APT Spear-Phishing Campaign Targeting South Korean Entities (April 2026) — LNK/PowerShell Loaders, AutoIt, XenoRAT, Infostealers/Keyloggers/Backdoors — Threadlinqs Intelligence
As of 2026-06-09, APT Spear-Phishing Campaign Targeting South Korean Entities (April 2026) — LNK/PowerShell Loaders, AutoIt, XenoRAT, Infostealers/Keyloggers/Backdoors is a high-severity apt threat attributed to a North Korea (suspected, low confidence)-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 24 indicators of compromise.
Threat ID: TL-2026-0744 · Severity: HIGH · Status: ACTIVE · Category: APT
Attribution: North Korea (suspected, low confidence) · ESPIONAGE
AhnLab ASEC's April 2026 APT report documents an ongoing spear-phishing campaign against domestic South Korean targets. Five distinct attack chains (Types A–E) deliver LNK-triggered PowerShell loaders
AhnLab ASEC's monthly APT threat trend report for April 2026 (domestic South Korea) describes a spear-phishing campaign in which emails disguised as work-related business correspondence deliver malicious LNK shortcut files. Opening an LNK executes embedded PowerShell that initiates one of five observed attack chains.
Type A: A PowerShell command embedded in the LNK uses curl.exe (often renamed) to download a legitimate AutoIt interpreter together with a malicious AutoIt script and a decoy document. The AutoIt script provides command execution, directory enumeration, and file upload/download, and the chain registers a Task Scheduler task masquerading as a system update (e.g., OneDrive, browser updates) for persistence.
Type B: PowerShell inside the LNK extracts HEX-encoded data delimited by specific markers (NCFO, BCFO) to reconstruct and run a legitimate decoy document and a malicious script. C2 is conducted over PubNub channels keyed on the victim's computer name and username; results are Base64-encoded before exfiltration.
Type C: curl.exe downloads malicious HTA (HTML Application) files from GitHub repositories or Google Drive, which load Infostealer, Keylogger, and backdoor modules directly into memory.
Type D: LNK-embedded PowerShell generates Base64 data, accesses GitHub to retrieve and execute decoy files and scripts, and ultimately deploys XenoRAT — an open-source C# remote access trojan offering keylogging, webcam/microphone capture, HVNC, multiple UAC bypasses, SOCKS5 reverse proxy, and process injection — disguised as a browser update.
Type E: XML, VBS, and PowerShell scripts within the LNK establish Task Scheduler persistence and execute malicious Python scripts bundled inside compressed archives, enabling remote command execution and backdoor functionality.
Successful compromise results in backdoor installation, infostealer/keylogger activity, system information leakage, and full system control. AhnLab detected the components as Backdoor/Win.Agent.C5882829, Infostealer/Win.Agent.C5882827, and Trojan variants (LNK.Agent, PS.Agent, HTA.Agent, VBS.Agent, XML.Task). The report does not formally attribute the activity; however, the victimology (South Korean entities), LNK/PowerShell/AutoIt tradecraft, abuse of cloud services for C2, and deployment of XenoRAT are consistent with North Korea–nexus espionage activity (XenoRAT/MoonPeak has been publicly linked to the Kimsuky group), so attribution is assessed at LOW confidence.
Target sectors: government, defense, academia, think-tanks
Target regions: South Korea, East Asia
Detections & IOCs
As of 2026-08-15, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 24 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
6 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
APT, HIGH, threat intelligence, cybersecurity, T1566, T1204, T1059, T1053, T1036, T1027, T1140, T1218, T1055, T1548