216.73.217.22

August 2025 APT Attack Trends Report

· Published 16/09/2025 13:40 · Modified 16/09/2025 14:40

Export JSON

Essential information

Published
16/09/2025 13:40
Modified
16/09/2025 14:40
Tags
2025-09-16 apt cab files lnk files powershell rat rokrat south korea spear-phishing xenorat
Related entities
5 observables, 9 techniques (mitre), 2 malware, 2 others

Description

In August 2025, attacks in primarily utilized spear phishing techniques, with being the most prevalent method. Two main types of attacks were observed: Type A, which used compressed containing malicious scripts for information exfiltration and additional malware downloads, and Type B, which executed malware like and using Dropbox API or Google Drive. The attacks targeted various sectors, employing sophisticated social engineering tactics and decoy documents to increase credibility. The malware performed actions such as keylogging, taking screenshots, and executing commands based on the threat actor's instructions. The report highlights the continuous evolution of tactics and the importance of vigilance against targeted phishing campaigns.

External references