Korea APT & Malware Monitoring

Topic Collection / Korea Signals

Korea APT & Malware Monitoring

English-language monitoring for Korean APT, malware, ransomware, phishing, dark-web, vulnerability, KISA/KrCERT, and AhnLab security signals. This page turns Korea records into a reusable analyst entry point instead of leaving them buried in the live tracker.

51Korea records
41High importance
25Malware/APT signals
20Ransomware overlap
87Top entities

Server-Rendered Workflow Proof

Korea APT and malware workflow is backed by source-linked database records.

Workflow pages now render a live proof panel before JavaScript runs. The panel uses the public database summary plus a capped matching record slice, so external checks see a working monitoring product rather than a static article.

Total public records3,033Public source-linked rows
Rendered workflow slice51Matching records before hydration
Core JP/KR/TW records1,844Taiwan, Japan, Korea focus
Added / seen in 24h141Latest 2026-08-14 13:37

Summary generated 2026-08-14 14:12. Slice regions 1, source families 0. Public exports are capped; full feeds and historical access remain request-only.

Workflow Status

Korea APT/malware workflow

This page is a saved tracker-backed workflow for Korea threat monitoring. A zero-record state means no public tracker records matched this rendered slice, not that Korea source monitoring is disabled.

Rendered records are capped public samples from the tracker. Use exports or API access for repeat monitoring, and verify source-linked records before operational decisions.

StatusActive tracker slice
Rendered records51
High-importance records41
Published briefs38
Regions in slice1
Source families0
Latest rendered record2026-08-12

What this collection covers

Korea security records from KISA/KrCERT, AhnLab, and related public sources. The collection emphasizes domestic Korean threat reports, malware activity, vulnerability notices, dark-web intelligence, phishing/smishing campaigns, ransomware, and Korean infrastructure or enterprise-security context that global English feeds may miss.

How analysts should use it

Start with the highest-priority records, then filter by entity, sector, or keyword. Treat the page as a recurring monitoring workflow: export records for weekly reviews, subscribe to the RSS preset, and open source-linked articles when a signal requires deeper context.

51 rendered Korea records. Source data remains tracker-first; only strong records become articles.

Priority Korea signals

High / Security

ASEC Weekly Report Highlights DragonForce, Qilin, and ShinyHunters Activity Across Education, Manufacturing, and Healthcare Sectors in August 2026

ASEC’s August 12, 2026 threat report details ransomware attacks by DragonForce on a Korean online education provider and Qilin on a Korean motor/robotics manufacturer, alongside ShinyHunters’ data theft claim against a U.S. digital healthcare firm, reflecting ongoing regional ransomware trends targeting critical sectors in East Asia and North America.

2026-08-12 / Korea / Korean
Medium / Security

July 2026 Dark Web Breach Trend Report Highlights South Korea and Global Data Leak Patterns

AhnLab’s July 2026 Dark Web Breach Incident Trend Report identifies confirmed and unverified data breach claims across South Korea’s manufacturing, distribution, IT, and education sectors, alongside global leaks of government/military data and internal source code from GitHub, with caution advised due to AI-generated false posts.

2026-08-10 / Korea / En / ShinyHunters
High / Security

South Korean Industrial Firms Face Ransomware and Dark Web Exposure in Early August 2026

In the first week of August 2026, ASEC reported two South Korean manufacturers — one in automotive parts and another in heavy equipment and advanced materials — had internal server access and databases offered for sale on the dark web, while one was hit by the Gunra ransomware. A Turkish HR consulting firm’s data was also leaked. These incidents highlight ongoing ransomware and data extortion threats targeting ind...

2026-08-05 / Korea / En
High / Security

Korean Auto Parts and Heavy Equipment Firms Face Ransomware and Data Leak Threats in Early August 2026

ASEC reports Korean automotive parts and heavy equipment manufacturers experienced internal server access sales and Gunra ransomware attacks, while a Turkish HR consulting firm leaked client data on the dark web in the first week of August 2026.

2026-08-05 / Korea / Korean
High / Security

Larva-24009 Threat Actor’s 2026 Phishing Campaign Reveals Persistent Use of LNK Malware and Telegram-Based Exfiltration

ASEC’s analysis of a 2026 phishing email campaign by the Larva-24009 threat actor details how LNK files disguised as legitimate documents deploy PowerShell backdoors, QuasarRAT, UltraVNC, and NirSoft tools for credential theft, with persistence via scheduled tasks and exfiltration through the Telegram API, targeting users in Korea and globally.

2026-08-02 / Korea / En / AhnLab, Cyble
High / Security

South Korea Ransomware and Dark Web Activity Trends

While the state-sponsored group deployed backdoors (Struggle/SIGNBT 3.0 and Brandoor/COPPERHEDGE) for espionage, Gunra ransomware was used in parallel attacks for data encryption and exfiltration. Overlapping indicators—including SSH key fingerprints, network infrastructure, and watering hole domains—suggest shared TTPs, though ASEC concludes no definitive collaboration has been proven. The campaign, named 'Operat...

2026-07-29 / Korea / En / AhnLab, Gunra

Top entities

AhnLab 12 KISA 11 KrCERT/CC 7 ShinyHunters 3 Cisco 3 Robinhood 3 Prudential Financial 3 Microsoft 3 Central Bank of Libya 2 HDFC Asset Management Company 2 OneFly 2 Bridgepay 2

Top sectors

Cybersecurity 17 Government 9 cybersecurity 8 Healthcare 7 government 7 technology 6 healthcare 6 manufacturing 6 Education 5 education 5 Information Technology 4 Software Development 4

Searchable Korea records

Hhigh

2026-08-12 / Security

ASEC Weekly Report Highlights DragonForce, Qilin, and ShinyHunters Activity Across Education, Manufacturing, and Healthcare Sectors in August 2026

ASEC’s August 12, 2026 threat report details ransomware attacks by DragonForce on a Korean online education provider and Qilin on a Korean motor/robotics manufacturer, alongside ShinyHunters’ data theft claim against a U.S. digital healthcare firm, reflecting ongoing regional ransomware trends targeting critical sectors in East Asia and North America.

