AhnLab's June 2026 threat trend report documents six categorized APT attack patterns targeting South Korean entities, all initiated via spear phishing with disguised file attachments (primarily LNK files). Attack chains leverage native Windows utilities (PowerShell, mshta, curl.exe), Task Scheduler-based persistence disguised as legitimate updates, and abuse of GitHub/Google Drive for payload staging, ultimately deploying AutoIt malware, XenoRAT, infostealers, keyloggers, and custom Python/DLL side-loaded backdoors.
XenoRAT
1 post
June 2026 Threat Trend Report on APT Attacks (South Korea)