합동 사이버 보안 권고문 기술 분석 보고서(워터링홀 공격)
2026-07-30 • ENKI • Technical Analysis Report on the Joint Cybersecurity Advisory (Watering-Hole Attack) •
https://www.enki.co.kr/media-center/blog/joint-cybersecurity-advisory-watering-hole-malware-analysis
State-sponsored attackers compromised legitimate South Korean websites and inserted exploit code targeting vulnerabilities in locally deployed security software, enabling drive-by malware installation. The recovered chains used ChaCha20 or AES-CBC-128 encryption, custom in-memory PE loading, service-slot hijacking, SSP persistence, registry and NTFS ADS storage, and modules concealed in valid PNG files. One final backdoor was identified as a COPPERHEDGE variant and supported system profiling, remote commands, file theft, payload execution, and process injection through encrypted HTTP or HTTPS traffic. Missing activation arguments, shellcode, ADS data, and externally stored keys prevented complete reconstruction of every infection chain.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 76c71c03440826adf26f4c35c36b973… | 2026-07-30 | 2026-07-30 |
| HASH | 2e1dd779b28f86b5766c08245b86e37… | 2026-07-30 | 2026-07-30 |