Sectors
Education, Healthcare, Manufacturing
Tags
Cyber Threat Intelligence, Dark Web, Data Breach, DragonForce, Qilin, Ransomware, ShinyHunters, South Korea
Cyber Threat IntelligenceDark WebData BreachDragonForceQilinRansomwareShinyHuntersSouth Korea
Open Nogosee brief
Mmedium

2026-08-10 / Security

July 2026 Dark Web Breach Trend Report Highlights South Korea and Global Data Leak Patterns

AhnLab’s July 2026 Dark Web Breach Incident Trend Report identifies confirmed and unverified data breach claims across South Korea’s manufacturing, distribution, IT, and education sectors, alongside global leaks of government/military data and internal source code from GitHub, with caution advised due to AI-generated false posts.

Entities
ShinyHunters
Sectors
IT, distribution, education, finance, government, healthcare
Tags
AI-generated false data, BreachForums, GitHub, ShinyHunters, South Korea, dark web, data breach, source code leak
AI-generated false dataBreachForumsGitHubShinyHuntersSouth Koreadark webdata breachsource code leak
Open public source
Hhigh

2026-08-05 / Security

South Korean Industrial Firms Face Ransomware and Dark Web Exposure in Early August 2026

In the first week of August 2026, ASEC reported two South Korean manufacturers — one in automotive parts and another in heavy equipment and advanced materials — had internal server access and databases offered for sale on the dark web, while one was hit by the Gunra ransomware. A Turkish HR consulting firm’s data was also leaked. These incidents highlight ongoing ransomware and data extortion threats targeting ind...

Sectors
advanced materials, automotive manufacturing, heavy equipment manufacturing, human resources consulting
Tags
Gunra, South Korea, Turkey, dark web, data leak, industrial cybersecurity, ransomware
GunraSouth KoreaTurkeydark webdata leakindustrial cybersecurityransomware
Open public source
Hhigh

2026-08-05 / Security

Korean Auto Parts and Heavy Equipment Firms Face Ransomware and Data Leak Threats in Early August 2026

ASEC reports Korean automotive parts and heavy equipment manufacturers experienced internal server access sales and Gunra ransomware attacks, while a Turkish HR consulting firm leaked client data on the dark web in the first week of August 2026.

Sectors
automotive manufacturing, heavy equipment manufacturing, human resources consulting
Tags
Gunra, South Korea, Turkey, dark web, data breach, ransomware
GunraSouth KoreaTurkeydark webdata breachransomware
Open public source
Hhigh

2026-08-02 / Security

Larva-24009 Threat Actor’s 2026 Phishing Campaign Reveals Persistent Use of LNK Malware and Telegram-Based Exfiltration

ASEC’s analysis of a 2026 phishing email campaign by the Larva-24009 threat actor details how LNK files disguised as legitimate documents deploy PowerShell backdoors, QuasarRAT, UltraVNC, and NirSoft tools for credential theft, with persistence via scheduled tasks and exfiltration through the Telegram API, targeting users in Korea and globally.

Entities
AhnLab, Cyble
Sectors
cybersecurity, threat intelligence
Tags
Korea, LNK malware, Larva-24009, MD5 hashes, NirSoft, PowerShell backdoor, QuasarRAT, Task Scheduler persistence
KoreaLNK malwareLarva-24009MD5 hashesNirSoftPowerShell backdoorQuasarRATTask Scheduler persistence
Open Nogosee brief
Hhigh

2026-07-29 / Security

South Korea Ransomware and Dark Web Activity Trends

While the state-sponsored group deployed backdoors (Struggle/SIGNBT 3.0 and Brandoor/COPPERHEDGE) for espionage, Gunra ransomware was used in parallel attacks for data encryption and exfiltration. Overlapping indicators—including SSH key fingerprints, network infrastructure, and watering hole domains—suggest shared TTPs, though ASEC concludes no definitive collaboration has been proven. The campaign, named 'Operat...

Entities
AhnLab, Gunra
Sectors
education, financial services, healthcare, manufacturing, media
Tags
SSH key, backdoor, financial software, ransomware, state-sponsored, supply chain, vulnerability, watering hole
SSH keybackdoorfinancial softwareransomwarestate-sponsoredsupply chainvulnerabilitywatering hole
Open Nogosee brief
Hhigh

2026-07-29 / Security

ASEC Highlights The Gentlemen Ransomware Attack on South Korean IT Distributor Amid Broader Dark Web Threats

ASEC Blog's Week 5, July 2026 report details a ransomware attack by The Gentlemen group on a South Korean IT software distributor and infrastructure service provider, alongside a Termite ransomware incident targeting a U.S. nonprofit healthcare provider and a ShinyHunters data leak claim involving a global accounting and consulting firm, underscoring persistent ransomware risks to technology service providers and ...

Sectors
cybersecurity, information-technology, infrastructure-services
Tags
ASEC, East Asia threat landscape, IT distribution, South Korea, The Gentlemen, dark web, infrastructure services, ransomware
ASECEast Asia threat landscapeIT distributionSouth KoreaThe Gentlemendark webinfrastructure servicesransomware
Open Nogosee brief
Hhigh

2026-07-29 / Security

Operation Double Barrel Links State-Backed Hackers and Gunra Ransomware via Shared Financial Software Exploits

A joint South Korean cybersecurity advisory reveals that state-backed hacking groups and the Gunra ransomware group exploited the same vulnerabilities in domestic financial security software between 2025 and mid-2026, sharing infrastructure, tools, and tactics despite differing final payloads—suggesting limited collaboration or tool reuse in attacks on media, education, healthcare, and manufacturing sectors.

