Beware of phishing emails disguised as requests to review quotes (PhantomStealer)

Beware of phishing emails disguised as requests to review quotes (PhantomStealer)

The AhnLab SEcurity intelligence Center (ASEC) recently identified a phishing email campaign that disguised itself as a request to review a quote. The threat actor impersonated a sales team member at a specific overseas company and, by claiming that a previous quote needed to be revised and product versions verified,

Beware of Phishing Emails Disguised as Transaction Receipts

Beware of Phishing Emails Disguised as Transaction Receipts

Recently, the AhnLab SEcurity intelligence Center (ASEC) identified instances of phishing emails that were disguised as transaction receipts. The emails impersonated employees of a specific US company. The body of the message stated that a transaction receipt was attached and asked the recipient to review it and confirm whether funds

March 2026 Phishing Email Trends Report

March 2026 Phishing Email Trends Report

Statistics on Attachment Threats Types. trojans accounted for the largest share of attachment-based threats in March 2026 at 21%. phishing (FakePage) came in at 15%, with a significant month-over-month decrease in share from 42% to 15%, but a slight decrease in volume. downloaders were identified at 9% and droppers at

January 2026 Phishing Email Trends Report

January 2026 Phishing Email Trends Report

This report provides the distribution quantity, statistics, trends, and case information on phishing emails and email threats collected and analyzed for one month in January 2026. The following are some statistics and cases included in the original report. 1) Phishing Email Threat Statistics In January 2026, the most prevalent threat

November 2025 Trends Report on Phishing Emails

November 2025 Trends Report on Phishing Emails

This report provides statistics, trends, and case information on the distribution volume, attachment threats, and other aspects of phishing emails collected and analyzed for one month in November 2025. The following are some of the statistics and cases included in the original report. 1) Statistics of Phishing Email Threats In

October 2025 Trends Report on Phishing Emails

October 2025 Trends Report on Phishing Emails

This report provides the statistics, trends, and case information on the distribution of phishing emails and attachment-based threats collected and analyzed for one month in October 2025. Below is a portion of the statistics and cases included in the original report. 1) Statistics of Phishing Email Threats In October 2025,

September 2025 Trends Report on Phishing Emails

September 2025 Trends Report on Phishing Emails

This report provides the statistics, trends, and case information on the distribution quantity, attachment-based threats, and phishing emails collected and analyzed for a month in September 2025. Below is a portion of the statistics and cases included in the original report. 1) Statistics of phishing email threats In September 2025,

DBatLoader (ModiLoader) Being Distributed to Turkish Users

DBatLoader (ModiLoader) Being Distributed to Turkish Users

Recently, AhnLab SEcurity intelligence Center (ASEC) has identified cases of the ModiLoader (DBatLoader) malware being distributed via email. ModiLoader ultimately executes SnakeKeylogger. SnakeKeylogger is an Infostealer-type malware developed in .NET. It is known for its data exfiltration methods using emails, FTP, SMTP, or Telegram. Figure 1 shows the email being

Remcos RAT Malware Disguised as Major Carrier’s Waybill

Remcos RAT Malware Disguised as Major Carrier’s Waybill

AhnLab SEcurity intelligence Center (ASEC) has recently discovered the Remcos malware disguised as a waybill from a major shipping company. This article details the distribution distribution flow from HTML, JavaScript, and AutoIt scripts leading to the execution of the final Remcos malware.   Figure 1 shows the original email with

Distribution of LockBit Ransomware and Vidar Infostealer Disguised as Resumes

Distribution of LockBit Ransomware and Vidar Infostealer Disguised as Resumes

The distribution method involving the impersonation of resumes is one of the main methods used by the LockBit ransomware. Information related to this has been shared through the ASEC Blog in February of this year. [1] In contrast to the past where only the LockBit ransomware was distributed, it has