Analysis of Lazarus Group’s Attack on Windows Web Servers

Analysis of Lazarus Group’s Attack on Windows Web Servers

AhnLab SEcurity intelligence Center (ASEC) has identified attack cases of the Lazarus group breaching a normal server and using it as a C2. Attacks that install a web shell and C2 script on South Korean web servers continue to occur. Additionally, there are cases where LazarLoader malware and privilege escalation

January 2025 Threat Trend Report on APT Attacks (South Korea)

January 2025 Threat Trend Report on APT Attacks (South Korea)

Overview AhnLab is monitoring Advanced Persistent Threat (APT) attacks in South Korea using its own infrastructure. This report covers the classification and statistics of APT attacks in South Korea that have been identified over the course of a month in January 2025, as well as the features of each attack

Statistical Report on Malware Targeting Windows Web Servers in Q4 2024

Statistical Report on Malware Targeting Windows Web Servers in Q4 2024

Overview AhnLab SEcurity intelligence Center (ASEC) responds to and classifies attacks that target inappropriately managed Windows web servers by utilizing the AhnLab Smart Defense (ASD) infrastructure. This post covers the damage status of Windows web servers that have been targeted in attacks and provides statistics on the attacks based on

Analysis of Attack Cases Against Korean Solutions by the Andariel Group (SmallTiger)

Analysis of Attack Cases Against Korean Solutions by the Andariel Group (SmallTiger)

The Andariel group has been attacking various software used by South Korean companies since the past [1]. Notably, these include asset management solutions and data loss prevention (DLP) solutions, and vulnerability attack cases have also been identified in various other solutions.  Attack cases by the Andariel group are continuing in

Analysis Report on Larva-24011 Threat Actor’s Latest Attack Trend

Analysis Report on Larva-24011 Threat Actor’s Latest Attack Trend

1. Overview The Larva-24011 threat actor is targeting vulnerable systems to install CoinMiner and proxyware for financial gain. AhnLab Security Intelligence Center (ASEC) has recently observed that besides installing CoinMiner and proxyware, the threat actor is engaging in more attack cases of controlling infected systems and exfiltrating information such as

Statistical Report on Malware Targeting Windows Web Servers in Q3 2024

Statistical Report on Malware Targeting Windows Web Servers in Q3 2024

OverviewStatistics1. Status of Attacks Against Windows Web Servers 2. Categorization of Malware Used in Attacks  2.1. Privilege Escalation Tools   2.2. Hacking Tools   2.3. Backdoor   2.4. CoinMiner 3. Statistics on Web Shells Used in Attacks  3.1. Web Shell Statistics 4. Cases of Attacks in Q3 2024 Conclusion   Overview   AhnLab SEcurity intelligence Center (ASEC)

Statistical Report on Malware Targeting Windows Web Servers in Q2 2024

Statistical Report on Malware Targeting Windows Web Servers in Q2 2024

Overview   AhnLab SEcurity intelligence Center (ASEC) uses the AhnLab Smart Defense (ASD) infrastructure to respond to and classify attacks on poorly managed Windows web servers. This report covers the current state of damage to Windows web servers which have become the target of attacks based on the logs identified

Analysis of CoinMiner Attacks Targeting Korean Web Servers

Analysis of CoinMiner Attacks Targeting Korean Web Servers

Since web servers are externally exposed to provide web services to all available users, they have been major targets for threat actors since the past. AhnLab SEcurity Intelligence Center (ASEC) is monitoring attacks against vulnerable web servers that have unpatched vulnerabilities or are being poorly managed, and is sharing the

Analysis of Attack Case Installing SoftEther VPN on Korean ERP Server

Analysis of Attack Case Installing SoftEther VPN on Korean ERP Server

AhnLab SEcurity intelligence Center (ASEC) has recently discovered an attack case where a threat actor attacked the ERP server of a Korean corporation and installed a VPN server. In the initial compromise process, the threat actor attacked the MS-SQL service and later installed a web shell to maintain persistence and

Statistical Report on Malware Targeting Windows Web Servers in Q1 2024

Statistical Report on Malware Targeting Windows Web Servers in Q1 2024

Overview   AhnLab SEcurity intelligence Center (ASEC) uses the AhnLab Smart Defense (ASD) infrastructure to respond to and classify attacks on poorly managed Windows web servers. This report covers the current state of damage to Windows web servers which have become the target of attacks based on the logs identified