TTPs #11: Operation An Octopus - 중앙 집중형 관리 솔루션을 노리는 공격전략 분석
2024-06-28 • KRCERT • Operation An Octopus: Attack Strategy Targeting Centralized Management Solutions •
https://thorcert.notion.site/TTPs-11-Operation-An-Octopus-d875862055ca4b7b815b5e496b219671
Attachments
Andariel, described as a Lazarus subgroup, is analyzed using vulnerabilities in centralized management solutions deployed by South Korean enterprises. The activity relied heavily on exposed administrator console ports and scanning for vulnerable software, allowing the group to compromise organizations where management tools were reachable from the internet. The report says the operation evolved beyond opportunistic scanning into supply-chain distribution through developers with many downstream customers. Separating attacker rented-server TTPs from victim-environment intrusion TTPs helps defenders focus on attack-surface management, third-party software monitoring, and controls around file-distribution and administrative platforms.