TTPs $ 포털사이트 피싱을 통한 가상자산 탈취 위협 분석
2025-01-17 • KRCERT • Cyber threat report on Cryptocurrency, Phishing •
https://thorcert.notion.site/ttps-cybersecurity-threats-targeting-cryptocurrencies
KISA describes a cryptocurrency-theft phishing operation that used reconnaissance on Naver Cafe and online communities, phishing email delivery, and Python automation to target virtual-asset users. The attackers focused on wallet seed phrases, private keys, wallet balances, and transaction conditions, including checks for Solana, Dogecoin, XRP, Filecoin, Anchor Wallet, and Wombat Wallet through JSON-RPC and HTTP APIs. The report is useful for defenders tracking phishing tradecraft that combines social targeting with scripted wallet enumeration and automated theft preparation.