Entities
AhnLab, Gunra
Sectors
education, financial, government, healthcare, manufacturing, media
Tags
Gunra ransomware, Operation Double Barrel, SSH key fingerprint, South Korea, backdoor, financial software vulnerability, spear phishing, state-backed hacking
Gunra ransomwareOperation Double BarrelSSH key fingerprintSouth Koreabackdoorfinancial software vulnerabilityspear phishingstate-backed hacking
Open public source
Hhigh

2026-07-29 / Security

Weekly Ransom & Dark Web Report Highlights Termite, ShinyHunters, and The Gentlemen Attacks

ASEC’s weekly report details ransomware attacks by Termite on a U.S. nonprofit healthcare provider, data leak claims by ShinyHunters against a global accounting firm, and The Gentlemen targeting a Korean IT software distributor and infrastructure builder, reflecting ongoing ransomware and data extortion trends.

Sectors
Accounting and Consulting, Healthcare, IT Infrastructure, IT Services
Tags
Dark Web, Data Breach, Ransomware, ShinyHunters, South Korea, Termite, The Gentlemen, USA
Dark WebData BreachRansomwareShinyHuntersSouth KoreaTermiteThe GentlemenUSA
Open public source
Hhigh

2026-07-27 / Security

AtlasRAT Loader Chain Reveals Builder-Based Malware Framework Targeting WeChat in East Asia

AhnLab ASEC details a four-stage in-memory loader chain for AtlasRAT, a Windows RAT using Delphi-based Flash Player lures, TLS-ChaCha20 C2, offline keylogging, and WeChat.exe DLL injection, with evidence pointing to a builder-based framework rather than a single operator, highlighting implications for regional threat monitoring.

Entities
AhnLab
Sectors
cybersecurity, malware analysis, threat intelligence
Tags
AtlasRAT, ChaCha20, East Asia threat, WeChat injection, builder framework, in-memory execution, loader chain, modular malware
AtlasRATChaCha20East Asia threatWeChat injectionbuilder frameworkin-memory executionloader chainmodular malware
Open Nogosee brief
Hhigh

2026-07-22 / Security

June 2026 Financial Sector Threat Analysis Reveals Multi-Stage Attack Chain Dominance

AhnLab's June 2026 report shows phishing as the top initial attack vector against financial institutions globally, followed by droppers/downloaders and infostealers, with HTML-based smuggling and script-based execution prevalent. Dark web markets actively traded financial data from Canada Life, Robinhood, Prudential, Robinhood, and AYA Bank, while ransomware groups like Lapsus$ and MORPHEUS claimed large-scale dat...

Entities
AYA Bank Public Company Limited, Bridgepay, Canada Life, Central Bank of Libya, HDFC Asset Management Company, OneFly
Sectors
asset management, banking, cybercrime underground, financial services, insurance
Tags
HTML smuggling, LOLBins, Telegram exfiltration, dark web, data leak, dropper, financial threat, infostealer
HTML smugglingLOLBinsTelegram exfiltrationdark webdata leakdropperfinancial threatinfostealer
Open Nogosee brief
Hhigh

2026-07-16 / Security

Kimsuky Group Uses Diplomatic Impersonation to Deploy PebbleDash and PrxClient in 2026 Spear Phishing Campaigns

The Kimsuky threat group has resumed spear phishing attacks in 2026 by impersonating diplomatic personnel to deploy PebbleDash backdoor and PrxClient proxy malware, using LNK droppers and HTA scripts to establish persistence, exfiltrate data, and enable remote access via RDP wrapper and UAC bypass tools.

Entities
AhnLab
Sectors
defense, education, government, technology
Tags
Kimsuky, LNK malware, PebbleDash, PrxClient, RDP wrapper, UAC bypass, backdoor, diplomatic impersonation
KimsukyLNK malwarePebbleDashPrxClientRDP wrapperUAC bypassbackdoordiplomatic impersonation
Open public source
Hhigh

2026-07-16 / Security

Korea Issues Alert on Credential Exposure in DevOps Environments

KrCERT/CC warns that hardcoded credentials in source code and collaboration tools are leading to unauthorized access, data leaks, and supply chain risks in Korean organizations, urging immediate credential rotation and enhanced monitoring.

Sectors
finance, government, healthcare, technology
Tags
DevOps, KISA, KrCERT/CC, cloud security, credential security, supply chain risk
DevOpsKISAKrCERT/CCcloud securitycredential securitysupply chain risk
Open public source
Mmedium

2026-07-15 / Security

ASEC Weekly Report Maps Ransomware Threats Across Japan Transportation, Food Supply Chains, and Saudi Chemical Sector

ASEC's Week 3, July 2026 threat summary documents three geographically and sectorally distinct cyber incidents: an AiLock ransomware attack on Japan's largest taxi and limousine operator, a cyberattack disrupting operations at Japan's largest frozen food company with cascading supply chain effects, and a DragonForce ransomware incident targeting a Saudi Arabian chemical manufacturer. The report presents these as s...

Sectors
Chemical Manufacturing, Food Manufacturing, Logistics, Transportation
Tags
AiLock, Cyberattack, DragonForce, Japan, Ransomware, Saudi Arabia, Supply Chain
AiLockCyberattackDragonForceJapanRansomwareSaudi ArabiaSupply Chain
Open Nogosee brief
Hhigh

2026-07-15 / Security

ASEC June 2026 Report Details Multi-Stage Financial Sector Threats with Telegram Exfiltration and Dark Web Data Trading

In June 2026, ASEC documented a multi-stage threat campaign targeting the Korean financial sector, where phishing via HTML attachments initiated attacks, droppers/downloaders delivered secondary payloads, and infostealers exfiltrated data via Telegram, representing 5% of observed leaks, while dark web markets traded stolen data from global financial entities including Robinhood, Prudential, and AYA Bank, alongside...

