합동 사이버 보안 권고문 기술 분석 보고서(워터링홀 공격)

2026-07-30 ENKI Technical Analysis Report on the Joint Cybersecurity Advisory (Watering-Hole Attack)

https://www.enki.co.kr/media-center/blog/joint-cybersecurity-advisory-watering-hole-malware-analysis

Thumbnail for 합동 사이버 보안 권고문 기술 분석 보고서(워터링홀 공격)

State-sponsored attackers compromised legitimate South Korean websites and inserted exploit code targeting vulnerabilities in locally deployed security software, enabling drive-by malware installation. The recovered chains used ChaCha20 or AES-CBC-128 encryption, custom in-memory PE loading, service-slot hijacking, SSP persistence, registry and NTFS ADS storage, and modules concealed in valid PNG files. One final backdoor was identified as a COPPERHEDGE variant and supported system profiling, remote commands, file theft, payload execution, and process injection through encrypted HTTP or HTTPS traffic. Missing activation arguments, shellcode, ADS data, and externally stored keys prevented complete reconstruction of every infection chain.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 76c71c03440826adf26f4c35c36b973… 2026-07-30 2026-07-30
HASH 2e1dd779b28f86b5766c08245b86e37… 2026-07-30 2026-07-30

Related Reports

« Back