공격자간 협력 사례 공유

2025-04-15 Plainbit Sharing Cases of Cooperation Among Attackers

https://www.dailysecu.com/form/html/k-cti/image/2025/down-11.pdf

Attachments

down-11.pdf (2 MB)

The source discusses cooperation patterns among state-backed intrusion groups and focuses on North Korean operators' use of Windows LNK shortcut malware for initial access. It highlights how LNK file structure, embedded environment artifacts, and repeated builder characteristics can help cluster activity across campaigns, while noting that Lazarus and Andariel are not usually heavy LNK users. The report frames DFIR around root-cause analysis and shared defense rather than only measuring the final impact of an intrusion.

Related Actors

Related Reports

« Back