워터링홀 사고 사례
2026-07-30 • Plainbit • Watering-Hole Incident Case Study •
Attachments
PLAINBIT reconstructed a watering-hole intrusion in which a compromised trusted website exploited a vulnerable third-party security component and installed DLL backdoors without requiring a user to launch a file. One chain modified SageThumbs-related shell-extension code, decrypted an embedded payload, injected into svchost.exe, and stored encrypted C2 configuration in the registry; another used Windows service loaders and encrypted .dat payloads to activate a memory-resident RAT. The intruders used privilege-escalation exploits, credential dumping, RDP-based lateral movement, a scheduled VBScript reverse SSH tunnel, and SDelete and CCleaner for anti-forensics. The publication supports a joint advisory about state-backed activity but does not identify North Korea or a specific actor.