TTPs #10 : Operation GoldGoblin - 제로데이 취약점을 이용, 선별적으로 침투하는 공격전략 분석
2023-06-28 • KRCERT • TTPs #10: Operation GoldGoblin - Analysis of attack strategies that selectively infiltrate using zero-day vulnerabilities •
https://thorcert.notion.site/TTPs-10-Operation-GoldGoblin-bab695345e984edbb8fe5e16e36face6?pvs=4
Attachments
The Operation GoldGoblin analysis describes a Lazarus campaign that abused security software and media websites for initial access into South Korean targets. Attackers inserted malicious scripts into news-article pages to create watering-hole sites and used vulnerabilities in security software to install malware on visitors' systems. The report says Lazarus stole source code from a security-solution developer to build exploit code and also abused domestic infrastructure, including media sites, groupware, and hosting providers, to expand command-and-control operations.