Skip to main content

Recent Attack Activity Analysis Using North Korea-Related Lures

0
Medium
Published: 08/13/2026 (08/13/2026, 13:09:17 UTC)
Source: AlienVault OTX General

Description

APT-C-06 (Darkhotel) is an APT organization that has been active since at least 2007, targeting corporate executives, defense industries, and electronics sectors. In April 2026, the group launched phishing attacks using a decoy document titled 'North Korean Central Television Real-time Broadcasting Program Instructions.' The document instructs users to download an application for watching North Korean Central Television. By late May, attacks evolved to deliver malicious MSI files through phishing emails. These MSI files execute VBS code that creates scheduled tasks to download and execute PowerShell scripts, which then retrieve subsequent payloads. The malware employs ChaCha20 encryption and ultimately deploys shellcode. PowerShell has become a high-frequency component in APT-C-06's attack chain since 2025, handling payload downloads and persistence mechanisms.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/13/2026, 17:31:16 UTC

Technical Analysis

APT-C-06 (Darkhotel) launched phishing attacks in April 2026 using a decoy document themed around North Korean Central Television to trick targets into downloading an application. By late May 2026, the campaign evolved to deliver malicious MSI installers via phishing emails. These MSI files execute VBS code that establishes scheduled tasks to download and execute PowerShell scripts. The PowerShell scripts retrieve subsequent payloads encrypted with ChaCha20 and ultimately deploy shellcode. This reflects a sophisticated multi-stage attack chain leveraging scripting and encryption for stealth and persistence. PowerShell usage has been a frequent tactic for this group since 2025.

Potential Impact

The campaign targets high-value individuals and sectors such as corporate executives, defense, and electronics. Successful exploitation leads to execution of encrypted payloads and shellcode on victim systems, potentially enabling unauthorized access, persistence, and further compromise. The use of scheduled tasks and PowerShell scripts facilitates stealthy and persistent infection. However, no known exploits in the wild have been reported for this specific campaign as of the publication date.

Defensive Guidance

No official patch or remediation is applicable as this is a phishing campaign leveraging social engineering and malware delivery. Organizations should focus on user awareness training to recognize phishing lures, implement email filtering to block malicious attachments (MSI files), and monitor for suspicious scheduled tasks and PowerShell activity. Endpoint detection and response solutions can help identify and block the execution of malicious scripts and shellcode. Since this is a targeted campaign, heightened vigilance in affected sectors is advised.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://mp.weixin.qq.com/s/KrQyZ2AZn9dcL3Fqyg_y3Q"]
Adversary
DarkHotel
Pulse Id
6a7dc1fd395815126acd4647

Indicators of Compromise

Hash

ValueDescriptionCopy
hash4a88efd00ba8b036ec4642fcecbe6df3
—
hash60fd3dbfeb1a44ed2a8ad46113d58262
—
hashbe6d6d01740d210cb16973d81a1fd782
—
hashd033868f7b4374936dc462b0b016abaf
—

Domain

ValueDescriptionCopy
domainbuilt.3jkg8d.com
—

Threat ID: 6a7dc98bbf8831d539431293

Added to database: 08/13/2026, 13:41:31 UTC

Last enriched: 08/13/2026, 17:31:16 UTC

Last updated: 09/26/2026, 17:06:58 UTC

Views: 213

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses