2025년 4월 APT 그룹 동향 보고서

2025-05-15 Ahnlab Cyber threat report on Trend, Konni, Lazarus

https://asec.ahnlab.com/ko/87992/

Thumbnail for 2025년 4월 APT 그룹 동향 보고서

AhnLab's April 2025 APT trend report summarizes multiple regional threat activities, including North Korean groups exploiting South Korean software ecosystems. It describes Konni spear-phishing campaigns impersonating Korean government agencies and delivering LNK and AutoIT-based malware to North Korean human-rights and NGO-related targets. It also summarizes Lazarus Operation SyncHole, a watering-hole campaign abusing Korean software vulnerabilities such as Innorix Agent and Cross EX to compromise at least six South Korean organizations in software, IT, finance, semiconductor manufacturing, and telecommunications. The report also covers separate China-linked activity, including APT41 infrastructure exposure involving Fortinet exploit scripts, encrypted web shells, and reconnaissance tooling.

Related Actors

Related Reports

2025-04-24 • 60% Match
#ThreatNeedle #LPEClient #SIGNBT #AGAMEMNON #Lazarus #Innorix #SyncHole #CrossEX #T1027.013 #T1082 #T1140 #T1071.001 #T1083 #T1057 #T1583.003 #T1583.001 #T1105 #T1620 #T1574.002 #T1135 #T1573.001 #T1190 #T1189 #T1049 #T1573.002 #T1016 #T1087.001 #T1218.011 #T1584.001 #T1574.001 #T1564.004 #T1027.009 #T1569.002 #T1543.003 #T1087.002 #T1570 #T1608.004 #T1547.005 #T1007
Shares tags: Lazarus, SyncHole • Published within a month
« Back