logo

December 2025 APT Attack Trend Report (South Korea)

ID: f95dc7d0-4887-5860-9939-5b16a12b6682

STIX ID: report--f95dc7d0-4887-5860-9939-5b16a12b6682

Feed Name: ASEC

Threat Score
85/100

Date Published: 2026-01-13

Date Updated: 2026-04-26

Author: ATCP

...
...

AhnLab monitored multiple APT campaigns targeting South Korea in December 2025, reporting spear-phishing with malicious LNK attachments as the dominant vector. The report identifies two LNK-based types: one delivering RATs (confirmed XenoRAT and RoKRAT) via PowerShell and cloud downloads, and another dropping AutoIt-based payloads by copying curl.exe, registering Task Scheduler jobs for persistence; sample filenames, MD5 hashes and malicious URLs are provided as IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.