Entities
AYA Bank Public Company Limited, Bridgepay, Central Bank of Libya, HDFC Asset Management Company, OneFly, Prudential Financial
Sectors
asset management, banking, cybercrime, financial, insurance
Tags
June 2026, Korea, Telegram, credential theft, dark web, data leak, droppers, financial sector
June 2026KoreaTelegramcredential theftdark webdata leakdroppersfinancial sector
Open Nogosee brief
Hhigh

2026-07-10 / Security

BreachForums Governance Crisis and Clone Forum Impersonation Reveal Dark Web Volatility in June 2026

In June 2026, BreachForums underwent leadership upheaval involving diencracked's return, conflict with HasanBroker experienced leadership instability as former operator diencracked returned, clashed with HasanBroker, announced retirement, and signaled ownership transfer to user L, raising governance concerns. Simultaneously, clone forums attempted to sell BreachForums infrastructure for $3,000 in cryptocurrency wh...

Entities
BlackForums, BreachForums, DaMaGeLiB, DarkForums, RAIDForums, ReHub
Sectors
cybercrime, dark web forums, illicit infrastructure
Tags
BlackForums, BreachForums, DaMaGeLiB, DarkForums, HasanBroker, L, RAIDForums, ReHub
BlackForumsBreachForumsDaMaGeLiBDarkForumsHasanBrokerLRAIDForumsReHub
Open Nogosee brief
Hhigh

2026-07-10 / Security

June 2026 Dark Web Breach Trends Report Highlights Global Data Leak Claims and AI-Generated Disinformation Risks

ASEC’s June 2026 Dark Web Breach Trends Report details widespread data leak claims across healthcare, finance, government, and AI platforms across North America, Europe, Middle East, Asia, and Latin America, while noting AI-generated disinformation and recycled posts undermine threat intelligence reliability in East Asia and globally.

Entities
Baker Distributing Company, Bank of America, Fidelity Finance, Fortinet, Keio University, Prudential Financial
Sectors
defense, education, energy, finance, government, healthcare
Tags
AI platform abuse, AI-generated disinformation, ASEC, Africa, AhnLab, Dark Web, Data Breach, East Asia
AI platform abuseAI-generated disinformationASECAfricaAhnLabDark WebData BreachEast Asia
Open public source
Hhigh

2026-07-09 / Security

Korean Phishing Campaign Uses CVE-2017-0199 to Deploy Remcos RAT via Steganographic PNG

ASEC identified a phishing campaign targeting Korean users with emails that uses malicious XLS files exploiting CVE-2017-0199 to deliver Remcos RAT through steganographic PNG files and obfuscated PowerShell.

Entities
AhnLab
Sectors
cybersecurity, threat intelligence
Tags
CVE-2017-0199, Korea, Remcos RAT, phishing, steganography
CVE-2017-0199KoreaRemcos RATphishingsteganography
Open public source
Mmedium

2026-07-08 / Security

Dark Web Data Leaks Highlight Global Healthcare and ICT Sector Exposure

ASEC Blog reports three separate data breaches appearing on cybercrime forums in early July 2026: Saudi Arabian medical records, an Irish ICT company leak, and a US healthcare insurer breach via LeakNet, all offered for sale on dark web marketplaces.

Sectors
Healthcare, Information and Communications Technology, Insurance
Tags
Cybercrime Forums, Dark Web, Data Breach, Data Leak, Ransomware
Cybercrime ForumsDark WebData BreachData LeakRansomware
Open public source
Hhigh

2026-06-29 / Security

AhnLab Details May 2026 Korean APT Campaigns Using LNK Files and Living-off-the-Land Techniques

AhnLab’s May 2026 report identifies spear phishing with malicious LNK files as the dominant APT infection vector in South Korea, detailing six attack types that abuse PowerShell, curl.exe, and legitimate Windows tools to deploy info-stealers, keyloggers, and backdoors via GitHub and Google Drive, while also noting CHM and JSE-based variants using regsvr32 and certutil for evasion.

Entities
AhnLab
Sectors
cybersecurity, technology
Tags
APT, Backdoor, CHM, GitHub, Google Drive, InfoStealer, JSE, Keylogger
APTBackdoorCHMGitHubGoogle DriveInfoStealerJSEKeylogger
Open Nogosee brief
Hhigh

2026-06-17 / Security

Converging Ransomware and Data Leak Threats Target South Korea's Critical Sectors in June 2026

In Week 3 of June 2026, South Korea faced a multi-vector cyber threat landscape as Qilin ransomware struck a big data solution provider, Anubis ransomware targeted a semiconductor equipment parts manufacturer, and confidential defense industry documents appeared for sale on the dark web forum Spear Forums, highlighting coordinated risks to national technological and security assets.

Sectors
big data, defense, semiconductor equipment
Tags
Anubis, Qilin, South Korea, Spear Forums, dark web, data leak, ransomware
AnubisQilinSouth KoreaSpear Forumsdark webdata leakransomware
Open Nogosee brief
Hhigh

2026-06-16 / Security

Malicious LNK Files Disguised as Privacy Consent Forms Target South Korean Users via Fileless PowerShell and Task Scheduler Abuse

AhnLab identifies a campaign distributing malicious LNK files masquerading as personal information consent forms to execute fileless PowerShell scripts, establish persistence via Windows Task Scheduler, deploy info-stealers and backdoors, and use decoy documents to evade detection, with observed TTP overlaps to Kimsuky-like activity.

Entities
AhnLab
Sectors
Cybersecurity, Defense, Energy, Finance, Government, Healthcare
Tags
East Asia, Kimsuky, Korea, Korean language lure, LNK file, PowerShell, Windows, backdoor loader
East AsiaKimsukyKoreaKorean language lureLNK filePowerShellWindowsbackdoor loader
Open Nogosee brief
Hhigh

2026-06-15 / Security

May 2026 APT Trends Highlight Developer Ecosystem and Runtime Exploitation as Key Attack Vectors

ASEC’s May 2026 APT report identifies supply chain, developer environment, and runtime abuse as dominant trends, with Lazarus exploiting Git hooks and CI/CD pipelines, Famous Chollima poisoning npm/Packagist branches, and MuddyWater leveraging Microsoft Teams and Quick Assist for credential theft. Groups like Gamaredon and UAC-0010 abused WinRAR CVE-2025-8088 against Ukrainian entities, while Chinese APTs targeted...

