Skip to content

AhnLab vulnerabilities

AhnLab features in recent reports from its ASEC unit highlighting multiple APT campaigns targeting South Korean and global entities. Key threats include Kimsuky group's spear-phishing mimicking diplomats to deploy PebbleDash and PrxClient malware, along with activities from Larva-24009/26005 threat actors distributing tools like Xctdoor and XMRig coinminers. Reports also cover MS-SQL server intrusions, infostealer trends, and a joint advisory linking state-sponsored actors to Gunra ransomware. Defenders should focus on detecting phishing lures, suspicious LNK files, and the specific TTPs of these tracked threat groups.

Azərbaycanca: AhnLab, öz təhlükəsizlik araşdırma mərkəzi ASEC-in son hesabatlarında Cənubi Koreya və qlobal istifadəçiləri hədəf alan APT qrupları kontekstində görünür. Əsas diqqət Kimsuky qrupunun diplomatları hədəf alan fişinq hücumları (PebbleDash, PrxClient zərərli proqramları) və Larva-24009/26005 kimi digər qrupların zərərli proqram yayma (Xctdoor, XMRig) fəaliyyətlərinə yönəlib. MS-SQL serverlərinə edilən hədəfli hücumlar, məlumat oğurlayan proqram tendensiyaları və dövlət dəstəkli qruplarla Gunra ransomware-i arasındakı əlaqələr kimi mövzular da araşdırılır. Müdafiəçilər fişinq e-poçtlarına, şübhəli LNK fayllarına qarşı sayıqlığı artırmalı və bu qrupların taktika, texnika və prosedurlarını (TTP) izləməlidirlər.

This hub is built from skopnix's own reporting on AhnLab: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.