국내 엔드포인트 대상 공격의 두 축, 스피어피싱과 워터링 홀
2026-07-22 • Ahnlab • Two Main Vectors of Attacks Against South Korean Endpoints: Spearphishing and Watering Holes •
Attachments
source_3853_PZtzFwO.pdf (5 MB)
AhnLab contrasts two endpoint-compromise paths observed in South Korea: targeted phishing that launches BAT, executable, VBScript, and PowerShell stages, and watering-hole attacks that exploit locally installed Non-ActiveX security software. The demonstrated chains perform system discovery, anti-analysis checks, in-memory execution, file transfer, and remote command handling. The watering-hole example uses Dropbox, Cloudflare, GitHub, Solana, and Discord during payload delivery and command-and-control operations.
Related Reports
2026-07-30 •
50% Match
#Phishing
#Ransomware
#Whitepaper
#Wateringhole
#SIGNBT
#Gunra
#Copperhedge
#DoubleBarrel
Shares tags: Phishing, Wateringhole • Same author: Ahnlab • Published within a month
2026-07-30 •
50% Match
Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group)
Ahnlab
Shares tags: Phishing, Wateringhole • Same author: Ahnlab • Published within a month
Shares tag: Phishing • Same author: Ahnlab • Published within a month
Shares tag: Phishing • Same author: Ahnlab • Published within a month
Shares tags: Wateringhole, Fileless • Published within a month
Shares tags: Phishing, Wateringhole • Published within a month