AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and Script-Based Backdoors

AhnLab ASEC August 2026 APT Attack Trend Report (South (TL-2026-2800), also tracked as AhnLab ASEC August 2026 Domestic APT Trend, is a high-severity advanced persistent threat campaign, first published 2026-09-30. It has no confirmed attribution, affects Microsoft Windows (LNK, PowerShell, Task Scheduler, curl.exe, mshta), maps to 16 MITRE ATT&CK techniques (T1036.004, T1053.005, T1055), and is covered by 9 detection rules and 29 indicators of compromise.

Key facts for TL-2026-2800

Threat ID
TL-2026-2800
Also known as
AhnLab ASEC August 2026 Domestic APT Trend
Severity
HIGH
Status
ACTIVE
Category
APT
First published
2026-09-30
Last reviewed
2026-09-30
Attribution confidence
LOW
Motivation
ESPIONAGE
Target sectors
government administration, defense, research, general-enterprise, cryptocurrency
Target regions
south korea
Detection rules
9
Indicators of compromise
29

Malware and tooling in AhnLab ASEC August 2026 APT Attack Trend Report (South

Malware and tooling: Backdoor/Python.Agent, Downloader/BAT.Agent, Dropper/LNK.Generic, Rakhni, Trojan/HWP.Agent, Trojan/LNK.Agent, Trojan/PowerShell.Agent, Trojan/VBS.Agent, XenoRAT, AutoIt, curl.exe

AhnLab ASEC's monthly report on APT activity against South Korean targets describes six spear-phishing-driven attack types (A-F) in August 2026, mostly malicious LNK files that drop decoy documents and deploy AutoIt, PowerShell, VBS, BAT and Python backdoors, XenoRAT variants, and DLL side-loaded implants. The report names no threat actor.

How AhnLab ASEC August 2026 APT Attack Trend Report (South works

AhnLab Security Emergency response Center (ASEC) published its August 2026 domestic APT trend report on 2026-09-30, classifying the month's APT attacks against South Korean targets by delivery chain. Spear phishing with malicious LNK files dominates.

Type A: an LNK embeds a PowerShell script that restores HEX-encoded data into a legitimate decoy document, a legitimate AutoIt interpreter and a malicious AutoIt script. The script runs from C:\ProgramData and persists through a scheduled task disguised as a OneDrive update. Commands are retrieved through PubNub channels, and collected data is sent out Base64-encoded.

Type B: Windows-native curl.exe downloads a malicious HTA file into %TEMP%. The HTA is hosted on GitHub repositories or Google Drive. It creates decoy files and a downloader named sys.dll, which loads infostealers, keyloggers and backdoors into memory.

Type C: LNK-embedded PowerShell writes Base64 data in %temp% and executes it, pulls decoy files and further malicious scripts from GitHub, creates scheduled tasks, exfiltrates system information and deploys XenoRAT-type malware.

Type D: LNK files masquerading as resumes or other documents carry a legitimate decoy plus malicious PowerShell. They generate VBS, BAT and PowerShell scripts registered in Task Scheduler, download supplementary files and use DLL side-loading to inject a backdoor into legitimate processes.

Type E: LNK files use CMD and PowerShell to copy curl.exe into %TEMP% and download further files, including a decoy PDF and a BAT downloader. The BAT installs Python packages and registers pythonw.exe in Task Scheduler, which runs a Python backdoor that executes attacker commands.

Type F: OLE objects embedded in HWP (Hangul Word Processor) documents carry attachment links. Opening a link writes object files to %TEMP% and launches a legitimate tool that loads a malicious version.dll by DLL side-loading, followed by BAT scripts and a PowerShell backdoor.

The report lists five MD5 hashes and five C2/download URLs across cwmodern.com, dolgicap.com and dpaper.dothome.co.kr. AhnLab detection names are Backdoor/Python.Agent, Downloader/BAT.Agent, Dropper/LNK.Generic, Trojan/LNK.Agent, Trojan/PowerShell.Agent, Trojan/VBS.Agent and Trojan/HWP.Agent. The article states no CVEs and no attribution. The related July 2026 report likewise names no group, uses the same Type A-F taxonomy, and cites GitHub, Google Drive, Dropbox and PubNub as infrastructure. Severity is an analyst assessment.

