January 2025 Threat Trend Report on APT Attacks (South Korea)
ID: 749a8a85-ac62-51a4-80f8-80175b9d5fa7
STIX ID: report--749a8a85-ac62-51a4-80f8-80175b9d5fa7
Feed Name: ASEC
Threat Score
AhnLab observed and analyzed APT spear‑phishing attacks in South Korea during January 2025 that primarily used malicious LNK files to extract CAB archives containing obfuscated scripts and Python payloads; these attacks established persistence (Task Scheduler), performed information exfiltration and fetched additional malware. The report provides attack classification, example decoy files, confirmed file names, MD5 hashes, download URLs and IPs to support detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
