November 2024 Threat Trend Report on APT Attacks (South Korea)
ID: 543e4c2d-ef69-58c5-ae5e-f7192fd39291
STIX ID: report--543e4c2d-ef69-58c5-ae5e-f7192fd39291
Feed Name: ASEC
Threat Score
AhnLab's November 2024 APT report documents a surge of spear-phishing attacks in Korea using malicious .lnk files that invoke PowerShell to extract CAB archives and run multiple scripts or drop RATs (notably XenoRAT and RoKRAT), enabling information exfiltration and remote access. The report categorizes two main LNK-based delivery types, shows decoy filenames and screenshots, and lists IOCs (filenames, MD5 hashes, URLs, and IP addresses) observed during the campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
