TTPs#2 스피어 피싱으로 정보를 수집하는 공격망 구성 방식 분석

2020-06-29 KRCERT TTPs #2 analysis of attacker infrastructure for collecting information through spear phishing

https://www.krcert.or.kr/kr/bbs/view.do?searchCnd=1&bbsId=B0000127&searchWrd=TTP&menuNo=205021&pageIndex=1&categoryCode=&nttId=35471

Attachments

TTPs_2_스피어_피싱으로_정보를_수집하는_공격망_구성_방식.pdf (10 MB)

Thumbnail for TTPs#2 스피어 피싱으로 정보를 수집하는 공격망 구성 방식 분석

The available excerpt is an outline for a Korean TTP report about building an attack chain that uses spear phishing to collect information. It frames the activity across MITRE ATT&CK stages including initial access, execution, persistence, privilege escalation, defense evasion, credential access, discovery, collection, lateral movement, command and control, exfiltration, and impact. The table of contents indicates that the full material includes malware analysis and a YARA rule, but the excerpt does not provide actor attribution, victim details, malware names, infrastructure, or specific IOCs.

Related Reports

« Back