Visualização normal

Ontem — 7 de Setembro de 2026ASEC BLOG
  • ✇ASEC BLOG
  • Detection and Removal of the Syslogk Rootkit in a Linux Environment ATCP
    1. Overview The AhnLab SEcurity intelligence Center (ASEC) continuously monitors various threats targeting Linux environments. Techniques that modify the Linux kernel to conceal malware and signs of compromise have been used for a long time, and Syslogk is one such rootkit that operates in this manner. This document provides an analysis of the key features […]
     

Detection and Removal of the Syslogk Rootkit in a Linux Environment

Por:ATCP
2 de Setembro de 2026, 12:00
1. Overview The AhnLab SEcurity intelligence Center (ASEC) continuously monitors various threats targeting Linux environments. Techniques that modify the Linux kernel to conceal malware and signs of compromise have been used for a long time, and Syslogk is one such rootkit that operates in this manner. This document provides an analysis of the key features […]
Antes de ontemASEC BLOG
  • ✇ASEC BLOG
  • Attack Cases in Korea Involving the Installation of Radmin and UltraVNC ATCP
    The AhnLab SEcurity intelligence Center (ASEC) recently identified attack cases that exploited Radmin and UltraVNC. Although the Initial Intrusion method remains unknown, the attackers installed Radmin—a remote control tool—and then installed UltraVNC. The threat actors exploited the remote control tools to gain control of the infected systems and installed Netch and CCProxy to use the […]
     

Attack Cases in Korea Involving the Installation of Radmin and UltraVNC

Por:ATCP
2 de Setembro de 2026, 12:00
The AhnLab SEcurity intelligence Center (ASEC) recently identified attack cases that exploited Radmin and UltraVNC. Although the Initial Intrusion method remains unknown, the attackers installed Radmin—a remote control tool—and then installed UltraVNC. The threat actors exploited the remote control tools to gain control of the infected systems and installed Netch and CCProxy to use the […]
  • ✇ASEC BLOG
  • “Evasive” Malware Attack Tactics: Hiding, Bypassing, and Reappearing ATCP
      People who initially seem fine but tend to subtly avoid others as the relationship deepens or when conflicts arise—and who disappear when pressured—are commonly referred to as “avoidant types.” By repeatedly pulling away only to reappear, they drain the other person’s emotions and energy, ultimately undermining the relationship. The attack pattern of the recently […]
     

“Evasive” Malware Attack Tactics: Hiding, Bypassing, and Reappearing

Por:ATCP
1 de Setembro de 2026, 12:00
  People who initially seem fine but tend to subtly avoid others as the relationship deepens or when conflicts arise—and who disappear when pressured—are commonly referred to as “avoidant types.” By repeatedly pulling away only to reappear, they drain the other person’s emotions and energy, ultimately undermining the relationship. The attack pattern of the recently […]
  • ✇ASEC BLOG
  • Kim Sooki again? This time, it was disguised as a request for seafood ingredients ATCP
    A request to review the purchase of seafood ingredients arrived. When the file is opened, a normal hwp document appears, but while the user is reviewing the contents, a malicious script runs in the background and even registers a scheduled task. It then extracts system information to an external location, downloads and executes additional commands, […]
     

Kim Sooki again? This time, it was disguised as a request for seafood ingredients

Por:ATCP
1 de Setembro de 2026, 12:00
A request to review the purchase of seafood ingredients arrived. When the file is opened, a normal hwp document appears, but while the user is reviewing the contents, a malicious script runs in the background and even registers a scheduled task. It then extracts system information to an external location, downloads and executes additional commands, […]
  • ✇ASEC BLOG
  • July 2026 Threat Trend Report on Ransomware ATCP
    Purpose and Scope The July 2026 Threat Trend Report on Ransomware summarizes major Korean & global ransomware issues based on statistics regarding the quantity of new ransomware samples, the number of compromised systems, and statistics on targeted businesses. Statistics on targeted businesses were compiled based on information published on DLS (Dedicated Leak Sites, also referred […]
     

