Korea APTs Push LNK “Resume” Spear‑Phish

AhnLab ASEC · High sophistication
Last updated August 28, 2026

AhnLab reports that many APT attacks targeting organizations in South Korea in July 2026 started with spear‑phishing emails that delivered malicious Windows shortcut (LNK) files disguised as legitimate documents (including resumes). When opened, the LNK runs scripts that install backdoors/infostealers, set up stealthy scheduled tasks (e.g., fake OneDrive or browser updates), and exfiltrate system information to services like Dropbox or via attacker-controlled channels.

Key findings

  • Most APT attacks observed were delivered via spear phishing, with LNK (Windows shortcut) files being the most common payload format in July 2026.
  • Multiple variants used embedded PowerShell/CMD/JavaScript/VBS/BAT inside LNK files to run malware, drop decoy documents, and fetch additional payloads from public services (GitHub, Google Drive, Dropbox).
  • Persistence commonly relied on Windows Task Scheduler entries disguised as legitimate software updates (e.g., OneDrive or browser updates).
  • Observed tooling included infostealers, keyloggers, backdoors (including XenoRAT-type), and techniques like DLL side-loading and in-memory loading (e.g., via regsvr32).
  • Exfiltration and command/control were performed via cloud/platform channels (e.g., Dropbox, PubNub) and attacker-controlled URLs.

Who’s being targeted

  • Commonly targeted roles: All Employees, HR/Recruiting, Finance, Executive Assistants, IT/Security Operations.
  • Affected industries: Unspecified (multiple sectors in South Korea).
  • Attack channels: email.
  • Impersonated: External job applicant or business contact, Business contact sending a work document.

Awareness takeaways

  • Treat unexpected “document” attachments, especially shortcut (LNK) files, as high risk and report them.
  • Verify the sender’s identity using a trusted method before opening attachments from new or unusual contacts.
  • Be alert to messages crafted to match your work interests (e.g., work requests, resumes) because that is a common lure.
  • Keep systems updated (OS/browser/security tools) to reduce the chance that a single click turns into a lasting compromise.

Red flags to watch for

  • Attachment is a Windows shortcut (LNK) instead of a normal PDF/DOCX
  • File appears to be a document but behaves like a program when opened
  • Unexpected request to open an attachment from an unknown sender
  • A “document” attachment triggers scripts (PowerShell/CMD) rather than opening normally
  • System creates a new scheduled task labeled like an update (e.g., OneDrive/browser update)
  • Decoy document opens but background activity continues (downloads/exfiltration)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine this lands in your inbox: "Please review the attached resume." Looks normal… until you check the file type. That .lnk is a Windows shortcut. In recent Korea APT cases, opening it quietly ran PowerShell and CMD, dropped a decoy resume, and installed backdoors that talk out to Dropbox and other cloud services. Here’s the sneaky part: it even registers a fake OneDrive or browser "update" in Task Scheduler so it keeps running long after you close the decoy file. Your move: if an unexpected "document" is actually a .lnk shortcut, don’t open it, report it to security right away and let them handle it.

Similar attacks

Larva-24009 Lures Firms With Fake Doc Attachments

Larva-24009 Lures Firms With Fake Doc Attachments

AhnLab reports Larva-24009 has continued phishing campaigns through 2026, sending emails that trick employees into opening fake “document” attachments that are actually shortcut (LNK) files. When opened, the attachment runs hidden PowerShell commands, shows a decoy document, and silently downloads…

August 3, 2026
APT28 Uses Diplomatic Word Lures to Drop HOOKEDGE

APT28 Uses Diplomatic Word Lures to Drop HOOKEDGE

Researchers report real-world campaigns targeting European government and diplomatic organizations using diplomatic-themed Microsoft Word documents. Victims are prompted to click “Enable Content,” which runs malicious macros that install the HOOKEDGE backdoor and connect to webhook-based…

August 28, 2026
Law Firm Hit by Phish Using Fake Python Runtime

Law Firm Hit by Phish Using Fake Python Runtime

Researchers say a law firm was targeted with a spear‑phishing email that led staff to download an encrypted archive containing a Windows shortcut labeled like legal case files. After the user ran it and approved admin rights, the malware told Microsoft Defender to ignore a folder and a fake…

August 3, 2026
Fake Zoom/Webex Installers Drop Starland RAT

Fake Zoom/Webex Installers Drop Starland RAT

Cisco Talos reports a real campaign by a Russian-speaking group (UAT-11795) targeting users in the U.S. and Europe with trojanized installers for popular tools like Zoom, Webex, and MobaXterm. Victims are socially engineered via a “ClickFix” style trick into running a command that silently…

July 17, 2026
Phishers Hide Lua Malware as “.TTF Font”

Phishers Hide Lua Malware as “.TTF Font”

A real, ongoing phishing campaign is tricking recipients into opening malicious archives that appear to contain harmless TrueType font files (.ttf) but actually hide a Lua-based loader. Once executed, the loader uses stealthy, mostly in-memory techniques to install remote access trojans and…

July 16, 2026
Voucher Lure Drops RAT via FTP Banner Tricks

Voucher Lure Drops RAT via FTP Banner Tricks

Researchers reported a real malware campaign where attackers use Spanish-language “voucher claim” messages to trick people into running a Windows Shortcut file. After the user clicks it, the malware pulls commands from an FTP server’s welcome banner and continues downloading additional payloads,…

August 25, 2026