Statistical Report on Phishing Email in Q4 2023

Statistical Report on Phishing Email in Q4 2023

Overview   AhnLab SEcurity intelligence Center (ASEC) monitors phishing email threats with the ASEC automatic sample analysis system (RAPIT) and honeypot. This post will cover the cases of distribution of phishing emails during the fourth quarter of 2023 (October, November, and December) and provide statistical information on each type. Generally,

Statistics Report on Malware Threat in Q4 2023

Statistics Report on Malware Threat in Q4 2023

Overview  AhnLab uses the automatic analysis system RAPIT to categorize and respond to malware collected through a variety of routes. This report categorizes and shares statistics on known malware among the ones collected during Q4 2023.  The malware included in the statistics are in the executable format. These were reported

2023 Dec. – Threat Trend Report on APT Groups

2023 Dec. – Threat Trend Report on APT Groups

The cases of major APT groups for December 2023 gathered from materials made public by security companies and institutions are as follows.   1) Andariel The Korean police announced that the Andariel group attacked 14 targets in Korea including companies in the defense industry, IT security companies, research centers, and

Trend Report on Smishing – Q4 2023 Statistics and Analysis on Smishing Threats

Trend Report on Smishing – Q4 2023 Statistics and Analysis on Smishing Threats

01. Overview AhnLab analyzes and responds to phishing messages detected based on machine-learning. This report provides an extensive analysis along with the statistics of smishing messages discovered during the fourth quarter of 2023. In the fourth quarter of 2023, there was an increase in specific types of attacks such as

Statistics Report on Malware Targeting  Windows Web Servers in Q4 2023

Statistics Report on Malware Targeting Windows Web Servers in Q4 2023

Overview   AhnLab SEcurity intelligence Center (ASEC) is using the AhnLab Smart Defense (ASD) infrastructure to respond to and categorize attacks against poorly managed Windows web servers. This report will cover the current state of damage to Windows web servers which have become the target of attacks based on the

2023 Dec. – Threat Trend Report on Kimsuky Group

2023 Dec. – Threat Trend Report on Kimsuky Group

Overview   The Kimsuky group’s activities in December 2023 showed an overall decrease in comparison to November, but phishing (ETC) domains increased by almost threefold with all the others showing a slight decrease.   Attack Statistics   Compared to November, the number of fully qualified domain names (FQDNs) decreased slightly

Statistics Report on Malware Targeting MS-SQL in Q4 2023

Statistics Report on Malware Targeting MS-SQL in Q4 2023

Overview   The ASEC analysis team uses the AhnLab Smart Defense (ASD) infrastructure to categorize and respond to attacks on vulnerable MS-SQL servers. This report will cover the current state of damage to MS-SQL servers which have become the target of attacks based on the logs discovered in Q4 2023,

2023 Dec. – Threat Trend Report on Ransomware Statistics and Major Issues

2023 Dec. – Threat Trend Report on Ransomware Statistics and Major Issues

This report provides statistics on the number of new ransomware samples, targeted systems, and targeted businesses in December 2023, as well as notable ransomware issues in Korea and other countries   Statistics   The total number of new ransomware samples collected during the past six months is as follows. Figure

Statistics Report on Malware Targeting Linux SSH Servers in Q4 2023

Statistics Report on Malware Targeting Linux SSH Servers in Q4 2023

Overview   AhnLab SEcurity intelligence Center (ASEC) conducts response and classification of brute force or dictionary attacks targeting poorly managed Linux SSH servers using honeypots. This report will cover the status of attack sources identified in the fourth quarter of 2023 based on logs, as well as statistics on attacks

Trend Analysis on Kimsuky Group’s Attacks Using AppleSeed

Trend Analysis on Kimsuky Group’s Attacks Using AppleSeed

Known to be supported by North Korea, the Kimsuky threat group has been active since 2013. At first, they attacked North Korea-related research institutes in South Korea before attacking a South Korean energy corporation in 2014. Since 2017, attacks targeting countries other than South Korea have also been observed. [1] The