Visualização normal

Hoje — 7 de Setembro de 2026ASEC BLOG
  • ✇ASEC BLOG
  • Detection and Removal of the Syslogk Rootkit in a Linux Environment ATCP
    1. Overview The AhnLab SEcurity intelligence Center (ASEC) continuously monitors various threats targeting Linux environments. Techniques that modify the Linux kernel to conceal malware and signs of compromise have been used for a long time, and Syslogk is one such rootkit that operates in this manner. This document provides an analysis of the key features […]
     

Detection and Removal of the Syslogk Rootkit in a Linux Environment

Por:ATCP
2 de Setembro de 2026, 12:00
1. Overview The AhnLab SEcurity intelligence Center (ASEC) continuously monitors various threats targeting Linux environments. Techniques that modify the Linux kernel to conceal malware and signs of compromise have been used for a long time, and Syslogk is one such rootkit that operates in this manner. This document provides an analysis of the key features […]
Antes de ontemASEC BLOG
  • ✇ASEC BLOG
  • Attack Cases in Korea Involving the Installation of Radmin and UltraVNC ATCP
    The AhnLab SEcurity intelligence Center (ASEC) recently identified attack cases that exploited Radmin and UltraVNC. Although the Initial Intrusion method remains unknown, the attackers installed Radmin—a remote control tool—and then installed UltraVNC. The threat actors exploited the remote control tools to gain control of the infected systems and installed Netch and CCProxy to use the […]
     

Attack Cases in Korea Involving the Installation of Radmin and UltraVNC

Por:ATCP
2 de Setembro de 2026, 12:00
The AhnLab SEcurity intelligence Center (ASEC) recently identified attack cases that exploited Radmin and UltraVNC. Although the Initial Intrusion method remains unknown, the attackers installed Radmin—a remote control tool—and then installed UltraVNC. The threat actors exploited the remote control tools to gain control of the infected systems and installed Netch and CCProxy to use the […]
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 1, September 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 1, September 2026           ZaWoo Data Extortion Attacks Against Multiple Organizations Worldwide Black X Ransomware Attack on a South Korean Automotive Parts Manufacturer Internal Data of a South Korean Asset Management and Investment Firm Offered for Sale
     

Ransom & Dark Web Issues Week 1, September 2026

Por:ATCP
2 de Setembro de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 1, September 2026           ZaWoo Data Extortion Attacks Against Multiple Organizations Worldwide Black X Ransomware Attack on a South Korean Automotive Parts Manufacturer Internal Data of a South Korean Asset Management and Investment Firm Offered for Sale
  • ✇ASEC BLOG
  • “Evasive” Malware Attack Tactics: Hiding, Bypassing, and Reappearing ATCP
      People who initially seem fine but tend to subtly avoid others as the relationship deepens or when conflicts arise—and who disappear when pressured—are commonly referred to as “avoidant types.” By repeatedly pulling away only to reappear, they drain the other person’s emotions and energy, ultimately undermining the relationship. The attack pattern of the recently […]
     

“Evasive” Malware Attack Tactics: Hiding, Bypassing, and Reappearing

Por:ATCP
1 de Setembro de 2026, 12:00
  People who initially seem fine but tend to subtly avoid others as the relationship deepens or when conflicts arise—and who disappear when pressured—are commonly referred to as “avoidant types.” By repeatedly pulling away only to reappear, they drain the other person’s emotions and energy, ultimately undermining the relationship. The attack pattern of the recently […]
  • ✇ASEC BLOG
  • Kim Sooki again? This time, it was disguised as a request for seafood ingredients ATCP
    A request to review the purchase of seafood ingredients arrived. When the file is opened, a normal hwp document appears, but while the user is reviewing the contents, a malicious script runs in the background and even registers a scheduled task. It then extracts system information to an external location, downloads and executes additional commands, […]
     

Kim Sooki again? This time, it was disguised as a request for seafood ingredients

