December 2024 Threat Trend Report on APT Attacks (South Korea)

Jan. 9, 2025, 9:39 a.m.

Description

This intelligence report analyzes Advanced Persistent Threat (APT) attacks targeting South Korea in December 2024. The primary method of attack was spear phishing, with a focus on distributing LNK files. Two main types of attacks were identified: Type A, which uses compressed CAB files containing malicious scripts for information exfiltration and additional malware downloads, and Type B, which executes Remote Access Trojan (RAT) malware like XenoRAT and RoKRAT. The attacks often use deceptive file names and decoy documents to appear legitimate. The report highlights the sophisticated nature of these attacks, including the use of reconnaissance, email spoofing, and various malicious scripts to bypass security measures and compromise target systems.

Date

  • Created: Jan. 9, 2025, 8:57 a.m.
  • Published: Jan. 9, 2025, 8:57 a.m.
  • Modified: Jan. 9, 2025, 9:39 a.m.

Indicators

  • 206.206.127.152
  • 118.194.249.90
  • 118.193.69.53

Attack Patterns

  • XenoRAT
  • ROKRAT - S0240
  • T1036.002
  • T1059.005
  • T1059.003
  • T1059.001
  • T1059.007
  • T1056.001
  • T1113
  • T1204.002
  • T1105
  • T1566.001
  • T1140
  • T1027
  • T1078