Jan 2025 — Cyber Attack Trends

Contents Download

In Logpresso's CTI Report Vol. 10, we focused on reviewing the 2024 threats and providing insights into the outlook for 2025, highlighting credential leaks in Indonesia following our coverage of Japan, Taiwan, India, and Vietnam. Additionally, we conducted a comparative analysis of cyberattack cases across the Asia-Pacific region in 2024.

1. Review of 2024 Cyber Threats and Outlook for 2025

  • 2024 Cyber Threat in Review
  • 2025 Cyber Threat Outlook

2. Threat Analysis

  • Analysis of Personal Information Leakage Due to Botnet Infection in Indonesia
  • Analysis of Decoy Files for Cyberattacks in 2024

3. Why Cloud and SaaS Security Management are Necessary



Contents Download




Logpresso Cyber Threat Intelligence

Logpresso is a specialized company in security and IT operations(SecOps), established in 2013. We offer security operation solutions such as log management, SIEM(Security Information and Event Management), SOAR(Security Orchestration, Automation, and Response), and DFIR(Digital Forensic & Incident Response) based on our fundamental technology.

Logpresso CTI is a cyber threat intelligence service optimized to immediately utilize such security threat information in security information and event management (SIEM) / security orchestration, automation, and response (SOAR) platforms. Relying on various open-source intelligence (OSINT) data sources such as the dark web and deep web, Logpresso CTI provides intelligence feeds that can detect various cyber-attacks including advanced persistent threats (APT), phishing, and credential stuffing.

Unlike many CTI services that are only available on a limited basis through API, Logpresso CTI synchronizes all indicators of compromise (IoC) directly to SIEM/SOAR, enabling full, real-time investigation of all logs. Unlike existing security architectures that primarily rely on detection through security devices, our approach enables the detection of threats proactively before a direct attack occurs.

See Also

More

[위협 분석] 건강검진 안내 문서로 위장한 악성코드

2025년 10월 말, 건강검진 안내 문서로 위장한 JSE 파일이 조직적인 APT 공격에 활용되었으며, 분석 결과 북한 Kimsuky 조직에 의한 공격으로 판단됩니다. Kimsuky는 북한과 연계된 것으로 추정되는 APT(Advanced Persistent Threat) 그룹으로, 주로 정보 수집과 관련된 각종 스파이 활동을 수행합니다.

2025-11-06