Por:ATCP
1 de Setembro de 2026, 12:00
A request to review the purchase of seafood ingredients arrived. When the file is opened, a normal hwp document appears, but while the user is reviewing the contents, a malicious script runs in the background and even registers a scheduled task. It then extracts system information to an external location, downloads and executes additional commands, […]
  • ✇ASEC BLOG
  • July 2026 Threat Trend Report on APT Attacks (South Korea) ATCP
    Overview AhnLab monitored APT (Advanced Persistent Threat) attacks targeting entities in Korea using its own infrastructure. This report summarizes the classification, statistics, and functional characteristics for each type of domestic APT attacks identified during the month of July 2026. Trends of APT Attacks in South Korea Most APT attacks detected in South Korea were distributed […]
     

July 2026 Threat Trend Report on APT Attacks (South Korea)

Por:ATCP
27 de Agosto de 2026, 12:00
Overview AhnLab monitored APT (Advanced Persistent Threat) attacks targeting entities in Korea using its own infrastructure. This report summarizes the classification, statistics, and functional characteristics for each type of domestic APT attacks identified during the month of July 2026. Trends of APT Attacks in South Korea Most APT attacks detected in South Korea were distributed […]
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 4, August 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 4, August2026           Saudi Arabian Digital Entertainment Streaming Service User Data Offered for Sale SAFEPAY Ransomware Attack on a South Korean Industrial Gas Manufacturer and Supplier NoName057(16) and BD Anonymous Claim DDoS Attacks Against Major Japanese Organizations and Companies [1] [2] [3] […]
     

Ransom & Dark Web Issues Week 4, August 2026

Por:ATCP
26 de Agosto de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 4, August2026           Saudi Arabian Digital Entertainment Streaming Service User Data Offered for Sale SAFEPAY Ransomware Attack on a South Korean Industrial Gas Manufacturer and Supplier NoName057(16) and BD Anonymous Claim DDoS Attacks Against Major Japanese Organizations and Companies [1] [2] [3] […]
  • ✇ASEC BLOG
  • July 2026 Threat Trend Report on Ransomware ATCP
    Purpose and Scope The July 2026 Threat Trend Report on Ransomware summarizes major Korean & global ransomware issues based on statistics regarding the quantity of new ransomware samples, the number of compromised systems, and statistics on targeted businesses. Statistics on targeted businesses were compiled based on information published on DLS (Dedicated Leak Sites, also referred […]
     

July 2026 Threat Trend Report on Ransomware

Por:ATCP
23 de Agosto de 2026, 12:00
Purpose and Scope The July 2026 Threat Trend Report on Ransomware summarizes major Korean & global ransomware issues based on statistics regarding the quantity of new ransomware samples, the number of compromised systems, and statistics on targeted businesses. Statistics on targeted businesses were compiled based on information published on DLS (Dedicated Leak Sites, also referred […]
  • ✇ASEC BLOG
  • Security Issues in the Korean & Global Financial Sector in July 2026 ATCP
    Statistics on Malware Distributed to the Financial Sector In Attack Stage 1, phishing (a technique that tricks users into opening malicious links or attachments) had the highest rate at 1.7, Down from 2.3 The previous month. In Attack Stage 2, Dropper/Downloader (a type that downloads additional malware) was the most prevalent at 1.7, Up from […]
     

Security Issues in the Korean & Global Financial Sector in July 2026

Por:ATCP
9 de Agosto de 2026, 12:00
Statistics on Malware Distributed to the Financial Sector In Attack Stage 1, phishing (a technique that tricks users into opening malicious links or attachments) had the highest rate at 1.7, Down from 2.3 The previous month. In Attack Stage 2, Dropper/Downloader (a type that downloads additional malware) was the most prevalent at 1.7, Up from […]
  • ✇ASEC BLOG
  • July 2026 Infostealer Trend Report ATCP
    Content This report summarizes the distribution channels, number of Infostealers, number of detections, and target companies that were disguised as Infostealers collected during the month of July 2026. It was compiled based on results from AhnLab SEcurity intelligence Center (ASEC)’s automated data collection system, email honeypots, and automated C2 analysis, as well as diagnostic logs […]
     

