Cloud storage를 활용하는 APT 공격

2024-05-23 Ahnlab APT attacks using cloud storage services

https://asec.ahnlab.com/ko/65684/

Thumbnail for Cloud storage를 활용하는 APT 공격

AhnLab ASEC describes APT attacks that rely on cloud services such as Google Drive, OneDrive, and Dropbox to host malicious scripts, decoy documents, and RAT payloads. The infection chain uses lure files such as LNK shortcuts and cloud-hosted components that can collect information, download additional malware, and complicate detection because attacker-controlled files are staged through legitimate cloud infrastructure.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 159.100.29.122 2024-05-23 2024-08-21
HASH dd2988c792b0252db4c39309e6cb2c48 2024-05-23 2024-06-11
HASH f396bf5ff64656b592fe3d665eab8aa3 2024-05-23 2024-06-11
HASH c45d209f666f77d70bed61e6fca48bc2 2024-05-23 2024-06-11
HASH 6ad00d48fdce8dc632b13f6c2438f893 2024-05-23 2024-06-11
HASH d9d9b8375f74812c41a1cd9abce25ac9 2024-05-23 2024-06-11
HASH bcb0a6360f057475c63fb16e61fb3adc 2024-05-23 2024-06-11
HASH 52e5d2cd15ea7d0928e90b18039ec6c6 2024-05-23 2024-06-11
HASH 5d2fdc098d1e1a7674a40ef9140058ed 2024-05-23 2024-06-11
HASH 66b5ffb611505f0067c868dfa84aea60 2024-05-23 2024-06-11
HASH 238cd8f609b06258ab8b4ded82ebbff8 2024-05-23 2024-06-11
EMAIL [email protected] 2024-05-23 2024-06-11
EMAIL [email protected] 2024-05-23 2024-06-11
EMAIL [email protected] 2024-05-23 2024-06-11
EMAIL [email protected] 2024-05-23 2024-06-11
EMAIL [email protected] 2024-05-23 2024-06-11

Related Reports

« Back