Security Issues in the Korean & Global Financial Sector in June 2026

Security Issues in the Korean & Global Financial Sector in June 2026
June’s financial sector threat analysis shows phishing as the dominant initial attack method, followed by droppers/downloaders and infostealers in multi-stage intrusion chains that end in information theft. The report also highlights HTML-heavy malicious attachments, Telegram-based account leakage, dark web database sales, ransomware extortion, and the trading of access credentials across multiple victims including AYA Bank, HDFC AMC, and the Central Bank of Libya. #LAPSUS$ #MORPHEUS #Qilin #AYABank #HDFCAMC #CentralBankofLibya

Keypoints

  • Phishing was the most common initial attack method in Attack Stage 1 for the financial sector in June.
  • Droppers/downloaders were the most prevalent in Attack Stage 2, showing a multi-stage malware delivery chain.
  • Infostealers appeared in Attack Stage 3, indicating a progression from initial access to information theft.
  • HTML was the most common malicious attachment type, with heavy use of script-based and web-document-based extensions such as js, vbe, vbs, bat, hta, html, htm, and shtml.
  • Threat actors used HTML phishing pages, HTML smuggling, scripts, and LOLBins to conceal and deliver malicious files.
  • Domestic account information was leaked through the Telegram API after infections and phishing emails, with finance-related lures accounting for a notable share.
  • Dark web activity included database leaks, ransomware extortion, and sales of access credentials targeting financial organizations and related systems.

MITRE Techniques

  • [T1566 ] Phishing – Used as the main initial access vector, with emails containing lure keywords like “money transfer,” “receipt,” and “voicemail” that led victims to login pages or malicious attachments. (‘Emails used keywords such as “money transfer,” “receipt,” and “voicemail,” and opening the malicious links or HTML attachments led to login pages.’)
  • [T1204 ] User Execution – Victims were induced to open malicious links and HTML attachments, triggering the attack chain. (‘opening the malicious links or HTML attachments led to login pages’)
  • [T1056.003 ] Web Portal Capture – Fake login pages were used to capture credentials through phishing. (‘led to login pages’)
  • [T1027 ] Obfuscated Files or Information – HTML smuggling was used to conceal and deliver malicious files through the browser. (‘HTML smuggling (a technique that uses browsers to conceal and deliver Malicious Files)’)
  • [T1059 ] Command and Scripting Interpreter – Script-based attachments such as js, vbe, vbs, bat, and hta suggest execution of scripts to run malicious payloads. (‘script-based extensions such as js, vbe, vbs, bat, and hta’)
  • [T1105 ] Ingress Tool Transfer – Droppers/downloaders were used to fetch additional malware in later attack stages. (‘droppers/downloaders (distribution tools that download additional malware)’)
  • [T1021 ] Remote Services – Access credentials were sold for systems and services such as WordPress, GitHub, MSSQL, S3, MinIO, Grafana, and production environments, implying unauthorized access through remote services. (‘access to the WordPress main domain, GitHub organization administrator accounts, MSSQL SA accounts, S3, MinIO, Grafana, and production environments’)
  • [T1567 ] Exfiltration to Cloud Storage – Domestic account information was leaked to attackers through the Telegram API, indicating exfiltration via an online service. (‘collected through malware infections and phishing emails, was leaked to attackers through the Telegram API’)
  • [T1588.002 ] Tool – Malware attachments and distribution tools were used as part of the intrusion chain. (‘droppers/downloaders’ and ‘malicious attachments’)

Indicators of Compromise

  • [Domains ] Dark web and victim organization domains mentioned in the report – canadalife.com, robinhood.com, and other domains such as prudential.com, ayabank.com, hdfcfund.com, cbl.gov.ly
  • [File extensions ] Malicious attachment formats and script types – html, js, exe, vbe, and other extensions such as vbs, bat, hta, htm, shtml
  • [File names / document lures ] Business-document-themed attachment names used to gain trust – tax receipts, payment receipts, HR documents, and contract-related documents
  • [Organizations ] Victims and targeted entities referenced in leaks and extortion – Canada Life, Robinhood, Prudential Financial, AYA Bank Public Company Limited, HDFC Asset Management Company, Central Bank of Libya
  • [Platforms / services ] Infrastructure and services listed in access-sale posts – WordPress main domain, GitHub organization administrator accounts, MSSQL SA accounts, S3, MinIO, Grafana, and production environments
  • [Data types ] Sensitive information exposed in leaks and sales – names, email addresses, phone numbers, addresses, account information, SSNs, bank account information, insurance information, KYC documents


Read more: https://asec.ahnlab.com/en/94543/