February 2025 APT Group Trends (South Korea)
ID: f0f9f8af-fbea-5745-8c4b-dcd3fad5ab54
STIX ID: report--f0f9f8af-fbea-5745-8c4b-dcd3fad5ab54
Feed Name: ASEC
Threat Score
AhnLab observed multiple APT-style spear-phishing campaigns in South Korea during February 2025 that delivered malicious LNK files. The LNKs unpack CAB archives and execute obfuscated PowerShell, batch, VBS, or Python components (including a pythonw.exe+malicious script registered as a scheduled task) to exfiltrate information and fetch additional malware; the report lists sample filenames, MD5 hashes, and command-and-control/download URLs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
