January 2026 Threat Trend Report on APT Attacks (South Korea)
ID: 4f172eab-56ff-52ad-ad80-39b45e37e00e
STIX ID: report--4f172eab-56ff-52ad-ad80-39b45e37e00e
Feed Name: ASEC
Threat Score
AhnLab observed APT campaigns targeting South Korea in January 2026 that primarily used spear-phishing LNK and HTA payloads to deploy AutoIt-based malware, infostealers, and backdoors; the report includes confirmed malicious filenames, MD5 hashes, and C2 URLs/IPs and notes persistence via scheduled tasks and use of curl (including a copied curl.exe) for payload retrieval.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
