logo

February 2026 APT Attack Trends Report (South Korea)

ID: ffdb07f7-472d-596b-b826-02d7b3474341

STIX ID: report--ffdb07f7-472d-596b-b826-02d7b3474341

Feed Name: ASEC

Threat Score
78/100

Date Published: 2026-03-18

Date Updated: 2026-05-12

Author: ATCP

...
...

AhnLab observed a February 2026 domestic APT campaign that primarily used spear‑phishing LNK/CHM attachments to execute PowerShell or curl-based downloaders which retrieve malicious HTA/AutoIt payloads. The actors established persistence via Task Scheduler, deployed Infostealers, keyloggers, and a memory-resident backdoor to exfiltrate system and cryptocurrency-related data; the report includes sample filenames, MD5 hashes, URLs, and IP indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.