August 2026 Threat Trend Report on APT Attacks (South Korea)
Overview
AhnLab monitored APT (Advanced Persistent Threat) attacks targeting entities in Korea using its own infrastructure. This report summarizes the types and statistics on domestic APT attacks identified during the month of August 2026.
Trends of APT Attacks in South Korea
Most of the APT attacks detected in South Korea were distributed via spear phishing (a form of phishing targeting specific individuals or groups). In particular, attacks utilizing LNK files accounted for the highest proportion in August 2026.
- Type A involves a PowerShell script embedded within a LNK file that extracts HEX data to restore and execute a legitimate decoy file, a legitimate AutoIt program, and a malicious AutoIt script file. It executes the malicious script in the
C:\ProgramDataPath and registers a Task Scheduler entry that is disguised as a OneDrive update. It then receives commands through a PubNub channel and exfiltrates the results by encoding them in Base64. - Type B uses curl.Exe, a native Windows tool, to download and execute a malicious HTA file in
%TEMP%. It is distributed through GitHub repositories or Google Drive and creates a decoy file and a downloader namedsys.Dll. This downloader loads Infostealers, keyloggers, and backdoors into memory, which exfiltrate system information, lists of important files, and information related to virtual assets. - Type C uses PowerShell code embedded in an LNK file to generate and execute Base64-encoded data in
%temp%, then downloads and executes a decoy file and additional malicious scripts from a GitHub repository. It also creates a Task Scheduler task to exfiltrate system information and distribute XenoRAT-type malware. - Type D involves an LNK file that is disguised as a resume or document file and contains a legitimate decoy file and malicious PowerShell commands. Upon execution, it creates VBS, BAT, and PowerShell scripts, registers them with the Task Scheduler, and downloads additional files from external URLs. It then executes a loader via DLL side-loading (a method where a legitimate program loads a malicious DLL alongside itself) to inject backdoor malware into legitimate processes.
- Type E uses CMD and PowerShell commands within the LNK file to download additional files. It copies
curl.Exeto %TEMP% and then executes a decoy PDF and a BAT downloader. The BAT file installs a Python package, disguisespythonw.Exe, and registers it in the Task Scheduler; ultimately, the Python backdoor performs command execution on the threat actor’s server and transmits the results. - Type Unknown refers to cases distributed via spear phishing that do not fall under the preceding types.
- Type F involves embedding an OLE object within a Hangul (hwp) document and prompting the user to execute it through a link to an Attachment within the document. The object file is created in
%TEMP%; when the link is opened, a legitimate tool runs while the maliciousversion.Dllfile in the same path is loaded via DLL side-loading. Subsequently, a BAT script and a PowerShell backdoor are executed.
AhnLab Response Overview
The AhnLab product suite detected these threats under various detection names, including Backdoor/Python.Agent, Downloader/BAT.Agent, Dropper/LNK.Generic, Trojan/LNK.Agent, Trojan/PowerShell.Agent, Trojan/VBS.Agent, and Trojan/HWP.Agent. However, AhnLab noted that untracked variants may not be detected.
Conclusion
Targeted APT attacks often begin with phishing emails designed to pique the user’s interest, such as those containing work-related content. The malware used for distribution is disguised as legitimate files in various formats, such as executable files and shortcut files. Once executed, it can lead to information leakage via backdoors and Infostealers, the hijacking of System Control over infected systems, and the uploading of additional malware. Users should refrain from opening files from unknown sources, verify the sender’s identity, check for vulnerable system settings, apply patches to their operating systems and web browsers, and ensure V3 is updated to the latest version.