April 2026 Threat Trend Report on APT Attacks (South Korea)
ID: e71271ef-847b-5885-86ba-a5b3cc98ec48
STIX ID: report--e71271ef-847b-5885-86ba-a5b3cc98ec48
Feed Name: ASEC
ahnLab observed an APT campaign in Korea (April 2026) that used spear-phishing to distribute LNK-embedded PowerShell/HEX loaders, curl-based downloaders, AutoIt scripts, HTA loaders, VBS/BAT/Python backdoors and infostealers. Attackers achieved persistence via Task Scheduler, used PubNub and GitHub/Drive-hosted artifacts for C2 and payload delivery, and exfiltrated system and credential-related data; the report lists MD5 hashes, malicious URLs, detection names, and recommends patching and caution with email attachments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
