국내 엔드포인트 대상 공격의 두 축, 스피어피싱과 워터링 홀
2026-07-22 • Ahnlab • Two Main Vectors of Attacks Against South Korean Endpoints: Spearphishing and Watering Holes •
Attachments
source_3853_PZtzFwO.pdf (5 MB)
AhnLab contrasts two endpoint-compromise paths observed in South Korea: targeted phishing that launches BAT, executable, VBScript, and PowerShell stages, and watering-hole attacks that exploit locally installed Non-ActiveX security software. The demonstrated chains perform system discovery, anti-analysis checks, in-memory execution, file transfer, and remote command handling. The watering-hole example uses Dropbox, Cloudflare, GitHub, Solana, and Discord during payload delivery and command-and-control operations.
Related Reports
Shares tag: Phishing • Same author: Ahnlab • Published within a week
Shares tags: Phishing, Slides • Published within a week
Shares tag: Phishing • Same author: Ahnlab • Published within a week
Shares tag: Phishing • Published within a week
Shares tag: Phishing • Published within a week
Shares tag: Phishing • Published within a week