AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and Script-Based Backdoors
AhnLab ASEC August 2026 APT Attack Trend Report (South (TL-2026-2800), also tracked as AhnLab ASEC August 2026 Domestic APT Trend, is a high-severity advanced persistent threat campaign, first published 2026-09-30. It has no confirmed attribution, affects Microsoft Windows (LNK, PowerShell, Task Scheduler, curl.exe, mshta), maps to 16 MITRE ATT&CK techniques (T1036.004, T1053.005, T1055), and is covered by 9 detection rules and 29 indicators of compromise.
Key facts for TL-2026-2800
- Threat ID
- TL-2026-2800
- Also known as
- AhnLab ASEC August 2026 Domestic APT Trend
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- 2026-09-30
- Last reviewed
- 2026-09-30
- Attribution confidence
- LOW
- Motivation
- ESPIONAGE
- Target sectors
- government administration, defense, research, general-enterprise, cryptocurrency
- Target regions
- south korea
- Detection rules
- 9
- Indicators of compromise
- 29
Malware and tooling in AhnLab ASEC August 2026 APT Attack Trend Report (South
Malware and tooling: Backdoor/Python.Agent, Downloader/BAT.Agent, Dropper/LNK.Generic, Rakhni, Trojan/HWP.Agent, Trojan/LNK.Agent, Trojan/PowerShell.Agent, Trojan/VBS.Agent, XenoRAT, AutoIt, curl.exe
AhnLab ASEC's monthly report on APT activity against South Korean targets describes six spear-phishing-driven attack types (A-F) in August 2026, mostly malicious LNK files that drop decoy documents and deploy AutoIt, PowerShell, VBS, BAT and Python backdoors, XenoRAT variants, and DLL side-loaded implants. The report names no threat actor.
How AhnLab ASEC August 2026 APT Attack Trend Report (South works
AhnLab Security Emergency response Center (ASEC) published its August 2026 domestic APT trend report on 2026-09-30, classifying the month's APT attacks against South Korean targets by delivery chain. Spear phishing with malicious LNK files dominates.
Type A: an LNK embeds a PowerShell script that restores HEX-encoded data into a legitimate decoy document, a legitimate AutoIt interpreter and a malicious AutoIt script. The script runs from C:\ProgramData and persists through a scheduled task disguised as a OneDrive update. Commands are retrieved through PubNub channels, and collected data is sent out Base64-encoded.
Type B: Windows-native curl.exe downloads a malicious HTA file into %TEMP%. The HTA is hosted on GitHub repositories or Google Drive. It creates decoy files and a downloader named sys.dll, which loads infostealers, keyloggers and backdoors into memory.
Type C: LNK-embedded PowerShell writes Base64 data in %temp% and executes it, pulls decoy files and further malicious scripts from GitHub, creates scheduled tasks, exfiltrates system information and deploys XenoRAT-type malware.
Type D: LNK files masquerading as resumes or other documents carry a legitimate decoy plus malicious PowerShell. They generate VBS, BAT and PowerShell scripts registered in Task Scheduler, download supplementary files and use DLL side-loading to inject a backdoor into legitimate processes.
Type E: LNK files use CMD and PowerShell to copy curl.exe into %TEMP% and download further files, including a decoy PDF and a BAT downloader. The BAT installs Python packages and registers pythonw.exe in Task Scheduler, which runs a Python backdoor that executes attacker commands.
Type F: OLE objects embedded in HWP (Hangul Word Processor) documents carry attachment links. Opening a link writes object files to %TEMP% and launches a legitimate tool that loads a malicious version.dll by DLL side-loading, followed by BAT scripts and a PowerShell backdoor.
The report lists five MD5 hashes and five C2/download URLs across cwmodern.com, dolgicap.com and dpaper.dothome.co.kr. AhnLab detection names are Backdoor/Python.Agent, Downloader/BAT.Agent, Dropper/LNK.Generic, Trojan/LNK.Agent, Trojan/PowerShell.Agent, Trojan/VBS.Agent and Trojan/HWP.Agent. The article states no CVEs and no attribution. The related July 2026 report likewise names no group, uses the same Type A-F taxonomy, and cites GitHub, Google Drive, Dropbox and PubNub as infrastructure. Severity is an analyst assessment.
