home.social

#ahnlab — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #ahnlab, aggregated by home.social.

fetched live
  1. Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005)

    Indicators extracted from public reporting. Source: asec.ahnlab.com/en/94847/

    Pulse ID: 6a746883a8e4c60d2223e68a
    Pulse Link: otx.alienvault.com/pulse/6a746
    Pulse Author: CyberHunter_NL
    Created: 2026-08-06 10:57:06

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ASEC #AhnLab #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RAT #RCE #bot #CyberHunter_NL

  2. Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005)

    Indicators extracted from public reporting. Source: asec.ahnlab.com/en/94847/

    Pulse ID: 6a746883a8e4c60d2223e68a
    Pulse Link: otx.alienvault.com/pulse/6a746
    Pulse Author: CyberHunter_NL
    Created: 2026-08-06 10:57:06

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ASEC #AhnLab #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RAT #RCE #bot #CyberHunter_NL

  3. June 2026 Threat Trend Report on APT Attacks (South Korea)

    AhnLab monitored Advanced Persistent Threat attacks targeting South Korea during June 2026, identifying multiple attack types distributed primarily through spear phishing campaigns. Threat actors disguised malicious files as work-related documents, with LNK files being the most common delivery method. Six distinct attack types were observed, employing various techniques including malicious PowerShell commands, AutoIt malware, curl.exe abuse, GitHub repository exploitation, Task Scheduler persistence, DLL side-loading, and Python backdoors. These attacks deployed Infostealers, keyloggers, backdoors, and remote access tools like XenoRAT. Once executed, the malware established persistence, exfiltrated system information, and enabled remote control of compromised systems. Organizations are advised to verify email senders, avoid opening files from unknown sources, apply security patches, and maintain updated antivirus software to mitigate these persistent threats.

    Pulse ID: 6a635bdf995351cf539c3b56
    Pulse Link: otx.alienvault.com/pulse/6a635
    Pulse Author: AlienVault
    Created: 2026-07-24 12:34:39

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AhnLab #Autoit #BackDoor #CyberSecurity #Email #GitHub #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #Python #RAT #RCE #SouthKorea #SpearPhishing #bot #AlienVault

  4. June 2026 Threat Trend Report on APT Attacks (South Korea)

    AhnLab monitored Advanced Persistent Threat attacks targeting South Korea during June 2026, identifying multiple attack types distributed primarily through spear phishing campaigns. Threat actors disguised malicious files as work-related documents, with LNK files being the most common delivery method. Six distinct attack types were observed, employing various techniques including malicious PowerShell commands, AutoIt malware, curl.exe abuse, GitHub repository exploitation, Task Scheduler persistence, DLL side-loading, and Python backdoors. These attacks deployed Infostealers, keyloggers, backdoors, and remote access tools like XenoRAT. Once executed, the malware established persistence, exfiltrated system information, and enabled remote control of compromised systems. Organizations are advised to verify email senders, avoid opening files from unknown sources, apply security patches, and maintain updated antivirus software to mitigate these persistent threats.

    Pulse ID: 6a635bdf995351cf539c3b56
    Pulse Link: otx.alienvault.com/pulse/6a635
    Pulse Author: AlienVault
    Created: 2026-07-24 12:34:39

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AhnLab #Autoit #BackDoor #CyberSecurity #Email #GitHub #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #Python #RAT #RCE #SouthKorea #SpearPhishing #bot #AlienVault

  5. z0Miner Exploits Korean Web Servers to Attack WebLogic Server

    AhnLab Security intelligence Center (ASEC) has discovered numerous instances of threat actors attacking vulnerable Korean servers. This post examines a recent case in which the 'z0Miner' threat actor targeted Korean WebLogic servers. The actor has a history of distributing miners against vulnerable servers and is known for exploiting WebLogic server vulnerabilities.

    Pulse ID: 65eb43b73126f426dbb1e92b
    Pulse Link: otx.alienvault.com/pulse/65eb4
    Pulse Author: AlienVault
    Created: 2024-03-08 16:58:30

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #OTX #OpenThreatExchange #InfoSec #bot #CyberSecurity #AhnLab #ASEC #AlienVault

  6. WogRAT Malware Exploits aNotepad

    AhnLab Security intelligence Center (ASEC) has recently discovered the distribution of backdoor malware via aNotepad, a free online notepad platform. The malware, classified as WogRAT, supports both Windows and Linux systems. It has been used in attacks since late 2022, often disguised as legitimate software. WogRAT sends data to a command and control server, and can execute commands, upload/download files, etc. The Linux version connects to a Tiny Shell server to receive commands.

    Pulse ID: 65e88e7ae77b71e99ddb944e
    Pulse Link: otx.alienvault.com/pulse/65e88
    Pulse Author: AlienVault
    Created: 2024-03-06 15:40:42

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #OTX #OpenThreatExchange #InfoSec #bot #CyberSecurity #Malware #BackDoor #Linux #Windows #RAT #AhnLab #ASEC #AlienVault

  7. "👾 HiddenGh0st Malware: A Silent Menace to MS-SQL Servers 🖥️"

    The HiddenGh0st malware, a variant of the notorious Gh0st RAT, has been wreaking havoc on MS-SQL servers. Developed by the C. Rufus Security Team from China, this malware has evolved, now deploying an open-source rootkit named Hidden to ensure its stealth and persistence on infected systems. The malware is distributed in a packed state to evade detection, and once unpacked, it communicates with its C&C server, receiving commands to execute various malicious activities. It's capable of keylogging, stealing account credentials via Mimikatz, and even enabling remote desktop for further exploitation. The primary targets appear to be Chinese users, given the malware's specific focus on QQ Messenger data exfiltration. The detailed analysis by AhnLab's ASEC provides a deep dive into its nefarious functionalities and the threat it poses to poorly managed MS-SQL servers.

    Source: ASEC Blog

    Tags: #HiddenGh0st #Gh0stRAT #MSSQL #Cybersecurity #MalwareAnalysis #Rootkit #ChineseCyberThreats #InfoSec #AhnLab 🇨🇳🔐🖥️

  8. "👾 HiddenGh0st Malware: A Silent Menace to MS-SQL Servers 🖥️"

    The HiddenGh0st malware, a variant of the notorious Gh0st RAT, has been wreaking havoc on MS-SQL servers. Developed by the C. Rufus Security Team from China, this malware has evolved, now deploying an open-source rootkit named Hidden to ensure its stealth and persistence on infected systems. The malware is distributed in a packed state to evade detection, and once unpacked, it communicates with its C&C server, receiving commands to execute various malicious activities. It's capable of keylogging, stealing account credentials via Mimikatz, and even enabling remote desktop for further exploitation. The primary targets appear to be Chinese users, given the malware's specific focus on QQ Messenger data exfiltration. The detailed analysis by AhnLab's ASEC provides a deep dive into its nefarious functionalities and the threat it poses to poorly managed MS-SQL servers.

    Source: ASEC Blog

    Tags: #HiddenGh0st #Gh0stRAT #MSSQL #Cybersecurity #MalwareAnalysis #Rootkit #ChineseCyberThreats #InfoSec #AhnLab 🇨🇳🔐🖥️

  9. Interesting article on how information stealers make a profit from #AhnLab: asec.ahnlab.com/en/45150/

  10. Interesting article on how information stealers make a profit from #AhnLab: asec.ahnlab.com/en/45150/