#DarkPrism

Incident/Operation

2025-12-22 • 국가배후 해킹조직의 LNK 악성코드 위협 분석 (Campaign Dark Prism)

Dark Prism is an analytical grouping for state-sponsored activity that used malicious Windows shortcut files between January 2024 and September 2025. It covers multiple operators and layered intrusion patterns rather than a single payload or threat actor. The grouped activity includes evolving tactics and techniques, final-stage malware used to gain control of systems, and command-and-control traffic associated with LNK-based infection chains, providing a common label for varied state-backed operations that shared this initial delivery mechanism.

Tagged Reports

« Back