March 2025 APT Group Trends (South Korea)

March 2025 APT Group Trends (South Korea)

Overview   AhnLab is monitoring Advanced Persistent Threat (APT) attacks in South Korea using its own infrastructure. This report covers the classification, statistics, and features of the APT attacks in South Korea that were identified in March 2025, as well as the attack types.     Figure 1. Statistics of

ViperSoftX Malware Distributed by Arabic-Speaking Threat Actor

ViperSoftX Malware Distributed by Arabic-Speaking Threat Actor

AhnLab SEcurity intelligence Center (ASEC) uncovered that attackers, suspected to be Arabic speakers, have been distributing ViperSoftX malware targeting Korean victims since April 1, 2025. ViperSoftX is typically spread through cracked software or torrents, masquerading as legitimate programs. The main characteristic of ViperSoftX is that it operates as a PowerShell

Remcos RAT Malware Disguised as Major Carrier’s Waybill

Remcos RAT Malware Disguised as Major Carrier’s Waybill

AhnLab SEcurity intelligence Center (ASEC) has recently discovered the Remcos malware disguised as a waybill from a major shipping company. This article details the distribution distribution flow from HTML, JavaScript, and AutoIt scripts leading to the execution of the final Remcos malware.   Figure 1 shows the original email with

Warning Against Phishing Emails Distributing GuLoader Malware by Impersonating a Famous International Shipping Company

Warning Against Phishing Emails Distributing GuLoader Malware by Impersonating a Famous International Shipping Company

AhnLab SEcurity intelligence Center (ASEC) recently identified the distribution of GuLoader malware via a phishing email by impersonating a famous international shipping company. The phishing email was obtained through the email honeypot operated by ASEC. The mail body instructs users to check their post-paid customs tax and demands them to

February 2025 APT Group Trends (South Korea)

February 2025 APT Group Trends (South Korea)

Overview   AhnLab is monitoring Advanced Persistent Threat (APT) attacks in South Korea using its own infrastructure. This report covers the classification, statistics, and features of the APT attacks in South Korea that were identified in February 2025, as well as the attack types.   Figure 1. Statistics of APT

Android Malware & Security Issue 1st Week of November, 2024

Android Malware & Security Issue 1st Week of November, 2024

ASEC Blog publishes “Android Malware & Security Issue 1st Week of November, 2024”

Android Malware & Security Issue 5st Week of October, 2024

Android Malware & Security Issue 5st Week of October, 2024

ASEC Blog publishes “Android Malware & Security Issue 5st Week of October, 2024”

RAT Malware Operating via Discord Bot

RAT Malware Operating via Discord Bot

Discord is a social platform where users can create servers to form communities and communicate in real-time, supporting voice, video, and text chat. While it initially gained popularity among gamers, it has now expanded into a space where groups with diverse interests gather to communicate. A Discord Bot is a

WrnRAT Distributed Under the Guise of Gambling Games

WrnRAT Distributed Under the Guise of Gambling Games

AhnLab SEcurity intelligence Center (ASEC) recently discovered that malware was being distributed under the guise of gambling games such as badugi, 2-player go-stop, and hold’em. The threat actor created a website disguised as a gambling game site, and if the game launcher is downloaded, it installs malware that can control

Distribution of AsyncRAT Disguised as Ebook

Distribution of AsyncRAT Disguised as Ebook

1. Overview AhnLab SEcurity intelligence Center (ASEC) covered cases of AsyncRAT being distributed via various file extensions (.chm, .wsf, and .lnk). [1] [2] In the aforementioned blog posts, it can be seen that the threat actor used normal document files disguised as questionnaires to conceal the malware. In a similar vein, there