MITRE ATT&CK techniques used in TL-2026-2800
Defense Evasion
T1036.004 Masquerade Task or Service; T1055 Process Injection; T1140 Deobfuscate/Decode Files or Information; T1218.005 Mshta; T1574.001 DLL
Persistence
Collection
Execution
T1059.001 PowerShell; T1059.003 Windows Command Shell; T1059.005 Visual Basic; T1059.006 Python; T1059.010 AutoHotKey & AutoIT; T1204.002 Malicious File
Discovery
T1082 System Information Discovery
Command and Control
T1102.002 Bidirectional Communication
Initial Access
Affected products and versions in AhnLab ASEC August 2026 APT Attack Trend Report (South
- Microsoft — Windows (LNK, PowerShell, Task Scheduler, curl.exe, mshta)
Vulnerable versions: Not version-specific; abuse of built-in functionality - Hancom — Hangul Word Processor (HWP) documents with embedded OLE objects
Vulnerable versions: Not specified in source
Remediation for AhnLab ASEC August 2026 APT Attack Trend Report (South
Immediate actions
- Block the listed C2/download URLs and domains (cwmodern.com, dolgicap.com, dpaper.dothome.co.kr) at proxy and DNS
- Hunt for the listed MD5 hashes and for scheduled tasks named like OneDrive updates that run AutoIt, pythonw.exe or scripts from C:\ProgramData or %TEMP%
- Quarantine inbound LNK attachments and LNK files inside archives; alert on LNK-spawned powershell.exe, cmd.exe, curl.exe or mshta.exe
Workarounds
- Disable HWP OLE object auto-execution and enforce Protected View / attachment prompts
- Block LNK and HTA attachments at the mail gateway
Longer-term hardening
- Restrict execution of curl.exe, mshta.exe and wscript/cscript from user-writable paths via application control
- Monitor or restrict outbound access to PubNub, GitHub raw content and Google Drive from endpoints that have no business need
- Deploy EDR rules for DLL side-loading (version.dll, sys.dll loaded from %TEMP% or ProgramData) and for HWP documents with embedded OLE objects
- Train users in Korean-language targets on resume- and document-themed spear phishing
Timeline of AhnLab ASEC August 2026 APT Attack Trend Report (South
- During August 2026, Type E (curl.exe copy, BAT downloader, pythonw.exe Python backdoor via Task Scheduler) and Type F (HWP with embedded OLE object, version.dll side-loading, BAT and PowerShell backdoor) observed (exact dates not stated in source)
- During August 2026, Type C (GitHub-sourced scripts, scheduled tasks, XenoRAT variants) and Type D (resume-themed LNK, VBS/BAT/PowerShell in Task Scheduler, DLL side-loading injection) observed (exact dates not stated in source)
- During August 2026, Type A (LNK PowerShell restoring decoy, AutoIt and malicious AutoIt script; OneDrive-update-disguised scheduled task; PubNub commands) and Type B (curl.exe pulling HTA from GitHub/Google Drive; sys.dll in-memory loader) observed (exact dates not stated in source)
- AhnLab ASEC begins the August 2026 monitoring window for domestic (South Korea) APT attacks; observed activity is spear phishing with malicious LNK files (approximate start of the reporting month)
- End of the August 2026 monitoring window covered by the ASEC report
- AhnLab ASEC publishes the August 2026 domestic APT attack trends report with MD5 hashes, C2 URLs and detection names
Sources cited for AhnLab ASEC August 2026 APT Attack Trend Report (South
- AhnLab ASEC: August 2026 APT Attack Trends Report (Domestic)
- AhnLab ASEC: July 2026 Threat Trend Report on APT Attacks (South Korea)
- AhnLab ASEC: June 2026 Threat Trend Report on APT Attacks (South Korea)
- AhnLab ASEC: May 2026 Threat Trend Report on APT Attacks (South Korea)
- AhnLab ASEC: April 2026 Threat Trend Report on APT Attacks (South Korea)
- AhnLab ASEC: March 2026 APT Attack Trends Report (Domestic)
- AhnLab ASEC: Malicious LNK Files Distributing a Python-Based Backdoor (Kimsuky Group) - related prior reporting
More in apt
- Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukraine
- Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)
- Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend Compromise and Authorization-Flow Abuse
- Nation-State Intrusions into Telecom Infrastructure via SS7, BGP Hijacking, and Router Compromise (Salt Typhoon)
- Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains WordPress wp2shell, Zyxel GS1900, and Ubiquiti UniFi OS Flaws to Steal Government Data
Detection coverage for TL-2026-2800
As of 2026-09-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2800 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-2800
2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.