TTPs #11: Operation An Octopus - 중앙 집중형 관리 솔루션을 노리는 공격전략 분석

2024-06-28 KRCERT Operation An Octopus: Attack Strategy Targeting Centralized Management Solutions

https://thorcert.notion.site/TTPs-11-Operation-An-Octopus-d875862055ca4b7b815b5e496b219671

Attachments

TTPs11_Operation_An_Octopus_-_중앙_집중형_관리_솔루션을_노리는_공격전략_분석.pdf (7 MB)

Thumbnail for TTPs #11: Operation An Octopus - 중앙 집중형 관리 솔루션을 노리는 공격전략 분석

Andariel, described as a Lazarus subgroup, is analyzed using vulnerabilities in centralized management solutions deployed by South Korean enterprises. The activity relied heavily on exposed administrator console ports and scanning for vulnerable software, allowing the group to compromise organizations where management tools were reachable from the internet. The report says the operation evolved beyond opportunistic scanning into supply-chain distribution through developers with many downstream customers. Separating attacker rented-server TTPs from victim-environment intrusion TTPs helps defenders focus on attack-surface management, third-party software monitoring, and controls around file-distribution and administrative platforms.

Related Actors

First seen: Jul 2017
Last seen: May 2026

Related Reports

2024-07-25 • 60% Match
#Andariel #Maui #MoneyLaundering #ArkansasHealthcare #CaliforniaDefense #ChineseEnergy #ColoradoMedical #ConnecticutHealthcare #FloridaHospital #KansasHospital #MassachusettsDefense #MichiganDefense #NASA #OregonDefense #RandolphAirForce #RobinsAirForce #SouthKoreanManufacturing #TaiwaneseDefense
Shares tag: Andariel • Published within a month
« Back