July 2026 Threat Trend Report on Ransomware

Por:ATCP
23 de Agosto de 2026, 12:00
Purpose and Scope The July 2026 Threat Trend Report on Ransomware summarizes major Korean & global ransomware issues based on statistics regarding the quantity of new ransomware samples, the number of compromised systems, and statistics on targeted businesses. Statistics on targeted businesses were compiled based on information published on DLS (Dedicated Leak Sites, also referred […]
  • ✇ASEC BLOG
  • Security Issues in the Korean & Global Financial Sector in July 2026 ATCP
    Statistics on Malware Distributed to the Financial Sector In Attack Stage 1, phishing (a technique that tricks users into opening malicious links or attachments) had the highest rate at 1.7, Down from 2.3 The previous month. In Attack Stage 2, Dropper/Downloader (a type that downloads additional malware) was the most prevalent at 1.7, Up from […]
     

Security Issues in the Korean & Global Financial Sector in July 2026

Por:ATCP
9 de Agosto de 2026, 12:00
Statistics on Malware Distributed to the Financial Sector In Attack Stage 1, phishing (a technique that tricks users into opening malicious links or attachments) had the highest rate at 1.7, Down from 2.3 The previous month. In Attack Stage 2, Dropper/Downloader (a type that downloads additional malware) was the most prevalent at 1.7, Up from […]
  • ✇ASEC BLOG
  • July 2026 Infostealer Trend Report ATCP
    Content This report summarizes the distribution channels, number of Infostealers, number of detections, and target companies that were disguised as Infostealers collected during the month of July 2026. It was compiled based on results from AhnLab SEcurity intelligence Center (ASEC)’s automated data collection system, email honeypots, and automated C2 analysis, as well as diagnostic logs […]
     

July 2026 Infostealer Trend Report

Por:ATCP
11 de Agosto de 2026, 12:00
Content This report summarizes the distribution channels, number of Infostealers, number of detections, and target companies that were disguised as Infostealers collected during the month of July 2026. It was compiled based on results from AhnLab SEcurity intelligence Center (ASEC)’s automated data collection system, email honeypots, and automated C2 analysis, as well as diagnostic logs […]
  • ✇ASEC BLOG
  • Beware of phishing emails disguised as requests to review quotes (PhantomStealer) ATCP
    The AhnLab SEcurity intelligence Center (ASEC) recently identified a phishing email campaign that disguised itself as a request to review a quote. The threat actor impersonated a sales team member at a specific overseas company and, by claiming that a previous quote needed to be revised and product versions verified, tricked recipients into opening the […]
     

Beware of phishing emails disguised as requests to review quotes (PhantomStealer)

Por:ATCP
11 de Agosto de 2026, 12:00
The AhnLab SEcurity intelligence Center (ASEC) recently identified a phishing email campaign that disguised itself as a request to review a quote. The threat actor impersonated a sales team member at a specific overseas company and, by claiming that a previous quote needed to be revised and product versions verified, tricked recipients into opening the […]
  • ✇ASEC BLOG
  • Attack Cases for Domestic Web Servers Running SoftEther VPN in Korea ATCP
    The AhnLab SEcurity intelligence Center (ASEC) recently identified attack cases in which attackers targeted web servers in Korea to install SoftEther VPN. Attack cases involving the installation of SoftEther VPN, an open-source VPN, were previously discussed in the 2024 ASEC blog post titled “Analysis of Attack Cases Targeting ERP Servers in Korea to Install SoftEther […]
     

Attack Cases for Domestic Web Servers Running SoftEther VPN in Korea

Por:ATCP
10 de Agosto de 2026, 12:00
The AhnLab SEcurity intelligence Center (ASEC) recently identified attack cases in which attackers targeted web servers in Korea to install SoftEther VPN. Attack cases involving the installation of SoftEther VPN, an open-source VPN, were previously discussed in the 2024 ASEC blog post titled “Analysis of Attack Cases Targeting ERP Servers in Korea to Install SoftEther […]
  • ✇ASEC BLOG
  • Beware of Phishing Emails Disguised as Transaction Receipts ATCP
    Recently, the AhnLab SEcurity intelligence Center (ASEC) identified instances of phishing emails that were disguised as transaction receipts. The emails impersonated employees of a specific US company. The body of the message stated that a transaction receipt was attached and asked the recipient to review it and confirm whether funds had been deposited into their […]
     

