2026년 5월 APT 공격 동향 보고서(국내)
2026-06-29 • Ahnlab • May 2026 APT Attack Trend Report (Domestic) •
AhnLab observed May 2026 domestic APT activity in South Korea dominated by spear-phishing delivery, especially malicious LNK files and some CHM-based attacks. The infection chains used PowerShell, curl, HTA, VBS, BAT, XML, JS, AutoIt, Python, DLL side-loading, regsvr32, certutil, GitHub, and Google Drive to stage decoys, loaders, infostealers, keyloggers, XenoRAT-like malware, and backdoors. Several variants created scheduled tasks for persistence and supported command execution, directory listing, file upload/download, system information theft, and additional script execution from external C2 infrastructure. AhnLab published hashes, URLs, and domains tied to the observed activity and listed product detections for related backdoor, downloader, infostealer, LNK, JSE, VBS, Python, and XML-task components.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | update.nstlog.store | 2026-06-29 | 2026-06-29 |
| DOMAIN | univercity.library.boxathome.net | 2026-06-29 | 2026-06-29 |
| URL | https://drive.google.com/uc?exp… | 2026-06-29 | 2026-06-29 |
| URL | https://drive.google.com/uc?exp… | 2026-06-29 | 2026-06-29 |
| URL | https://aplore.kesug.com/repmay… | 2026-06-29 | 2026-06-29 |
| URL | http://newtech.dkcreatech.com:5… | 2026-06-29 | 2026-06-29 |
| HASH | 12391f66ee33d379108fd649a999e1a0 | 2026-06-29 | 2026-06-29 |
| HASH | 0d2e61c8a5e6280e065b61e75b848c68 | 2026-06-29 | 2026-06-29 |
| HASH | 090cfb95ce9ff312c501d7f43267f9ff | 2026-06-29 | 2026-06-29 |
| HASH | 0896485da9a470d504fbaad570b16358 | 2026-06-29 | 2026-06-29 |
| HASH | 076a8a0ae0c7d6270070b297c8617e2e | 2026-06-29 | 2026-06-29 |
| URL | https://aplore.kesug.com/riln.p… | 2026-05-26 | 2026-06-29 |