Threat Trend Report on APT Attacks (South Korea) – April 2024 Major Issues on APT Attacks Against South Korea

Threat Trend Report on APT Attacks (South Korea) – April 2024 Major Issues on APT Attacks Against South Korea

Overview   AhnLab has been using AhnLab Smart Defense (ASD) to monitor advanced persistent threat (APT) attacks against targets in South Korea. This report discusses the categorization and statistics of APT attacks against Korean targets in April 2024 as well as the features of each type.   Figure 1. Statistics

CHM Malware Stealing User Information Being Distributed in Korea

CHM Malware Stealing User Information Being Distributed in Korea

AhnLab SEcurity intelligence Center (ASEC) has recently discovered circumstances of a CHM malware strain that steals user information being distributed to Korean users. The distributed CHM is a type that has been constantly distributed in various formats such as LNK, DOC, and OneNote from the past. A slight change to

Threat Trend Report on APT Attacks (South Korea) – March 2024 Major Issues on APT Attacks

Threat Trend Report on APT Attacks (South Korea) – March 2024 Major Issues on APT Attacks

Overview   AhnLab has been using its infrastructure to monitor advanced persistent threat (APT) attacks against Korean targets. This report will cover the categories of APT attacks targeting Korea detected during March 2024 as well as features for each type. Figure 1. March 2024 statistics on APT attacks against Korea

Threat Trend Report on APT Attacks (South Korea) – February 2024 Major Issues on APT Attacks

Threat Trend Report on APT Attacks (South Korea) – February 2024 Major Issues on APT Attacks

Overview   AhnLab monitors Advanced Persistent Threat (APT) attacks targeting South Korean entities using its infrastructure. This report will cover the classification and statistics of APT attacks in South Korea detected during February 2024, and introduce their features by type. Figure 1. Statistics on APT attacks in South Korea in

Threat Trend Report on APT Attacks (South Korea) – January 2024 Major Issues on APT Attacks

Threat Trend Report on APT Attacks (South Korea) – January 2024 Major Issues on APT Attacks

Overview AhnLab monitors Advanced Persistent Threat (APT) attacks targeting South Korean entities using its infrastructure. This report will cover the classification and statistics of APT attacks in South Korea detected during January 2024, and introduce their features by type.   Figure 1. Statistics of APT attacks in South Korea in

Kimsuky Distributing CHM Malware Under Various Subjects

Kimsuky Distributing CHM Malware Under Various Subjects

AhnLab Security Emergency response Center (ASEC) has continuously been tracking the Kimsuky group’s APT attacks. This post will cover the details confirmed during the past month of May. While the Kimsuky group often used document files for malware distribution, there have been many recent cases where CHM files were used

Chinese Hacker Group Stealing Information From Korean Companies

Chinese Hacker Group Stealing Information From Korean Companies

Recently, there have been frequent cases of attacks targeting vulnerable servers that are accessible externally, such as SQL servers or IIS web servers. The team has confirmed two affected companies in this case. One being a company for semiconductors, and the other being a smart manufacturing company which utilizes artificial

Malware Disguised as Normal Documents (Kimsuky)

Malware Disguised as Normal Documents (Kimsuky)

The ASEC analysis team has recently discovered that the malware introduced in the post, <Malware Disguised as a Manuscript Solicitation Letter (Targeting Security-Related Workers)>, is being distributed to broadcasting and ordinary companies as well as those in the security-related field. Identical to the malware introduced in the blog post above,

Malware Disguised as a Manuscript Solicitation Letter (Targeting Security-Related Workers)

Malware Disguised as a Manuscript Solicitation Letter (Targeting Security-Related Workers)

On January 8th, the ASEC analysis team identified the distribution of a document-type malware targeting workers in the security field. The obtained malware uses an external object within a Word document to execute an additional malicious macro. Such a technique is called the template Injection method. and a similar attack

Analysis Report on Lazarus Group’s Rootkit Attack Using BYOVD

Analysis Report on Lazarus Group’s Rootkit Attack Using BYOVD

Since 2009, Lazarus Group, known to be a group of hackers in North Korea, has been attacking not only Korea but various countries of America, Asia, and Europe. According to AhnLab’s ASD (AhnLab Smart Defense) infrastructure, in early 2022, the Lazarus Group performed APT (Advanced Persistent Threat) attacks on Korea’s