TTPs#2 스피어 피싱으로 정보를 수집하는 공격망 구성 방식 분석
2020-06-29 • KRCERT • TTPs #2 analysis of attacker infrastructure for collecting information through spear phishing •
Attachments
The available excerpt is an outline for a Korean TTP report about building an attack chain that uses spear phishing to collect information. It frames the activity across MITRE ATT&CK stages including initial access, execution, persistence, privilege escalation, defense evasion, credential access, discovery, collection, lateral movement, command and control, exfiltration, and impact. The table of contents indicates that the full material includes malware analysis and a YARA rule, but the excerpt does not provide actor attribution, victim details, malware names, infrastructure, or specific IOCs.