Entities
Amazon S3, AnyDesk, Cloudflare, DWAgent, Discord, Dropbox
Sectors
Cloud Services, Cryptocurrency, Defense, Diplomacy, Education, Energy
Tags
APT, CI/CD, ChatGPT, Cloud Atlas, Credential Theft, Cryptocurrency, Famous Chollima, Famous Sparrow
APTCI/CDChatGPTCloud AtlasCredential TheftCryptocurrencyFamous ChollimaFamous Sparrow
Open Nogosee brief
Hhigh

2026-06-10 / Security

ASEC Weekly Report Notes Black X Ransomware Activity and Education Platform Data Leak in June 2026

ASEC's Ransom & Dark Web Issues Week 2, June 2026 report documents Black X ransomware targeting Korean and U.S. organizations, a data leak from a South Korean education platform on BreachForums by threat actor Hasan, and exposure of French government messaging data on PwnForums, highlighting cross-sector dark web activity.

Sectors
Education, Government, Technology
Tags
BlackX, BreachForums, DarkWeb, DataLeak, EducationPlatform, France, PwnForums, Ransomware
BlackXBreachForumsDarkWebDataLeakEducationPlatformFrancePwnForumsRansomware
Open Nogosee brief
Hhigh

2026-06-10 / Security

KISA Advisory Highlights Regional Urgency for Microsoft June 2026 Patches Amid Privilege Escalation Surge

KISA and KrCERT/CC issued a June 10, 2026 advisory urging Korean organizations to apply Microsoft's June security updates addressing 17 vulnerabilities rated Critical or Important, including 11 Critical flaws enabling privilege escalation and remote code execution across Windows, Office, Azure, and SharePoint platforms.

Entities
KISA, KrCERT/CC, Microsoft
Sectors
cybersecurity, government, technology
Tags
Azure Kubernetes Service, KISA advisory, Korea, Microsoft Patch Tuesday, Remote Desktop Client, Windows DWM, privilege escalation, remote code execution
Azure Kubernetes ServiceKISA advisoryKoreaMicrosoft Patch TuesdayRemote Desktop ClientWindows DWMprivilege escalationremote code execution
Open Nogosee brief
Hhigh

2026-05-27 / Security

Japanese Education and Government Data Leaked on BreachForums in May 2026

In May 2026, customer data from a Japanese educational franchise and personnel records from a Japanese government agency for national civil servant administration were posted for sale on BreachForums by threat actor Hasan, according to ASEC Blog. The leak includes sensitive personal information and highlights ongoing risks to Japan’s education and public sectors from dark web data trafficking.

Sectors
Education, Government
Tags
BreachForums, Civil Servant Data, Dark Web, Data Breach, Educational Franchise, Japan, Personal Data Leak
BreachForumsCivil Servant DataDark WebData BreachEducational FranchiseJapanPersonal Data Leak
Open public source
Hhigh

2026-05-27 / Security

AI-Powered Hacking Tools Evolve from Assistants to Autonomous Attack Orchestrators

AI-driven hacking tools have evolved from basic phishing aids to autonomous systems that orchestrate attacks, embed AI in malware for real-time evasion, and exploit zero-days, lowering barriers for cybercriminals while increasing defensive complexity globally.

Entities
AWS, AhnLab, Anthropic, Google, OpenAI, PayPal
Sectors
artificial intelligence, cloud infrastructure, cybersecurity, financial services, healthcare
Tags
AI security, identity-centric security, malware evolution, threat intelligence, zero-day exploits
AI securityidentity-centric securitymalware evolutionthreat intelligencezero-day exploits
Open public source
Hhigh

2026-05-27 / Security

Japan Education Franchise and Government Data Leaked on BreachForums Ahead of 2026 FIFA World Cup

ASEC reports that customer data from a Japanese education franchise and personal data of Japanese national civil servants were found for sale on Hasan's BreachForums, alongside warnings of FIFA-themed phishing sites targeting the 2026 World Cup.

Sectors
Education, Government, Sports
Tags
BreachForums, Dark Web, Data Breach, FIFA World Cup, Japan, Phishing, Typosquatting
BreachForumsDark WebData BreachFIFA World CupJapanPhishingTyposquatting
Open public source
Hhigh

2026-05-20 / Security

ASEC Weekly Report Flags Ransomware on Nova and Dark Web Code Leak Claims in South Korea

ASEC’s Ransom & Dark Web Issues report for week 3 of May 2026 details a ransomware attack on South Korean cosmetics firm Nova, alleged data leakage from an open-source visualization platform attributed to CoinbaseCartel, and claimed source-code theft and sale from a developer platform by TeamPCP, based on AhnLab TIP monitoring.

Entities
CoinbaseCartel, Nova, TeamPCP
Sectors
cybersecurity, manufacturing, technology
Tags
ASEC, AhnLab, South Korea, cosmetics, dark web, data leak, ransomware, source code leak
ASECAhnLabSouth Koreacosmeticsdark webdata leakransomwaresource code leak
Open Nogosee brief
Hhigh

2026-04-12 / Security

Windows Web Server Exploitation Trends: Analysis of Q1 2026 Attack Patterns

AhnLab SEcurity intelligence Center (ASEC) reports persistent targeting of Windows-based IIS and Apache Tomcat servers in Q1 2026. Attackers, notably the Larva-26001 threat actor, utilize web shell command execution, privilege escalation exploits like JuicyPotato, and port-forwarding tools to seize control of infected systems through RDP-mediated access and internal network lateral movement.

