logo

October 2025 APT Attack Trends Report (South Korea)

ID: 4b161304-de9c-5474-bd8d-3593e4b60014

STIX ID: report--4b161304-de9c-5474-bd8d-3593e4b60014

Feed Name: ASEC

Threat Score
86/100

Date Published: 2025-11-13

Date Updated: 2026-04-26

Author: ATCP

...
...

**Executive summary:** AhnLab identified multiple APT spear‑phishing campaigns in South Korea in October 2025 that primarily used malicious LNK attachments and AutoIt loaders to retrieve and execute RATs (notably XenoRAT and RoKRAT); the report provides attack TTPs (PowerShell-based execution, use of Dropbox/Google Drive and renamed curl.exe, scheduled-task persistence), sample decoy filenames, MD5 hashes and download URLs, indicating active targeted data-collection operations (keylogging, screenshots, file upload/download).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.