July 2026 Infostealer Trend Report

Por:ATCP
11 de Agosto de 2026, 12:00
Content This report summarizes the distribution channels, number of Infostealers, number of detections, and target companies that were disguised as Infostealers collected during the month of July 2026. It was compiled based on results from AhnLab SEcurity intelligence Center (ASEC)’s automated data collection system, email honeypots, and automated C2 analysis, as well as diagnostic logs […]
  • ✇ASEC BLOG
  • July 2026 Threat Trend Report on APT Groups ATCP
    Purpose and Scope The July 2026 Threat Trend Report on APT Groups summarizes the trend in which state-sponsored threat actors and financially motivated attackers are employing a combination of supply chain attacks, account takeovers, cloud breaches, and social engineering techniques. Key targets include Microsoft 365, webmail accounts, cloud infrastructure, GitHub and development environments, VPN and […]
     

July 2026 Threat Trend Report on APT Groups

Por:ATCP
19 de Agosto de 2026, 12:00
Purpose and Scope The July 2026 Threat Trend Report on APT Groups summarizes the trend in which state-sponsored threat actors and financially motivated attackers are employing a combination of supply chain attacks, account takeovers, cloud breaches, and social engineering techniques. Key targets include Microsoft 365, webmail accounts, cloud infrastructure, GitHub and development environments, VPN and […]
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 3, August 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 3, August 2026         Customer and Operational Data of a South Korean Delivery Platform Offered for Sale Unauthorized Access Incident at a Japanese Cloud and Data Center Services Company ShinyHunters Threatens Data Disclosure Against a U.S. Live-Streaming Platform
     

Ransom & Dark Web Issues Week 3, August 2026

Por:ATCP
19 de Agosto de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 3, August 2026         Customer and Operational Data of a South Korean Delivery Platform Offered for Sale Unauthorized Access Incident at a Japanese Cloud and Data Center Services Company ShinyHunters Threatens Data Disclosure Against a U.S. Live-Streaming Platform
  • ✇ASEC BLOG
  • Beware of phishing emails disguised as requests to review quotes (PhantomStealer) ATCP
    The AhnLab SEcurity intelligence Center (ASEC) recently identified a phishing email campaign that disguised itself as a request to review a quote. The threat actor impersonated a sales team member at a specific overseas company and, by claiming that a previous quote needed to be revised and product versions verified, tricked recipients into opening the […]
     

Beware of phishing emails disguised as requests to review quotes (PhantomStealer)

Por:ATCP
11 de Agosto de 2026, 12:00
The AhnLab SEcurity intelligence Center (ASEC) recently identified a phishing email campaign that disguised itself as a request to review a quote. The threat actor impersonated a sales team member at a specific overseas company and, by claiming that a previous quote needed to be revised and product versions verified, tricked recipients into opening the […]
  • ✇ASEC BLOG
  • Attack Cases for Domestic Web Servers Running SoftEther VPN in Korea ATCP
    The AhnLab SEcurity intelligence Center (ASEC) recently identified attack cases in which attackers targeted web servers in Korea to install SoftEther VPN. Attack cases involving the installation of SoftEther VPN, an open-source VPN, were previously discussed in the 2024 ASEC blog post titled “Analysis of Attack Cases Targeting ERP Servers in Korea to Install SoftEther […]
     

Attack Cases for Domestic Web Servers Running SoftEther VPN in Korea

Por:ATCP
10 de Agosto de 2026, 12:00
The AhnLab SEcurity intelligence Center (ASEC) recently identified attack cases in which attackers targeted web servers in Korea to install SoftEther VPN. Attack cases involving the installation of SoftEther VPN, an open-source VPN, were previously discussed in the 2024 ASEC blog post titled “Analysis of Attack Cases Targeting ERP Servers in Korea to Install SoftEther […]
  • ✇ASEC BLOG
  • Beware of Phishing Emails Disguised as Transaction Receipts ATCP
    Recently, the AhnLab SEcurity intelligence Center (ASEC) identified instances of phishing emails that were disguised as transaction receipts. The emails impersonated employees of a specific US company. The body of the message stated that a transaction receipt was attached and asked the recipient to review it and confirm whether funds had been deposited into their […]
     