Entities
AhnLab, Microsoft, Apache Software Foundation
Sectors
Cybersecurity, Cloud Computing, Information Technology
Tags
Apache Tomcat, IIS, Larva-26001, Port Forwarding, Privilege Escalation, RDP, Web Shell
Apache TomcatIISLarva-26001Port ForwardingPrivilege EscalationRDPWeb Shell
Open Nogosee brief
Hhigh

2026-05-10 / Security

AhnLab April 2026 Dark Web Intelligence: High-Value Defense and Aerospace Data Leak Trends

The April 2026 dark web landscape was dominated by the leak of critical aerospace, defense, and military intelligence, including Boeing Artemis and Virginia-class submarine data. Notable activity from threat groups like ShinyHunters and the resurgence of BreachForums highlighted high-risk exposure across technology, financial, and government sectors, alongside the increasing commoditization of Phishing-as-a-Servic...

Entities
Boeing, Cisco, ADT Inc., 7-Eleven, Coinbase Global Inc., Vercel Inc.
Sectors
Aerospace & Defense, Technology, Government, Finance, Healthcare, Energy
Tags
Cybersecurity, Dark Web, Data Breach, Infostealer, Malware-as-a-Service, Military Intelligence, ShinyHunters, Threat Intelligence
CybersecurityDark WebData BreachInfostealerMalware-as-a-ServiceMilitary IntelligenceShinyHuntersThreat Intelligence
Open Nogosee brief
Hhigh

2026-05-11 / Security

AhnLab April 2026 Report Highlights Surge in Targeted Critical Infrastructure Ransomware Attacks

The April 2026 Ransomware Threat Trend Report from AhnLab reveals a significant shift in ransomware operations, with groups increasingly focusing on critical infrastructure sectors. The report details heighted activity in the manufacturing, healthcare, and finance industries globally, alongside the emergence of new threat groups and sustained campaigns by established actors like Qilin and INC Ransom.

Entities
AhnLab, Qilin, DragonForce, INC Ransom
Sectors
Manufacturing, Healthcare, Finance, Cybersecurity, Critical Infrastructure
Tags
DLS, Data Breach, Dedicated Leak Sites, Global Security Trends, Ransomware, South Korea, Threat Intelligence
DLSData BreachDedicated Leak SitesGlobal Security TrendsRansomwareSouth KoreaThreat Intelligence
Open Nogosee brief
Mmedium

2026-05-13 / Security

Trojan and Phishing Dominate Korean Phishing Email Attachments in April 2026

In April 2026, Trojan malware accounted for 47% of phishing email attachments in South Korea, followed by phishing payloads at 39%, according to ASEC analysis. Attackers used social engineering lures like fake tax invoices and logistics notifications, with Trojans often delivered via double-extension files and phishing via HTML spoofs. The share of phishing malware rose from 21% to 39% month-over-month.

Sectors
energy, government, logistics, manufacturing
Tags
ASEC, South Korea, Trojan, email security, malware, phishing
ASECSouth KoreaTrojanemail securitymalwarephishing
Open Nogosee brief
Hhigh

2026-05-12 / Security

KISA Issues Urgent Warning on Smishing Exploiting Breached Travel Platform Data

South Korea's internet security agency, KISA, has issued an urgent advisory regarding highly targeted smishing attacks. Cybercriminals are using stolen data from hacked travel platforms, such as accommodation reservation details, to impersonate hotel staff. These attacks aim to deceive travelers into entering credit card information on fraudulent sites to avoid supposed booking cancellations, posing significant se...

Entities
KISA, KrCERT/CC
Sectors
Cybersecurity, Hospitality, Travel & Tourism, Financial Services
Tags
Booking Scams, Identity Theft, Personal Information Leak, Phishing, Smishing, South Korea
Booking ScamsIdentity TheftPersonal Information LeakPhishingSmishingSouth Korea
Open Nogosee brief
Hhigh

2026-05-12 / Security

cPanel and WP Squared Address Critical Security Vulnerabilities in Global Update

cPanel has released urgent security updates for cPanel & WHM and WP Squared to address three critical vulnerabilities: improper input validation, code injection, and symbolic link following. These flaws affect numerous legacy and current versions, potentially allowing unauthorized system access. Administrators should immediately verify their software versions and apply the recommended patches to mitigate the risk ...

Entities
cPanel, WebPros
Sectors
Cloud Infrastructure, Web Hosting, Cybersecurity
Tags
CVE-2026-29201, CVE-2026-29202, CVE-2026-29203, Infrastructure Security, Patch Management, Vulnerability Management
CVE-2026-29201CVE-2026-29202CVE-2026-29203Infrastructure SecurityPatch ManagementVulnerability Management
Open Nogosee brief
Hhigh

2026-05-12 / Security

Ollama Issues Security Update to Patch Critical Out-of-Bounds Read Vulnerability

Ollama has released a critical security update to address CVE-2026-7482, an out-of-bounds read vulnerability. KISA has issued an advisory recommending that users upgrade to version 0.17.1 or higher. The flaw could allow unauthorized memory access, necessitating immediate patching or temporary mitigation by restricting external API access and rotating keys.

Entities
Ollama
Sectors
Artificial Intelligence, Cybersecurity, Cloud Infrastructure
Tags
API Security, KISA, Large Language Models, Memory Safety, Vulnerability
API SecurityKISALarge Language ModelsMemory SafetyVulnerability
Open Nogosee brief
Hhigh

2026-05-08 / Security

Cisco Unity Connection Security Update Addresses Critical Path Traversal and SSRF Vulnerabilities

Cisco has released critical security patches for Cisco Unity Connection to address vulnerabilities including Path Traversal (CVE-2026-20034) and Server-Side Request Forgery (CVE-2026-20035). These flaws affect versions 12.5 through 15.0, potentially allowing unauthorized system access. Organizations are advised to upgrade to version 15SU4 or 14SU5 to mitigate these infrastructure risks.

