국내 엔드포인트 대상 공격의 두 축, 스피어피싱과 워터링 홀

2026-07-22 Ahnlab Two Main Vectors of Attacks Against South Korean Endpoints: Spearphishing and Watering Holes

https://github.com/Plainbit/Slides/blob/main/2026%20%EC%83%81%EB%B0%98%EA%B8%B0%20%EC%B9%A8%ED%95%B4%EC%82%AC%EA%B3%A0%20%EC%A0%95%EB%B3%B4%EA%B3%B5%EC%9C%A0%20%EC%84%B8%EB%AF%B8%EB%82%98/04-%EA%B5%AD%EB%82%B4%20%EC%97%94%EB%93%9C%ED%8F%AC%EC%9D%B8%ED%8A%B8%20%EB%8C%80%EC%83%81%20%EA%B3%B5%EA%B2%A9%EC%9D%98%20%EB%91%90%20%EC%B6%95%2C%20%EC%8A%A4%ED%94%BC%EC%96%B4%ED%94%BC%EC%8B%B1%EA%B3%BC%20%EC%9B%8C%ED%84%B0%EB%A7%81%20%ED%99%80_%EC%9D%B4%EC%84%A0%ED%98%B8(%EC%95%88%EB%9E%A9).pdf

Attachments

source_3853_PZtzFwO.pdf (5 MB)

Thumbnail for 국내 엔드포인트 대상 공격의 두 축, 스피어피싱과 워터링 홀

AhnLab contrasts two endpoint-compromise paths observed in South Korea: targeted phishing that launches BAT, executable, VBScript, and PowerShell stages, and watering-hole attacks that exploit locally installed Non-ActiveX security software. The demonstrated chains perform system discovery, anti-analysis checks, in-memory execution, file transfer, and remote command handling. The watering-hole example uses Dropbox, Cloudflare, GitHub, Solana, and Discord during payload delivery and command-and-control operations.

Related Reports

« Back