#ByteTiger

Incident/Operation

2021-09-01 • TTPs#6 타겟형 워터링홀 공격전략 분석

Operation ByteTiger is the label used in KISA analysis for a targeted watering-hole intrusion chain. Attackers inserted a malicious script into a website visited by the intended organization, redirected selected visitors after IP filtering, exploited vulnerable software, and delivered a downloader. The first stage gathered system information, maintained command-and-control configuration, and supported command execution, file upload and download, termination, and server updates. A second-stage TigerRAT payload communicated through cloud-hosted infrastructure and exposed capabilities for victim profiling, shell commands, file management, keylogging, screen capture, tunneling, and port forwarding. The operation remains unattributed to a named threat actor.

Tagged Reports

« Back