logo

September 2025 APT Attack Trends Report (South Korea)

ID: 333a6753-3675-52f1-8bd5-a71df65fea39

STIX ID: report--333a6753-3675-52f1-8bd5-a71df65fea39

Feed Name: ASEC

Threat Score
75/100

Date Published: 2025-10-15

Date Updated: 2026-04-26

Author: ATCP

...
...

AhnLab observed and analyzed APT spear-phishing activity in South Korea (September 2025) that used malicious LNK files to extract bundled CAB archives and execute scripts which leak information and deploy additional malware, including RATs (XenoRAT, RoKRAT). The report includes confirmed malicious filenames, decoy documents, MD5 hashes, URLs and IP addresses as indicators of compromise, and describes two LNK-based delivery variants: one that extracts/decompresses and runs multiple scripts and another that deploys remote access trojans via cloud download or local persistence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.