logo

December 2024 Threat Trend Report on APT Attacks (South Korea)

ID: c8367f38-6190-530c-9f89-afe82b7d7e66

STIX ID: report--c8367f38-6190-530c-9f89-afe82b7d7e66

Feed Name: ASEC

Threat Score
78/100

Date Published: 2025-01-07

Date Updated: 2026-04-26

Author: ATCP

...
...

AhnLab reports that December 2024 APT activity targeting Korean entities primarily used spear-phishing with malicious LNK files to deploy multi-stage payloads: Type A extracted CAB archives containing scripts for data exfiltration and payload download, while Type B deployed RATs (e.g., XenoRAT, RoKRAT) via PowerShell and cloud-hosted binaries; the report includes sample decoy files, confirmed filenames, MD5 hashes and malicious URLs as IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.