Beware of Phishing Emails Disguised as Transaction Receipts

Por:ATCP
9 de Agosto de 2026, 12:00
Recently, the AhnLab SEcurity intelligence Center (ASEC) identified instances of phishing emails that were disguised as transaction receipts. The emails impersonated employees of a specific US company. The body of the message stated that a transaction receipt was attached and asked the recipient to review it and confirm whether funds had been deposited into their […]

Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005)

Por:ATCP
3 de Agosto de 2026, 12:00
1. Overview AhnLab SEcurity intelligence Center (ASEC) recently confirmed that the Larva-26005 threat actor is distributing Xctdoor to users in Korea. Xctdoor was disclosed through the ASEC blog in 2024, and [1] In March 2026, Hauri disclosed an attack case in which the malware was disguised as an integrated security program. [2]   While analyzing […]
  • ✇ASEC BLOG
  • Analysis of a Phishing Email Attack Case by the Larva-24009 Threat Actor ATCP
    The Larva-24009 threat actor has been active since at least 2023, carrying out phishing email attacks targeting users both in Korea and globally to install malware. ASEC (AhnLab SEcurity intelligence Center (ASEC) has previously disclosed attack cases by this threat actor in 2024, and [1] [2] [3] Subsequently, Cyble also identified this same attack campaign […]
     

Analysis of a Phishing Email Attack Case by the Larva-24009 Threat Actor

Por:ATCP
2 de Agosto de 2026, 12:00
The Larva-24009 threat actor has been active since at least 2023, carrying out phishing email attacks targeting users both in Korea and globally to install malware. ASEC (AhnLab SEcurity intelligence Center (ASEC) has previously disclosed attack cases by this threat actor in 2024, and [1] [2] [3] Subsequently, Cyble also identified this same attack campaign […]

[Joint Cybersecurity Advisory] Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group)

Por:ATCP
29 de Julho de 2026, 12:00
This technical analysis report was prepared as part of the joint cybersecurity advisory titled “Advisory on Cyberattacks Targeting Korean Citizens and Businesses by State-Sponsored Hacking Groups” issued by the Republic of Korea’s National Intelligence Service (NIS), National Police Agency (NPA), Korea Internet & Security Agency (KISA), and Financial Security Institute (FSI).   OverView AhnLab SEcurity […]
  • ✇ASEC BLOG
  • Not Every Fox is Silver: Inside an AtlasRAT loader chain ATCP
    Summary AtlasRAT is a Windows-based remote access malware. This report analyzes a four-stage in-memory loader chain—which begins with a Delphi executable that is disguised as AGE Flash Player—and its final RAT functionality. The final payload performs TLS-based ChaCha20-encrypted C2 communication, executes modular plugins, performs offline keylogging, and injects DLLs into WeChat processes. Group Characteristics Public […]
     

Not Every Fox is Silver: Inside an AtlasRAT loader chain

Por:ATCP
27 de Julho de 2026, 20:25
Summary AtlasRAT is a Windows-based remote access malware. This report analyzes a four-stage in-memory loader chain—which begins with a Delphi executable that is disguised as AGE Flash Player—and its final RAT functionality. The final payload performs TLS-based ChaCha20-encrypted C2 communication, executes modular plugins, performs offline keylogging, and injects DLLs into WeChat processes. Group Characteristics Public […]

Case Study: Targeted Attack Case on an MS-SQL Server Involving the Installation of GotoHTTP and SoftEther VPN

Por:ATCP
24 de Julho de 2026, 12:00
While monitoring attack cases targeting MS-SQL servers, the AhnLab SEcurity intelligence Center (ASEC) identified an instance in which the Larva-26009 threat actor installed the XMRig CoinMiner. While the installation of CoinMiner is common in attack cases targeting MS-SQL servers, in this particular attack case, the attacker installed VShell and GotoHTTP to gain control over the […]
  • ✇ASEC BLOG
  • Attack Cases by the Kimsuky Group Impersonating Diplomats (PebbleDash, PrxClient) ATCP
    AhnLab SEcurity intelligence Center (ASEC) previously disclosed an attack case in which the Kimsuky group used spear phishing attacks to install the PebbleDash malware in a post titled “Analysis of the Kimsuky Group’s Latest Attacks Exploiting PebbleDash and RDP Wrapper” [1]. The same threat actors have continued their activities in 2026 and have recently been […]
     