Entities
Cisco, KISA
Sectors
Information Technology, Telecommunications, Cybersecurity
Tags
CVE-2026-20034, CVE-2026-20035, Network Infrastructure, Path Traversal, SSRF, Unified Communications, Vulnerability Management
CVE-2026-20034CVE-2026-20035Network InfrastructurePath TraversalSSRFUnified CommunicationsVulnerability Management
Open Nogosee brief
Hhigh

2026-05-07 / Security

KISA Issues Security Advisory for Critical Out-of-Bounds Write Vulnerability in Palo Alto Networks PAN-OS

Palo Alto Networks has released critical security updates addressing CVE-2026-0300, an out-of-bounds write vulnerability in its PAN-OS software. Affecting versions 10.2 through 12.1, the flaw poses significant risks to network infrastructure security. The Korea Internet & Security Agency (KISA) strongly recommends that organizations apply the specific hotfixes and maintenance releases provided to mitigate potentia...

Entities
Palo Alto Networks, Korea Internet & Security Agency (KISA)
Sectors
Cybersecurity, Cloud Infrastructure, Government, Enterprise Software
Tags
CVE-2026-0300, KISA, Network Security, Out-of-Bounds Write, PAN-OS, Vulnerability Management
CVE-2026-0300KISANetwork SecurityOut-of-Bounds WritePAN-OSVulnerability Management
Open Nogosee brief
Hhigh

2026-05-07 / Security

Cisco Security Advisory Addresses Critical Vulnerabilities in Crosswork, NSO, and ESA Systems

Cisco has released urgent security updates to address significant vulnerabilities in its networking and security product lines. The advisories cover denial-of-service risks in the Crosswork Network Controller and Network Services Orchestrator (NSO), as well as long-standing resource management issues in Cisco Email Security Appliance (ESA) running legacy AsyncOS software.

Entities
Cisco, KISA
Sectors
Cybersecurity, Infrastructure, Network Automation, Information Technology
Tags
CVE-2022-20653, CVE-2026-20188, Denial of Service, Email Security, Network Automation, Patch Management, Vulnerability Management
CVE-2022-20653CVE-2026-20188Denial of ServiceEmail SecurityNetwork AutomationPatch ManagementVulnerability Management
Open Nogosee brief
Mmedium

2026-04-22 / Security

ShinyHunters Claims U.S. Retail and Software Breaches; New Extortion Group Prinz Eugen Emerges

In Week 4 of April 2026, ShinyHunters claimed responsibility for data breaches targeting a major U.S. convenience store chain and a U.S. software development firm, while a new data extortion group, Prinz Eugen, emerged on the dark web, according to ASEC Blog.

Entities
Prinz Eugen, ShinyHunters
Sectors
cybercrime, retail, software development
Tags
ASEC, AhnLab, Prinz Eugen, ShinyHunters, dark web, data breach, extortion, ransomware
ASECAhnLabPrinz EugenShinyHuntersdark webdata breachextortionransomware
Open Nogosee brief
Mmedium

2026-04-22 / Security

South Korea APT Campaigns in March 2026 Rely on LNK Files and Multi-Stage Scripting

In March 2026, AhnLab observed South Korea-targeted APT attacks primarily using spear-phishing emails with LNK files to deploy malware via PowerShell, curl, HTA, and scripting chains, leading to info-stealers, keyloggers, and memory-resident backdoors.

Entities
AhnLab
Sectors
Critical Infrastructure, Cybersecurity, Government
Tags
APT, AutoIt, Backdoor, HTA, InfoStealer, Keylogger, LNK, PowerShell
APTAutoItBackdoorHTAInfoStealerKeyloggerLNKPowerShell
Open Nogosee brief
Mmedium

2026-04-15 / Security

New Ransomware Strains TiMC, BlackWater, Lamashtu Emerge Amid DDoS Claims and Social Engineering Campaigns

ASEC reports three new ransomware variants—TiMC, BlackWater, and Lamashtu—alongside NoName05716’s claimed DDoS attacks on South Korean public and private entities and the VECT·TeamPCP campaign targeting a Dutch travel booking platform via social engineering.

Sectors
Financial, Healthcare, Medical Device, Public Institution, Travel Booking Service
Tags
BlackWater, DDoS, Lamashtu, Netherlands, NoName05716, Ransomware, Social Engineering, South Korea
BlackWaterDDoSLamashtuNetherlandsNoName05716RansomwareSocial EngineeringSouth Korea
Open Nogosee brief
Hhigh

2026-04-12 / Security

ASEC Q1 2026 Report Reveals Larva-26002’s Shift to Go-Based ICE Cloud Scanner via BCP Exploitation

ASEC’s analysis of ASD logs for Q1 2026 shows persistent attacks on Windows-based MS-SQL and MySQL servers, with a temporary decline in February followed by a March rebound. The Larva-26002 threat actor was observed deploying the Go-written ICE Cloud scanner via BCP exploitation on mismanaged MS-SQL systems, continuing prior use of Trigona and Mimic ransomware. Turkish-language strings in the scanner align with ea...

Sectors
cloud infrastructure, database administration, enterprise IT, managed security services
Tags
BCP exploitation, Go-language malware, ICE Cloud scanner, Larva-26002, MS-SQL, MySQL, Turkish-language strings, Windows Server
BCP exploitationGo-language malwareICE Cloud scannerLarva-26002MS-SQLMySQLTurkish-language stringsWindows Server
Open Nogosee brief
Mmedium

2026-03-25 / Security

Japanese Automaker Data Breach and South Korean Steel Ransomware Attack Highlight East Asia Cyber Threats

In March 2026, a Japanese automaker suffered a personal data breach via unauthorized external access, while INC Ransom targeted a South Korean steel manufacturer in a ransomware attack. Simultaneously, the administrator of the LeakBase dark web forum was arrested in Russia. These incidents underscore ongoing cyber risks to manufacturing sectors in Japan and South Korea, with implications for supply chain security ...

Sectors
automotive, manufacturing, steel manufacturing
Tags
INC Ransom, Japan, LeakBase, South Korea, dark web, data breach, ransomware, threat actor arrest
INC RansomJapanLeakBaseSouth Koreadark webdata breachransomwarethreat actor arrest
Open Nogosee brief
Hhigh

2026-02-27 / Security

CVE-2026-24498: EFM-Networks ipTIME Routers Vulnerable to Wi-Fi Password Exposure

A security bypass vulnerability (CVE-2026-24498) in EFM-Networks ipTIME wireless routers allows unauthorized actors to extract Wi-Fi passwords in plaintext. Impacting multiple models including the T5008 and AX-series, the flaw bypasses internal security controls. Users must update to firmware version 15.27.2 or higher to remediate the risk of local credential theft.

