TTPs #8 : Operation GWISIN - 맞춤형 랜섬웨어 공격 전략 분석

2022-08-17 KRCERT TTPs #8: Operation GWISIN - Analysis of customized ransomware attack strategies

https://thorcert.notion.site/TTPs-8-Operation-GWISIN-c3483353d20241b3a313fa4a8726302a

Attachments

TTPs_8_Operation_GWISIN_-_맞춤형_랜섬웨어_공격_전략_분석.pdf (29 MB)

Thumbnail for TTPs #8 : Operation GWISIN - 맞춤형 랜섬웨어 공격 전략 분석

KISA/KrCERT’s Operation GWISIN report analyzes customized ransomware intrusions against Korean organizations through an ATT&CK-style TTP lens rather than simple IOC lists. The source describes GWISIN operators as showing strong knowledge of victim businesses, Korean security products, domestic investigative bodies, and ISMS-P, with ransom artifacts customized to specific companies. The mapped tradecraft includes public-facing application exploitation, command execution, service execution, safe-mode persistence, Msiexec proxy execution, process injection into certrep.exe, log and artifact removal, credential access against LSASS, SMB/WinRM lateral movement, web-shell or internal-proxy C2, exfiltration, data destruction, service stopping, and recovery inhibition. The report emphasizes that defenders must understand the intrusion path and attacker TTPs to prevent repeated ransomware deployment against similarly prepared targets.

Related Reports

« Back