공격자간 협력 사례 공유
2025-04-15 • Plainbit • Sharing Cases of Cooperation Among Attackers •
https://www.dailysecu.com/form/html/k-cti/image/2025/down-11.pdf
Attachments
down-11.pdf (2 MB)
The source discusses cooperation patterns among state-backed intrusion groups and focuses on North Korean operators' use of Windows LNK shortcut malware for initial access. It highlights how LNK file structure, embedded environment artifacts, and repeated builder characteristics can help cluster activity across campaigns, while noting that Lazarus and Andariel are not usually heavy LNK users. The report frames DFIR around root-cause analysis and shared defense rather than only measuring the final impact of an intrusion.