April 2026 Security Issues in Korean & Global Financial Sector
ID: 7208443a-0e8d-5b17-a3da-068e629a267d
STIX ID: report--7208443a-0e8d-5b17-a3da-068e629a267d
Feed Name: ASEC
Threat Score
**Executive summary:** The report details coordinated malicious activity against the financial sector: phishing lures (Korean-language filenames) delivering backdoor/downloader/dropper and infostealer/ransomware families, credential exfiltration via Telegram, exploitation of an RCE in WGear (actively abused by Andariel using GeniexLoader linked to BlueNoroff/APT38), and numerous dark-web sales of breached customer data and access; several MD5 hashes for samples are provided as IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