Entities
EFM-Networks, KISA
Sectors
Consumer Electronics, Critical Infrastructure, Cybersecurity
Tags
CVE-2026-24498, Information Disclosure, Router Security, South Korea, Wi-Fi, ipTIME
CVE-2026-24498Information DisclosureRouter SecuritySouth KoreaWi-FiipTIME
Open Nogosee brief
Hhigh

2026-02-27 / Security

CVE-2026-24497: Critical Buffer Overflow in SimTech Systems ThinkWise Facilitates Remote Code Execution

A high-severity buffer overflow vulnerability (CVE-2026-24497) has been identified in SimTech Systems' ThinkWise mind-mapping software. Affecting versions 7 through 22, the flaw allows remote attackers to execute arbitrary code. Users are urged to upgrade to ThinkWise 23 immediately to mitigate the risk of complete system compromise via malicious file formats.

Entities
SimTech Systems, KISA
Sectors
Software, Cybersecurity, Infrastructure
Tags
Buffer Overflow, CVE-2026-24497, CWE-121, Enterprise Productivity, Remote Code Execution, South Korea Security, ThinkWise
Buffer OverflowCVE-2026-24497CWE-121Enterprise ProductivityRemote Code ExecutionSouth Korea SecurityThinkWise
Open Nogosee brief
Hhigh

2026-02-04 / Security

KISA Issues Warning for Type Confusion Vulnerability in Hancom Office

South Korea's KISA and KrCERT/CC have disclosed a high-severity type confusion vulnerability (CVE-2025-29867) in Hancom Office. The flaw resides in the DOC file processing logic, potentially allowing remote attackers to execute arbitrary code. Users of Hancom Office versions 2018 through 2024 must apply security updates to mitigate risks of system compromise through malicious documents.

Entities
Hancom, KISA, KrCERT/CC
Sectors
Cybersecurity, Public Sector, Software Development
Tags
CVE-2025-29867, Hancom Office, Remote Code Execution, South Korea Security, Type Confusion, Vulnerability
CVE-2025-29867Hancom OfficeRemote Code ExecutionSouth Korea SecurityType ConfusionVulnerability
Open Nogosee brief
Mmedium

2025-12-01 / Security

ALZip Vulnerability CVE-2025-29864 Bypass Windows Mark of the Web Defenses

A vulnerability in ESTsoft ALZip versions 12.01 through 12.29 fails to propagate 'Mark of the Web' (MoTW) Zone.Identifier streams when extracting files. This flaw, tracked as CVE-2025-29864, allows malicious content to bypass Windows security warnings, potentially leading to unauthorized code execution if users are tricked into opening unflagged malicious files.

Entities
ESTsoft, KISA, KrCERT/CC
Sectors
Cybersecurity, Software Development
Tags
ALZip, CVE-2025-29864, Mark of the Web, MoTW, South Korea, Vulnerability Disclosure
ALZipCVE-2025-29864Mark of the WebMoTWSouth KoreaVulnerability Disclosure
Open Nogosee brief
Hhigh

2025-08-01 / Security

CVE-2025-29866: Critical Improper Privilege Validation in Tagfree X-Free Uploader

A high-severity vulnerability (CVE-2025-29866) has been identified in Tagfree's X-Free Uploader, allowing unauthorized attackers to delete arbitrary files. With a CVSS score of 8.8, this improper privilege validation flaw enables data tampering and system disruption. South Korea's KISA recommends immediate patching to versions 1.0.1.0085 or 2.0.1.0035 to mitigate operational risks.

Entities
Tagfree, KISA, KrCERT/CC
Sectors
Software Development, Cybersecurity, Infrastructure
Tags
CVE-2025-29866, Data Tampering, File Management Security, Privilege Escalation, South Korea Security, Vulnerability
CVE-2025-29866Data TamperingFile Management SecurityPrivilege EscalationSouth Korea SecurityVulnerability
Open Nogosee brief
Hhigh

2025-07-31 / Security

CVE-2025-29865: Arbitrary File Download Vulnerability in Tagfree X-Free Uploader

KISA and KrCERT/CC have identified a high-severity arbitrary file download vulnerability in Tagfree X-Free Uploader. Designated as CVE-2025-29865, the flaw stems from insufficient validation of server communication parameters. If exploited, attackers could leak sensitive information or download arbitrary files. Users are urged to update to XFU versions 1.0.1.0085 or 2.0.1.0035.

Entities
Tagfree, KISA, KrCERT/CC
Sectors
Cybersecurity, Infrastructure Software
Tags
CVE-2025-29865, File Download Vulnerability, Information Leak, Software Supply Chain, X-Free Uploader
CVE-2025-29865File Download VulnerabilityInformation LeakSoftware Supply ChainX-Free Uploader
Open Nogosee brief
Mmedium

2024-11-05 / Security

Genians NAC SQL Injection Vulnerability Exposes Network Infrastructure to Data Disclosure

Genians has addressed CVE-2024-23843, a SQL injection vulnerability in its Genian NAC management console. The flaw stems from insufficient validation of user-supplied search parameters, potentially allowing unauthorized data exposure. Organizations using Genian NAC V5.0 or its LTS variants should upgrade to the latest versions to mitigate the risk of database compromise within their security infrastructure.

Entities
Genians, KISA, KrCERT/CC
Sectors
Cybersecurity, Infrastructure Software, Government
Tags
CVE-2024-23843, Information Disclosure, NAC, Network Access Control, SQL Injection, Vulnerability Management
CVE-2024-23843Information DisclosureNACNetwork Access ControlSQL InjectionVulnerability Management
Open Nogosee brief