logo

November 2025 APT Attack Trends Report (South Korea)

ID: 976d74b4-77b0-518c-9a86-3b6ada4e24bd

STIX ID: report--976d74b4-77b0-518c-9a86-3b6ada4e24bd

Feed Name: ASEC

Threat Score
75/100

Date Published: 2025-12-11

Date Updated: 2026-04-26

Author: ATCP

...
...

AhnLab monitored and classified APT attacks in South Korea during November 2025, finding that spear-phishing with malicious LNK attachments was the predominant delivery method; attackers used PowerShell to fetch payloads (including XenoRAT and RoKRAT) and AutoIt-based malware, established persistence via scheduled tasks, and employed decoy documents. The report catalogs confirmed filenames, MD5 hashes, and malicious URLs and characterizes the attack types and their behaviors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.