2026년 6월 APT 공격 동향 보고서(국내)

2026-07-23 Ahnlab June 2026 APT Attack Trends Report (South Korea)

https://asec.ahnlab.com/ko/94593

Thumbnail for 2026년 6월 APT 공격 동향 보고서(국내)

AhnLab observed June 2026 domestic APT activity delivered primarily through spear-phishing emails and malicious LNK files, and the source categorizes the analysis under Kimsuky. The documented chains used PowerShell, AutoIt, HTA files, GitHub-hosted payloads, scheduled tasks, DLL side-loading, and malicious Python components to establish persistence. Final payloads included XenoRAT, information stealers, keyloggers, and backdoors capable of executing commands, transferring files, collecting system information, and controlling infected hosts.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://kumhosports.com/inc/logq… 2026-07-23 2026-07-24
URL http://kumhosports.com/inc/logq… 2026-07-23 2026-07-24
URL http://kumhosports.com/inc/logq… 2026-07-23 2026-07-24
URL http://bohyeonsanvil.com/board/… 2026-07-23 2026-07-24
URL http://bohyeonsanvil.com/board/… 2026-07-23 2026-07-24
HASH 0b1de625a89da12bd1fdd292b341bad3 2026-07-23 2026-07-24
HASH 07ed2c9ed61b60078af0164f061696be 2026-07-23 2026-07-24
HASH 07bb21d28ae4ab07d62f8deb4343aaeb 2026-07-23 2026-07-24
HASH 05c07339603994b36dcfefcce720d03d 2026-07-23 2026-07-24
HASH 03e4bef86f3e3e6ea23eb6f017af0c98 2026-07-23 2026-07-24

Related Reports

« Back