Beware of Phishing Emails Disguised as Transaction Receipts

Por:ATCP
9 de Agosto de 2026, 12:00
Recently, the AhnLab SEcurity intelligence Center (ASEC) identified instances of phishing emails that were disguised as transaction receipts. The emails impersonated employees of a specific US company. The body of the message stated that a transaction receipt was attached and asked the recipient to review it and confirm whether funds had been deposited into their […]
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 2, August 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 2, August 2026.           DragonForce Ransomware Attack on a South Korean Online Education Company Qilin Ransomware Attack on a South Korean Motor and Robotics Manufacturer ShinyHunters Claims Data Leak from a U.S. Digital Healthcare Company
     

Ransom & Dark Web Issues Week 2, August 2026

Por:ATCP
12 de Agosto de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 2, August 2026.           DragonForce Ransomware Attack on a South Korean Online Education Company Qilin Ransomware Attack on a South Korean Motor and Robotics Manufacturer ShinyHunters Claims Data Leak from a U.S. Digital Healthcare Company
  • ✇ASEC BLOG
  • July 2026 Dark Web Breach Incident Trend Report ATCP
    Note The July 2026 Dark Web Breach Incident Trend Report was compiled based on data breach cases posted on deep web and dark web forums. Due to the nature of some posts, it is difficult to fully verify their accuracy; some posts related to South Korea included AI-generated false data or cases where it could […]
     
  • ✇ASEC BLOG
  • July 2026 Dark Web Threat Actor Trend Report ATCP
    Note The July 2026 Dark Web Threat Actor Trend Report focuses on trends among threat actors—including hacktivists—active on the deep web and dark web. It is explicitly noted that the factual accuracy of some content could not be verified. Major Issues Handala claimed to have compromised the core infrastructure of an Internet service provider in […]
     

July 2026 Dark Web Threat Actor Trend Report

Por:ATCP
10 de Agosto de 2026, 12:00
Note The July 2026 Dark Web Threat Actor Trend Report focuses on trends among threat actors—including hacktivists—active on the deep web and dark web. It is explicitly noted that the factual accuracy of some content could not be verified. Major Issues Handala claimed to have compromised the core infrastructure of an Internet service provider in […]
  • ✇ASEC BLOG
  • July 2026 Dark Web Issue Trend Report ATCP
    Note The July 2026 Dark Web Issue Trend Report summarizes major issues that occurred on the deep web and dark web. Due to the nature of some sources, it may be difficult to fully verify the accuracy of certain information; therefore, it is necessary to cross-check these details against official announcements. Major Issues RaidForums changed […]
     

July 2026 Dark Web Issue Trend Report

Por:ATCP
10 de Agosto de 2026, 12:00
Note The July 2026 Dark Web Issue Trend Report summarizes major issues that occurred on the deep web and dark web. Due to the nature of some sources, it may be difficult to fully verify the accuracy of certain information; therefore, it is necessary to cross-check these details against official announcements. Major Issues RaidForums changed […]
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 1, August 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 1, August 2026           South Korean Automotive Parts Manufacturer’s Internal Server Access and Database Offered for Sale Data of a Turkish HR Consulting Company Offered for Sale Gunra Ransomware Attack on a South Korean Heavy Equipment Parts and Advanced Materials Manufacturer
     

Ransom & Dark Web Issues Week 1, August 2026

Por:ATCP
5 de Agosto de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 1, August 2026           South Korean Automotive Parts Manufacturer’s Internal Server Access and Database Offered for Sale Data of a Turkish HR Consulting Company Offered for Sale Gunra Ransomware Attack on a South Korean Heavy Equipment Parts and Advanced Materials Manufacturer
❌
❌