August 2025 Threat Trend Report on APT Groups

August 2025 Threat Trend Report on APT Groups

Purpose and Scope This report covers nation-led threat groups, presumed to conduct cyber espionage or sabotage supported by certain governments. These groups are referred to as advanced persistent threat (APT) groups for the sake of convenience. Therefore, this report does not contain information on cybercriminal groups aiming to gain financial

July 2025 Major APT Group Trends

July 2025 Major APT Group Trends

Purpose and Scope This report covers nation-led threat groups, presumed to conduct cyber espionage or sabotage supported by certain governments. These groups are referred to as advanced persistent threat (APT) groups for the sake of convenience. Therefore, this report does not contain information on cybercriminal groups aiming to gain financial

Mobile Security & Malware Issue 2st Week of August, 2025

Mobile Security & Malware Issue 2st Week of August, 2025

ASEC Blog publishes “Mobile Security & Malware Issue 2st Week of August, 2025”  

Threat Trend Report on APT Groups – June 2025 Major APT Group Trends

Threat Trend Report on APT Groups – June 2025 Major APT Group Trends

Purpose and Scope This report covers nation-led threat groups, presumed to conduct cyber espionage or sabotage supported by certain governments. These groups are referred to as advanced persistent threat (APT) groups for the sake of convenience. Therefore, this report does not contain information on cybercriminal groups aiming to gain financial

April 2025 APT Group Trends

April 2025 APT Group Trends

  Trends of major APT groups by country   1) North Korea   Since November 2024, the North Korean APT group has been exploiting the vulnerability of South Korean Internet financial security software. Similar attacks have been carried out in the past, and the threat actors have been launching attacks

Analysis of Lazarus Group’s Attack on Windows Web Servers

Analysis of Lazarus Group’s Attack on Windows Web Servers

AhnLab SEcurity intelligence Center (ASEC) has identified attack cases of the Lazarus group breaching a normal server and using it as a C2. Attacks that install a web shell and C2 script on South Korean web servers continue to occur. Additionally, there are cases where LazarLoader malware and privilege escalation

Threat Trend Report on  APT Groups

Threat Trend Report on APT Groups

The following are the main APT groups and their cases based on the analysis reports released by security companies and organizations in January 2025.   1.   Andariel   The Andariel group has executed an attack using the RID Hijacking technique to escalate account privileges and create hidden accounts.[1] RID Hijacking

APT Group Trends in October 2024

APT Group Trends in October 2024

  The following are the main APT groups and their cases based on the analysis reports released by security companies and organizations in October 2024.   1.   Andariel   Symantec’s Threat Hunter Team has found evidence that the Andariel group is launching financially motivated attacks against companies in the United

Threat Trend Report on APT Groups – July 2024 Major Issues on APT Groups

Threat Trend Report on APT Groups – July 2024 Major Issues on APT Groups

Purpose and Scope   This report covers nation-led threat groups presumed to conduct cyber espionage or sabotage under the support of the governments of certain countries, referred to as “Advanced Persistent Threat (APT) groups” for the sake of convenience. Therefore, this report does not contain information on cybercriminal groups aiming

Threat Trend Report on APT Groups – May 2024 Major Issues on APT Groups

Threat Trend Report on APT Groups – May 2024 Major Issues on APT Groups

The cases of major APT groups for May 2024 gathered from materials made public by security companies and institutions are as follows.   1.    Andariel   AhnLab SEcurity intelligence Center (ASEC) has been sharing Andariel group’s various attack cases against Korea.[1]  The Nestdoor backdoor that the Andariel group had used