Recent Attack Activity Analysis Using North Korea-Related Lures
APT-C-06 (Darkhotel) is an APT organization that has been active since at least 2007, targeting corporate executives, defense industries, and electronics sectors. In April 2026, the group launched phishing attacks using a decoy document titled 'North Korean Central Television Real-time Broadcasting Program Instructions.' The document instructs users to download an application for watching North Korean Central Television. By late May, attacks evolved to deliver malicious MSI files through phishing emails. These MSI files execute VBS code that creates scheduled tasks to download and execute PowerShell scripts, which then retrieve subsequent payloads. The malware employs ChaCha20 encryption and ultimately deploys shellcode. PowerShell has become a high-frequency component in APT-C-06's attack chain since 2025, handling payload downloads and persistence mechanisms.
Indicators of Compromise
- hash: 4a88efd00ba8b036ec4642fcecbe6df3
- hash: 60fd3dbfeb1a44ed2a8ad46113d58262
- hash: be6d6d01740d210cb16973d81a1fd782
- hash: d033868f7b4374936dc462b0b016abaf
- domain: built.3jkg8d.com
Recent Attack Activity Analysis Using North Korea-Related Lures
Description
APT-C-06 (Darkhotel) is an APT organization that has been active since at least 2007, targeting corporate executives, defense industries, and electronics sectors. In April 2026, the group launched phishing attacks using a decoy document titled 'North Korean Central Television Real-time Broadcasting Program Instructions.' The document instructs users to download an application for watching North Korean Central Television. By late May, attacks evolved to deliver malicious MSI files through phishing emails. These MSI files execute VBS code that creates scheduled tasks to download and execute PowerShell scripts, which then retrieve subsequent payloads. The malware employs ChaCha20 encryption and ultimately deploys shellcode. PowerShell has become a high-frequency component in APT-C-06's attack chain since 2025, handling payload downloads and persistence mechanisms.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://mp.weixin.qq.com/s/KrQyZ2AZn9dcL3Fqyg_y3Q"]
- Adversary
- DarkHotel
- Pulse Id
- 6a7dc1fd395815126acd4647
- Threat Score
- null
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hash4a88efd00ba8b036ec4642fcecbe6df3 | — | |
hash60fd3dbfeb1a44ed2a8ad46113d58262 | — | |
hashbe6d6d01740d210cb16973d81a1fd782 | — | |
hashd033868f7b4374936dc462b0b016abaf | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainbuilt.3jkg8d.com | — |
Threat ID: 6a7dc98bbf8831d539431293
Added to database: 08/13/2026, 13:41:31 UTC
Last updated: 08/13/2026, 15:50:16 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.