April 2025 APT Group Trends

2025-05-15 Ahnlab

https://asec.ahnlab.com/en/88063/

Thumbnail for April 2025 APT Group Trends

AhnLab's April 2025 APT trend report highlights two DPRK-relevant campaigns. Konni used spear phishing that impersonated the Korean National Police Agency and National Human Rights Commission, first encouraging replies and then delivering LNK and AutoIT-based malware to activists tied to North Korea human rights and inter-Korean NGOs. Lazarus also breached at least six South Korean organizations through Operation SyncHole, a watering-hole campaign exploiting South Korean software components including Innorix Agent and Cross EX. Reported Lazarus tooling includes ThreatNeedle, wAgent, Agamemnon downloader, SIGNBT, and COPPERHEDGE, with victims in software, IT, finance, semiconductor manufacturing, and telecommunications.

Related Actors

Related Reports

2025-04-24 • 60% Match
#ThreatNeedle #LPEClient #SIGNBT #AGAMEMNON #Lazarus #Innorix #SyncHole #CrossEX #T1027.013 #T1082 #T1140 #T1071.001 #T1083 #T1057 #T1583.003 #T1583.001 #T1105 #T1620 #T1574.002 #T1135 #T1573.001 #T1190 #T1189 #T1049 #T1573.002 #T1016 #T1087.001 #T1218.011 #T1584.001 #T1574.001 #T1564.004 #T1027.009 #T1569.002 #T1543.003 #T1087.002 #T1570 #T1608.004 #T1547.005 #T1007
Shares tags: Lazarus, SyncHole • Published within a month
« Back