MITRE ATT&CK techniques used in TL-2026-2800

Defense Evasion

T1036.004 Masquerade Task or Service; T1055 Process Injection; T1140 Deobfuscate/Decode Files or Information; T1218.005 Mshta; T1574.001 DLL

Persistence

T1053.005 Scheduled Task

Collection

T1056.001 Keylogging

Execution

T1059.001 PowerShell; T1059.003 Windows Command Shell; T1059.005 Visual Basic; T1059.006 Python; T1059.010 AutoHotKey & AutoIT; T1204.002 Malicious File

Discovery

T1082 System Information Discovery

Command and Control

T1102.002 Bidirectional Communication

Initial Access

T1566.001 Spearphishing Attachment

Affected products and versions in AhnLab ASEC August 2026 APT Attack Trend Report (South

  • Microsoft — Windows (LNK, PowerShell, Task Scheduler, curl.exe, mshta)
    Vulnerable versions: Not version-specific; abuse of built-in functionality
  • Hancom — Hangul Word Processor (HWP) documents with embedded OLE objects
    Vulnerable versions: Not specified in source

Remediation for AhnLab ASEC August 2026 APT Attack Trend Report (South

Immediate actions

  • Block the listed C2/download URLs and domains (cwmodern.com, dolgicap.com, dpaper.dothome.co.kr) at proxy and DNS
  • Hunt for the listed MD5 hashes and for scheduled tasks named like OneDrive updates that run AutoIt, pythonw.exe or scripts from C:\ProgramData or %TEMP%
  • Quarantine inbound LNK attachments and LNK files inside archives; alert on LNK-spawned powershell.exe, cmd.exe, curl.exe or mshta.exe

Workarounds

  • Disable HWP OLE object auto-execution and enforce Protected View / attachment prompts
  • Block LNK and HTA attachments at the mail gateway

Longer-term hardening

  • Restrict execution of curl.exe, mshta.exe and wscript/cscript from user-writable paths via application control
  • Monitor or restrict outbound access to PubNub, GitHub raw content and Google Drive from endpoints that have no business need
  • Deploy EDR rules for DLL side-loading (version.dll, sys.dll loaded from %TEMP% or ProgramData) and for HWP documents with embedded OLE objects
  • Train users in Korean-language targets on resume- and document-themed spear phishing

Timeline of AhnLab ASEC August 2026 APT Attack Trend Report (South

  • During August 2026, Type E (curl.exe copy, BAT downloader, pythonw.exe Python backdoor via Task Scheduler) and Type F (HWP with embedded OLE object, version.dll side-loading, BAT and PowerShell backdoor) observed (exact dates not stated in source)
  • During August 2026, Type C (GitHub-sourced scripts, scheduled tasks, XenoRAT variants) and Type D (resume-themed LNK, VBS/BAT/PowerShell in Task Scheduler, DLL side-loading injection) observed (exact dates not stated in source)
  • During August 2026, Type A (LNK PowerShell restoring decoy, AutoIt and malicious AutoIt script; OneDrive-update-disguised scheduled task; PubNub commands) and Type B (curl.exe pulling HTA from GitHub/Google Drive; sys.dll in-memory loader) observed (exact dates not stated in source)
  • AhnLab ASEC begins the August 2026 monitoring window for domestic (South Korea) APT attacks; observed activity is spear phishing with malicious LNK files (approximate start of the reporting month)
  • End of the August 2026 monitoring window covered by the ASEC report
  • AhnLab ASEC publishes the August 2026 domestic APT attack trends report with MD5 hashes, C2 URLs and detection names

Sources cited for AhnLab ASEC August 2026 APT Attack Trend Report (South

More in apt

Detection coverage for TL-2026-2800

As of 2026-09-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2800 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-2800

2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats