216.73.217.98

March 2025 APT Group Trends (South Korea)

· Published 10/04/2025 18:50 · Modified 10/04/2025 20:13

Export JSON

Essential information

Published
10/04/2025 18:50
Modified
10/04/2025 20:13
Tags
2025-04-10 apt cab files lnk files nukesped obfuscation pebbledash powershell python south korea spear-phishing task scheduler
Related entities
11 techniques (mitre), 2 malware

Description

This intelligence report analyzes Advanced Persistent Threat () attacks in during March 2025. The majority of attacks were classified as spear phishing, with LNK file distribution being the most prevalent method. Two types of LNK-based attacks were identified: Type A, which uses a CAB file with malicious scripts, and Type B, which downloads a CAB file containing a malicious script. Both types employ techniques and execute multiple stages to perform various malicious activities, including information leakage and additional malware downloads. The attacks often use decoy files to appear legitimate and target specific individuals or groups with carefully crafted emails.

External references