워터링홀 사고 사례

2026-07-30 Plainbit Watering-Hole Incident Case Study

https://plainbit.co.kr/kr/insight/tech_hub?bgu=view&idx=72

Attachments

plainbit_watering_hole_incident_case_study.pdf (4 MB)

Thumbnail for 워터링홀 사고 사례

PLAINBIT reconstructed a watering-hole intrusion in which a compromised trusted website exploited a vulnerable third-party security component and installed DLL backdoors without requiring a user to launch a file. One chain modified SageThumbs-related shell-extension code, decrypted an embedded payload, injected into svchost.exe, and stored encrypted C2 configuration in the registry; another used Windows service loaders and encrypted .dat payloads to activate a memory-resident RAT. The intruders used privilege-escalation exploits, credential dumping, RDP-based lateral movement, a scheduled VBScript reverse SSH tunnel, and SDelete and CCleaner for anti-forensics. The publication supports a joint advisory about state-backed activity but does not identify North Korea or a specific actor.

Related Reports

« Back