Recent Attack Activity Analysis Using North Korea-Related Lures
APT-C-06 (Darkhotel) is an APT organization that has been active since at least 2007, targeting corporate executives, defense industries, and electronics sectors. In April 2026, the group launched phishing attacks using a decoy document titled 'North Korean Central Television Real-time Broadcasting Program Instructions.' The document instructs users to download an application for watching North Korean Central Television. By late May, attacks evolved to deliver malicious MSI files through phishing emails. These MSI files execute VBS code that creates scheduled tasks to download and execute PowerShell scripts, which then retrieve subsequent payloads. The malware employs ChaCha20 encryption and ultimately deploys shellcode. PowerShell has become a high-frequency component in APT-C-06's attack chain since 2025, handling payload downloads and persistence mechanisms.
AI Analysis
Technical Summary
APT-C-06 (Darkhotel) launched phishing attacks in April 2026 using a decoy document themed around North Korean Central Television to trick targets into downloading an application. By late May 2026, the campaign evolved to deliver malicious MSI installers via phishing emails. These MSI files execute VBS code that establishes scheduled tasks to download and execute PowerShell scripts. The PowerShell scripts retrieve subsequent payloads encrypted with ChaCha20 and ultimately deploy shellcode. This reflects a sophisticated multi-stage attack chain leveraging scripting and encryption for stealth and persistence. PowerShell usage has been a frequent tactic for this group since 2025.
Potential Impact
The campaign targets high-value individuals and sectors such as corporate executives, defense, and electronics. Successful exploitation leads to execution of encrypted payloads and shellcode on victim systems, potentially enabling unauthorized access, persistence, and further compromise. The use of scheduled tasks and PowerShell scripts facilitates stealthy and persistent infection. However, no known exploits in the wild have been reported for this specific campaign as of the publication date.
Mitigation Recommendations
No official patch or remediation is applicable as this is a phishing campaign leveraging social engineering and malware delivery. Organizations should focus on user awareness training to recognize phishing lures, implement email filtering to block malicious attachments (MSI files), and monitor for suspicious scheduled tasks and PowerShell activity. Endpoint detection and response solutions can help identify and block the execution of malicious scripts and shellcode. Since this is a targeted campaign, heightened vigilance in affected sectors is advised.
Indicators of Compromise
- hash: 4a88efd00ba8b036ec4642fcecbe6df3
- hash: 60fd3dbfeb1a44ed2a8ad46113d58262
- hash: be6d6d01740d210cb16973d81a1fd782
- hash: d033868f7b4374936dc462b0b016abaf
- domain: built.3jkg8d.com
Recent Attack Activity Analysis Using North Korea-Related Lures
Description
APT-C-06 (Darkhotel) is an APT organization that has been active since at least 2007, targeting corporate executives, defense industries, and electronics sectors. In April 2026, the group launched phishing attacks using a decoy document titled 'North Korean Central Television Real-time Broadcasting Program Instructions.' The document instructs users to download an application for watching North Korean Central Television. By late May, attacks evolved to deliver malicious MSI files through phishing emails. These MSI files execute VBS code that creates scheduled tasks to download and execute PowerShell scripts, which then retrieve subsequent payloads. The malware employs ChaCha20 encryption and ultimately deploys shellcode. PowerShell has become a high-frequency component in APT-C-06's attack chain since 2025, handling payload downloads and persistence mechanisms.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
APT-C-06 (Darkhotel) launched phishing attacks in April 2026 using a decoy document themed around North Korean Central Television to trick targets into downloading an application. By late May 2026, the campaign evolved to deliver malicious MSI installers via phishing emails. These MSI files execute VBS code that establishes scheduled tasks to download and execute PowerShell scripts. The PowerShell scripts retrieve subsequent payloads encrypted with ChaCha20 and ultimately deploy shellcode. This reflects a sophisticated multi-stage attack chain leveraging scripting and encryption for stealth and persistence. PowerShell usage has been a frequent tactic for this group since 2025.
Potential Impact
The campaign targets high-value individuals and sectors such as corporate executives, defense, and electronics. Successful exploitation leads to execution of encrypted payloads and shellcode on victim systems, potentially enabling unauthorized access, persistence, and further compromise. The use of scheduled tasks and PowerShell scripts facilitates stealthy and persistent infection. However, no known exploits in the wild have been reported for this specific campaign as of the publication date.
Defensive Guidance
No official patch or remediation is applicable as this is a phishing campaign leveraging social engineering and malware delivery. Organizations should focus on user awareness training to recognize phishing lures, implement email filtering to block malicious attachments (MSI files), and monitor for suspicious scheduled tasks and PowerShell activity. Endpoint detection and response solutions can help identify and block the execution of malicious scripts and shellcode. Since this is a targeted campaign, heightened vigilance in affected sectors is advised.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://mp.weixin.qq.com/s/KrQyZ2AZn9dcL3Fqyg_y3Q"]
- Adversary
- DarkHotel
- Pulse Id
- 6a7dc1fd395815126acd4647
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hash4a88efd00ba8b036ec4642fcecbe6df3 | — | |
hash60fd3dbfeb1a44ed2a8ad46113d58262 | — | |
hashbe6d6d01740d210cb16973d81a1fd782 | — | |
hashd033868f7b4374936dc462b0b016abaf | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainbuilt.3jkg8d.com | — |
Threat ID: 6a7dc98bbf8831d539431293
Added to database: 08/13/2026, 13:41:31 UTC
Last enriched: 08/13/2026, 17:31:16 UTC
Last updated: 09/26/2026, 17:06:58 UTC
Views: 213
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.