2026년 8월 APT 그룹 동향 보고서
2026-09-18 • Ahnlab • August 2026 APT Group Trends Report •
North Korea-linked actors focused on developers, software supply chains, remote hiring, and defense targets during August 2026. Famous Chollima continued PolinRider supply-chain activity and used Ethereum for covert command and control, while Jasper Sleet sought internal access through AI-generated identities and remote-job scams. Kimsuky employed AI-generated decoys and Git-based command and control. Lazarus used a malicious PDF viewer and the then-undisclosed CVE-2026-68820 zero-day against defense-sector targets in Operation Dream Job.
Related Actors
Related Reports
2026-09-18 •
90% Match
#Trend
#DreamJob
#Kimsuky
#Lazarus
#FamousChollima
#JasperSleet
#PolinRider
#CVE-2026-68820
Shares tags: Trend, DreamJob, Kimsuky • Same author: Ahnlab • Published within a week
2026-09-07 •
55% Match
#APT38
#Andariel
#Kimsuky
#CryptoCore
#TEMP.Hermit
#JadeSleet
#CitrineSleet
#ITWorker
#MoonstoneSleet
#Lazarus
#FamousChollima
Shares tags: Kimsuky, Lazarus, FamousChollima • Published within a month
2026-09-02 •
55% Match
#Kimsuky
#Phishing
#LNK
#T1082
#T1070.004
#T1057
#T1566.001
#T1053.005
#T1059.001
Shares tag: Kimsuky • Same author: Ahnlab • Published within a month
2026-09-02 •
55% Match
#Kimsuky
#Phishing
#LNK
#T1082
#T1070.004
#T1057
#T1566.001
#T1053.005
#T1059.001
Shares tag: Kimsuky • Same author: Ahnlab • Published within a month
Shares tags: Trend, Kimsuky, Lazarus • Same author: Ahnlab
Shares tags: Trend, Kimsuky, Lazarus • Same author: Ahnlab