216.73.216.145

June 2026 Threat Trend Report on APT Attacks (South Korea)

· Published 24/07/2026 14:34

Export JSON

Essential information

Published
24/07/2026 14:34
Modified
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
apt autoit github abuse kimsuky lnk files pebbledash powershell prxclient south korea spear phishing task scheduler xenorat
Related entities
2 indicators, 2 observables, 1 intrusion sets (apt), 20 techniques (mitre), 4 malware

Description

AhnLab monitored Advanced Persistent Threat attacks targeting during June 2026, identifying multiple attack types distributed primarily through campaigns. Threat actors disguised malicious files as work-related documents, with being the most common delivery method. Six distinct attack types were observed, employing various techniques including malicious commands, malware, curl.exe abuse, GitHub repository exploitation, persistence, DLL side-loading, and Python backdoors. These attacks deployed Infostealers, keyloggers, backdoors, and remote access tools like . Once executed, the malware established persistence, exfiltrated system information, and enabled remote control of compromised systems. Organizations are advised to verify email senders, avoid opening files from unknown sources, apply security patches, and maintain updated antivirus software to mitigate these persistent threats.

External references