGear process launched mshta to retrieve external HTML, download and execute additional payloads, and ultimately install GeniexLoader. The report states that GeniexLoader is associated with BlueNoroff, also known as CryptoCore and APT38, connecting the activity to financially motivated North Korea-linked operations. The broader financial-sector telemetry also includes phishing attachments, fake login pages, Telegram-based credential exfiltration, ransomware leak claims, and access-broker listings that increase risk to banks and financial services.

Indicators of Compromise

Type Value First Seen Last Seen
HASH b15a55f9a23998b1976622bd3b9a3ad9 2026-05-21 2026-05-21
HASH 08f8a56c22282f5827674c65e75b15a… 2026-05-21 2026-05-21
HASH 3f40c4a2b816271dd9e0a284b3e55c5… 2026-05-21 2026-05-21
HASH dd48995359efa2f7642f520c8882e03… 2026-05-21 2026-05-21
HASH ea68c7b248722013dd3a61ad7a5039d… 2026-05-21 2026-05-21

Related Actors

First seen: Jul 2017
Last seen: Jun 2026

Related Reports

« Back