216.73.217.22

May 2025 APT Group Trends (South Korea)

· Published 18/06/2025 17:46 · Modified 23/06/2025 19:59

Export JSON

Essential information

Published
18/06/2025 17:46
Modified
23/06/2025 19:59
Tags
2025-06-18 apt decoy documents lnk files obfuscation python scripts south korea spear-phishing task scheduler
Related entities
7 observables, 10 techniques (mitre)

Description

This analysis examines Advanced Persistent Threat () attacks in during May 2025. The majority of identified attacks utilized spear phishing as the primary infiltration method. Two main types of attacks were observed: Type A, which uses to execute malicious scripts and download additional malware, and Type B, which employs to download and execute obfuscated . Both types use deception techniques, including and manipulation. The attacks targeted various sectors, using topics such as financial reporting, privacy protection, and business registration to lure victims. The report provides detailed information on file names, , and indicators of compromise, including MD5 hashes, URLs, FQDNs, and IP addresses associated with the malicious activities.

External references