216.73.217.22

December 2024 Threat Trend Report on APT Attacks (South Korea)

· Published 09/01/2025 08:57 · Modified 09/01/2025 09:39

Export JSON

Essential information

Published
09/01/2025 08:57
Modified
09/01/2025 09:39
Tags
2025-01-09 apt decoy documents lnk files rat rokrat south korea spear-phishing xenorat
Related entities
3 observables, 13 techniques (mitre), 2 malware

Description

This intelligence report analyzes Advanced Persistent Threat () attacks targeting in December 2024. The primary method of attack was spear phishing, with a focus on distributing . Two main types of attacks were identified: Type A, which uses compressed CAB files containing malicious scripts for information exfiltration and additional malware downloads, and Type B, which executes Remote Access Trojan () malware like and . The attacks often use deceptive file names and to appear legitimate. The report highlights the sophisticated nature of these attacks, including the use of reconnaissance, email spoofing, and various malicious scripts to bypass security measures and compromise target systems.

External references