2026년 4월 국내외 금융권 관련 보안 이슈
2026-05-21 • Ahnlab • April 2026 Domestic and International Financial Sector Security Issues •
AhnLab's April 2026 financial-sector review links WGear RCE exploitation to DPRK-relevant activity, noting that Andariel has repeatedly abused the vulnerability. In observed cases, the WGear process launched mshta to retrieve external HTML, download and execute additional payloads, and ultimately install GeniexLoader. The report states that GeniexLoader is associated with BlueNoroff, also known as CryptoCore and APT38, connecting the activity to financially motivated North Korea-linked operations. The broader financial-sector telemetry also includes phishing attachments, fake login pages, Telegram-based credential exfiltration, ransomware leak claims, and access-broker listings that increase risk to banks and financial services.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | b15a55f9a23998b1976622bd3b9a3ad9 | 2026-05-21 | 2026-05-21 |
| HASH | 8edc77fb36bf80bb52d158cf9043cecd | 2026-05-21 | 2026-05-21 |
| HASH | 750173f1b36e502ff17e2c5eec03c602 | 2026-05-21 | 2026-05-21 |
| HASH | 53636c80d43a3c461dc8a3d2a2f2d4e1 | 2026-05-21 | 2026-05-21 |
| HASH | 15adac4d6fc1bddb0c940cdc0c6605b4 | 2026-05-21 | 2026-05-21 |