August 2026 Threat Trend Report on APT Attacks (South Korea)

August 2026 Threat Trend Report on APT Attacks (South Korea)

Overview


AhnLab monitored APT (Advanced Persistent Threat) attacks targeting entities in Korea using its own infrastructure. This report summarizes the types and statistics on domestic APT attacks identified during the month of August 2026.

Trends of APT Attacks in South Korea


Most of the APT attacks detected in South Korea were distributed via spear phishing (a form of phishing targeting specific individuals or groups). In particular, attacks utilizing LNK files accounted for the highest proportion in August 2026.

  • Type A involves a PowerShell script embedded within a LNK file that extracts HEX data to restore and execute a legitimate decoy file, a legitimate AutoIt program, and a malicious AutoIt script file. It executes the malicious script in the C:\ProgramData Path and registers a Task Scheduler entry that is disguised as a OneDrive update. It then receives commands through a PubNub channel and exfiltrates the results by encoding them in Base64.
  • Type B uses curl.Exe, a native Windows tool, to download and execute a malicious HTA file in %TEMP%. It is distributed through GitHub repositories or Google Drive and creates a decoy file and a downloader named sys.Dll. This downloader loads Infostealers, keyloggers, and backdoors into memory, which exfiltrate system information, lists of important files, and information related to virtual assets.
  • Type C uses PowerShell code embedded in an LNK file to generate and execute Base64-encoded data in %temp%, then downloads and executes a decoy file and additional malicious scripts from a GitHub repository. It also creates a Task Scheduler task to exfiltrate system information and distribute XenoRAT-type malware.
  • Type D involves an LNK file that is disguised as a resume or document file and contains a legitimate decoy file and malicious PowerShell commands. Upon execution, it creates VBS, BAT, and PowerShell scripts, registers them with the Task Scheduler, and downloads additional files from external URLs. It then executes a loader via DLL side-loading (a method where a legitimate program loads a malicious DLL alongside itself) to inject backdoor malware into legitimate processes.
  • Type E uses CMD and PowerShell commands within the LNK file to download additional files. It copies curl.Exe to %TEMP% and then executes a decoy PDF and a BAT downloader. The BAT file installs a Python package, disguises pythonw.Exe, and registers it in the Task Scheduler; ultimately, the Python backdoor performs command execution on the threat actor’s server and transmits the results.
  • Type Unknown refers to cases distributed via spear phishing that do not fall under the preceding types.
  • Type F involves embedding an OLE object within a Hangul (hwp) document and prompting the user to execute it through a link to an Attachment within the document. The object file is created in %TEMP%; when the link is opened, a legitimate tool runs while the malicious version.Dll file in the same path is loaded via DLL side-loading. Subsequently, a BAT script and a PowerShell backdoor are executed.

AhnLab Response Overview


The AhnLab product suite detected these threats under various detection names, including Backdoor/Python.Agent, Downloader/BAT.Agent, Dropper/LNK.Generic, Trojan/LNK.Agent, Trojan/PowerShell.Agent, Trojan/VBS.Agent, and Trojan/HWP.Agent. However, AhnLab noted that untracked variants may not be detected.

Conclusion


Targeted APT attacks often begin with phishing emails designed to pique the user’s interest, such as those containing work-related content. The malware used for distribution is disguised as legitimate files in various formats, such as executable files and shortcut files. Once executed, it can lead to information leakage via backdoors and Infostealers, the hijacking of System Control over infected systems, and the uploading of additional malware. Users should refrain from opening files from unknown sources, verify the sender’s identity, check for vulnerable system settings, apply patches to their operating systems and web browsers, and ensure V3 is updated to the latest version.

MD5

0099bf67cfa72030c1c317240441f3b8
01e099f0947d0ef7bcb967063d761fa6
02f87ffe09edad431746660b310956c5
03be987cd4c4e1e788f803ca6e464a29
06b3b6fbf106d46534459d2189aac739
URL

http[:]//www[.]cwmodern[.]com/include/inc/_src/contents[.]php
http[:]//www[.]cwmodern[.]com/include/inc/_src/contents[.]php?bbs=17
http[:]//www[.]cwmodern[.]com/include/inc/_src/contents[.]php?contents=bk6EJpIGNzp1Ez9sO&board=0MLCHR8dbWwo8VO08axcBSqQ8R3nABdv
http[:]//www[.]dolgicap[.]com/bbs/data/gongi/boardquery[.]php?query=lHg8pVCYNQ8HT8JP0aDgQ&number=PlI2C9VDvYsEQxf7t9Di7cHAjUnHtPFQGqV
https[:]//dpaper[.]dothome[.]co[.]kr/choijaa/?nonce=xPDi&fpt=WXNwam5PSnUwN3hpZkw0eQ==&fsz=39936