특정 홈페이지 제작 업체가 제작한 국내 다수의 홈페이지 피해 확인
2023-06-09 • Ahnlab • Confirmed damage to multiple domestic websites produced by a specific website production company •
AhnLab observed RedEyes/APT37-linked activity compromising multiple South Korean websites built by the same web production company and using them to distribute malware or host web shells. The affected sites spanned sectors including manufacturing, trade, electronics, education, construction, healthcare, and travel, and shared externally accessible admin paths that likely enabled malicious file uploads. Infections were initially distributed through email attachments and maintained through scheduled tasks that invoked mshta to connect to web-shell URLs on legitimate compromised sites, making victim awareness and attribution more difficult.