TTPs #8 : Operation GWISIN - 맞춤형 랜섬웨어 공격 전략 분석
2022-08-17 • KRCERT • TTPs #8: Operation GWISIN - Analysis of customized ransomware attack strategies •
https://thorcert.notion.site/TTPs-8-Operation-GWISIN-c3483353d20241b3a313fa4a8726302a
Attachments
KISA/KrCERT’s Operation GWISIN report analyzes customized ransomware intrusions against Korean organizations through an ATT&CK-style TTP lens rather than simple IOC lists. The source describes GWISIN operators as showing strong knowledge of victim businesses, Korean security products, domestic investigative bodies, and ISMS-P, with ransom artifacts customized to specific companies. The mapped tradecraft includes public-facing application exploitation, command execution, service execution, safe-mode persistence, Msiexec proxy execution, process injection into certrep.exe, log and artifact removal, credential access against LSASS, SMB/WinRM lateral movement, web-shell or internal-proxy C2, exfiltration, data destruction, service stopping, and recovery inhibition. The report emphasizes that defenders must understand the intrusion path and attacker TTPs to prevent repeated ransomware deployment against similarly prepared targets.