2026년 4월 APT 공격 동향 보고서(국내)
2026-05-26 • Ahnlab • April 2026 APT Attack Trend Report (South Korea) •
AhnLab observed April 2026 APT activity against South Korean targets, with most infections beginning through spear-phishing emails that used spoofed senders, malicious attachments, and malicious links. The activity relied heavily on LNK files, PowerShell, curl.exe, AutoIt, HTA, VBS, BAT, Python, GitHub, Google Drive, and scheduled tasks to retrieve payloads, maintain persistence, and execute attacker commands. Several chains delivered decoy documents while collecting host information, listing files, uploading and downloading data, receiving commands through PubNub channels, or loading infostealers, keyloggers, backdoors, and XenoRAT-type malware. AhnLab provides MD5 hashes and malicious URLs tied to the observed campaigns, making the report useful for tracking South Korea-focused phishing tradecraft and payload delivery patterns.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://sixtysixrealestate.com/… | 2026-05-26 | 2026-05-26 |
| URL | https://hypernotepad.com/n/9ad4… | 2026-05-26 | 2026-05-26 |
| URL | https://aplore.kesug.com/riln.p… | 2026-05-26 | 2026-05-26 |
| URL | https://aplore.kesug.com/fixpri… | 2026-05-26 | 2026-05-26 |
| URL | https://aplore.kesug.com/atrate… | 2026-05-26 | 2026-05-26 |
| HASH | 1194f56e15beb69fc41e498e240410f4 | 2026-05-26 | 2026-05-26 |
| HASH | 0e5509da6e2d2f12250821b871b439c3 | 2026-05-26 | 2026-05-26 |
| HASH | 0906e4d23fb07668c024263bc0311cff | 2026-05-26 | 2026-05-26 |
| HASH | 087955e719d00c7a0a07f1ed610894a2 | 2026-05-26 | 2026-05-26 |
| HASH | 04f017c65870791af565edcdd7407cf8 | 2026-05-26 | 2026-05-26 |