XwormRAT Being Distributed Using Steganography

XwormRAT Being Distributed Using Steganography

AhnLab SEcurity intelligence Center (ASEC) collects information on malware distributed through phishing emails by using its own “email honeypot system.” Based on this information, ASEC publishes the “Phishing Email Trend Report” and “Infostealer Trend Report” on the ASEC Blog every month. Recently, XwormRAT has been confirmed to be distributed using

May 2025 Infostealer Trend Report

May 2025 Infostealer Trend Report

This report provides statistics, trends, and case information on the distribution of Infostealer malware, including the distribution volume, methods, and disguises, based on the data collected and analyzed in May 2025. The following is a summary of the report.   1) Data Source and Collection Method   AhnLab SEcurity intelligence

April 2025 Infostealer Trend Report

April 2025 Infostealer Trend Report

This report provides statistics, trends, and case information on the distribution of Infostealer malware, including the distribution volume, methods, and disguises, based on the data collected and analyzed in April 2025. The following is a summary of the report.   1) Data Source and Collection Method   The AhnLab SEcurity

March 2025 Infostealer Trend Report

March 2025 Infostealer Trend Report

This report provides statistics, trends, and case information on the distribution quantity, distribution methods, and disguise techniques of Infostealer collected and analyzed during March 2025. Below is a summary of the report.   1. Data Sources and Collection Methods   To proactively repond to Infostealer, AhnLab SEcurity intelligence Center (ASEC)

February 2025 Infostealer Trend Report

February 2025 Infostealer Trend Report

This report provides statistics, trends, and case information on the distribution quantity, distribution methods, and disguise techniques of Infostealer collected and analyzed during February 2025. Below is a summary of the report.   1. Data Sources and Collection Methods   To proactively repond to Infostealer, AhnLab SEcurity intelligence Center (ASEC)

ACRStealer Infostealer Exploiting Google Docs as C2

ACRStealer Infostealer Exploiting Google Docs as C2

AhnLab SEcurity intelligence Center (ASEC) monitors the Infostealer malware disguised as illegal programs such as cracks and keygens being distributed, and publishes related trends and changes through the Ahnlab TIP and ASEC Blog posts. While the majority of the malware distributed in this manner has been the LummaC2 Infostealer, the

January 2025 Infostealer Trend Report

January 2025 Infostealer Trend Report

This report provides statistics, trends, and case information on the distribution quantity, distribution methods, and disguise techniques of Infostealer collected and analyzed during January 2025. Below is a summary of the report’s content.   1. Data Sources and Collection Methods   To proactively respond to Infostealer, AhnLab Security Emergency response

Increase in Distribution of AutoIt Compile Malware via Phishing Emails

Increase in Distribution of AutoIt Compile Malware via Phishing Emails

Overview AhnLab SEcurity intelligence Center (ASEC) releases weekly information about malware distributed via phishing emails under the title “Weekly Phishing Email Distribution Cases” on the ASEC Blog.   While .NET-based malware was previously the most common type in EXE file distributions, there has been a recent surge in malware created

Statistical Report on Malware Threat in Q4 2024

Statistical Report on Malware Threat in Q4 2024

Overview AhnLab uses the automatic analysis system RAPIT to categorize and respond to malware collected through a variety of routes. This report categorizes and shares statistics on known malware among the ones collected during Q4 2024.   The malware strains included in the statistics are in the executable format and

Infostealer Logs Analysis Report

Infostealer Logs Analysis Report

Notice     The Infostealer Logs analysis report is a report that analyzes various Infostealer logs (RedLine, Raccoon, Vidar, Meta, etc.) collected from the deep and dark web including Telegram. Please note that the source and content of the report cannot be verified in part. Infostealer Logs Analysis Report