November 2025 APT Attack Trends Report (South Korea)
ID: 976d74b4-77b0-518c-9a86-3b6ada4e24bd
STIX ID: report--976d74b4-77b0-518c-9a86-3b6ada4e24bd
Feed Name: ASEC
Threat Score
AhnLab monitored and classified APT attacks in South Korea during November 2025, finding that spear-phishing with malicious LNK attachments was the predominant delivery method; attackers used PowerShell to fetch payloads (including XenoRAT and RoKRAT) and AutoIt-based malware, established persistence via scheduled tasks, and employed decoy documents. The report catalogs confirmed filenames, MD5 hashes, and malicious URLs and characterizes the attack types and their behaviors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
