June 2026 Threat Trend Report on APT Attacks (South Korea)

2026-07-23 Ahnlab

https://asec.ahnlab.com/en/94594

Thumbnail for June 2026 Threat Trend Report on APT Attacks (South Korea)

AhnLab's June 2026 monitoring found that APT attacks in South Korea predominantly began with work-themed spear phishing and malicious LNK files, and the source categorizes the activity under Kimsuky. The observed chains used PowerShell, AutoIt, curl, HTA files, scheduled tasks, GitHub or Google Drive payload delivery, DLL side-loading, and Python. Resulting payloads included information stealers, keyloggers, XenoRAT-type malware, and backdoors supporting command execution, file transfer, information theft, persistence, and remote control.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://kumhosports.com/inc/logq… 2026-07-23 2026-07-24
URL http://kumhosports.com/inc/logq… 2026-07-23 2026-07-24
URL http://kumhosports.com/inc/logq… 2026-07-23 2026-07-24
URL http://bohyeonsanvil.com/board/… 2026-07-23 2026-07-24
URL http://bohyeonsanvil.com/board/… 2026-07-23 2026-07-24
HASH 0b1de625a89da12bd1fdd292b341bad3 2026-07-23 2026-07-24
HASH 07ed2c9ed61b60078af0164f061696be 2026-07-23 2026-07-24
HASH 07bb21d28ae4ab07d62f8deb4343aaeb 2026-07-23 2026-07-24
HASH 05c07339603994b36dcfefcce720d03d 2026-07-23 2026-07-24
HASH 03e4bef86f3e3e6ea23eb6f017af0c98 2026-07-23 2026-07-24

Related Reports

« Back