타겟형 워터링홀 공격, 그리고 KISA의 사이버 위협 헌팅

2022-02-21 KRCERT Targeted Watering-Hole Attack and KISA Cyber Threat Hunting

https://www.dailysecu.com/form/html/k-cti/image/2022/down-01.pdf

Attachments

down-01.pdf (3 MB)

KISA described a targeted watering-hole attack in which a compromised Korean website redirected visitors through malicious scripts and IP filtering before delivering malware via software vulnerability exploitation. The attack chain included initial access, command-and-control, RAT download, data collection, and exfiltration over the C2 channel. Technical artifacts in the excerpt include C:\users\public\iexplore.exe, a temporary LNK-named file, Base64 and RC4 decoding details, and TigerRAT identified as ASDCli.exe. The hunting section maps the activity to stages such as reconnaissance, resource development, exploitation for client execution, signed binary proxy execution, command scripting, automated collection, archive collection, and exfiltration.

Related Reports

« Back