Attack Cases by the Kimsuky Group Impersonating Diplomats (PebbleDash, PrxClient)

Por:ATCP
16 de Julho de 2026, 12:00
AhnLab SEcurity intelligence Center (ASEC) previously disclosed an attack case in which the Kimsuky group used spear phishing attacks to install the PebbleDash malware in a post titled “Analysis of the Kimsuky Group’s Latest Attacks Exploiting PebbleDash and RDP Wrapper” [1]. The same threat actors have continued their activities in 2026 and have recently been […]
  • ✇ASEC BLOG
  • June 2026 Security Issues in Korean & Global Financial Sector ATCP
    Statistics on Malware Distributed to the Financial Sector In the June threat analysis for the financial sector, phishing was the most prevalent attack method in Attack Stage 1, while droppers/downloaders (distribution tools that download additional malware) were the most prevalent in Attack Stage 2. Infostealers were identified in the third attack stage, indicating that multi-stage […]
     

June 2026 Security Issues in Korean & Global Financial Sector

Por:ATCP
15 de Julho de 2026, 12:00
Statistics on Malware Distributed to the Financial Sector In the June threat analysis for the financial sector, phishing was the most prevalent attack method in Attack Stage 1, while droppers/downloaders (distribution tools that download additional malware) were the most prevalent in Attack Stage 2. Infostealers were identified in the third attack stage, indicating that multi-stage […]
  • ✇ASEC BLOG
  • June 2026 Infostealer Trend Report ATCP
    Contents This report summarizes the distribution channels, number of Infostealers, number of detections, and information on companies targeted by new Infostealers collected during June 2026. The collected samples were obtained through an automated data collection system, an email honeypot system, and an automated malware C2 analysis system operated by AhnLab SEcurity intelligence Center (ASEC). Purpose […]
     

June 2026 Infostealer Trend Report

Por:ATCP
14 de Julho de 2026, 12:00
Contents This report summarizes the distribution channels, number of Infostealers, number of detections, and information on companies targeted by new Infostealers collected during June 2026. The collected samples were obtained through an automated data collection system, an email honeypot system, and an automated malware C2 analysis system operated by AhnLab SEcurity intelligence Center (ASEC). Purpose […]

Case Study: Distribution of a CoinMiner Targeting Linux SSH Servers via Malware Distribution via Network Transmission

Por:ATCP
11 de Julho de 2026, 12:00
The AhnLab SEcurity intelligence Center (ASEC) is monitoring attacks targeting poorly managed Linux servers using multiple honeypots. Recently, ASEC identified cases where malware with propagation capabilities was used to install the XMRig CoinMiner.   In these attack cases, malware such as ShellBot, MIG LogCleaner, and XHide were used. The threat actors created and used downloaders […]
  • ✇ASEC BLOG
  • Beware of Phishing Emails Disguised as Money Transfer Confirmations ATCP
    Recently, the AhnLab SEcurity intelligence Center (ASEC) identified a case of phishing emails that disguise themselves as payment confirmation notices. These emails impersonate employees of a specific company in Korea and trick recipients into opening a malicious XLS file attached to the email, which is disguised as a payment confirmation notice.   [Figure 1] Body […]
     

Beware of Phishing Emails Disguised as Money Transfer Confirmations

Por:ATCP
9 de Julho de 2026, 12:00
Recently, the AhnLab SEcurity intelligence Center (ASEC) identified a case of phishing emails that disguise themselves as payment confirmation notices. These emails impersonate employees of a specific company in Korea and trick recipients into opening a malicious XLS file attached to the email, which is disguised as a payment confirmation notice.   [Figure 1] Body […]
❌
❌