ºÏÇÑ Á¤ºÎ¿ÍÀÇ ¿¬°ü¼ºÀÌ Á¦±âµÅ ¿Â ±¹Á¦ ÇØÅ·±×·ì ¡®¶óÀڷ罺¡¯ÀÇ »çÀ̹ö °ø°ÝÀÌ ¶Ç´Ù½Ã µå·¯³µ½À´Ï´Ù. ¹Ì ¹æÀ§»ê¾÷ü¿¡¼ º¸³½ °Íó·³ À§ÀåÇÑ ¹®¼ÆÄÀÏ µîÀ» ÅëÇØ ±ÝÀüÀû À̵æÀ» ÃëÇϰųª °ü·Ã Á¤º¸ À¯ÃâÀ» ½ÃµµÇÑ °ÍÀ¸·Î Àü¹®°¡µéÀº ºÐ¼®Çß½À´Ï´Ù. ±è½Ã¿µ ±âÀÚÀÇ º¸µµÀÔ´Ï´Ù.
±¹Á¦ ÇØÅ·±×·ì ¶óÀڷ罺(Lazarus)°¡ ÃÖ±Ù ¹Ì±¹ ¹æÀ§»ê¾÷ü·Î À§ÀåÇÑ »çÀ̹ö °ø°ÝÀ» Áö¼Ó ÁßÀ̶ó´Â ºÐ¼®ÀÌ ³ª¿Ô½À´Ï´Ù.
Çѱ¹³» »çÀ̹ö º¸¾È ¾÷ü À̽ºÆ® ½ÃÅ¥¸®Æ¼ (EST Security)´Â 15ÀÏ ¡°Áö´ÉÇü Áö¼Ó °ø°Ý(APT, Advanced Persistent Threat) Á¶Á÷ÀÎ ¶óÀڷ罺(Lazarus)ÀÇ °ø°ÝÀÌ Áö¼ÓµÇ°í ÀÖÀ¸¸ç, ±¹³»¿Ü °ø°Ý »Ó¸¸ ¾Æ´Ï¶ó ÃÖ±Ù¿¡´Â ÇØ¿Ü ¹æÀ§»ê¾÷ü¸¦ Ÿ±êÀ¸·Î °ø°ÝÀ» Áö¼Ó Áß¡±À̶ó°í ¹àÇû½À´Ï´Ù.
Áö´ÉÇü Áö¼Ó °ø°Ý(APT)À̶õ ºÒƯÁ¤ ´Ù¼ö¸¦ ´ë»óÀ¸·Î ÇÏ´Â ÀϹÝÀû »çÀ̹ö °ø°Ý°ú´Â ´Þ¸®, ÇϳªÀÇ ´ë»óÀ» ¸ñÇ¥·Î Á¤ÇÑ µÚ °ø°ÝÀÌ ¼º°øÇÒ ¶§±îÁö ¿©·¯ º¸¾È À§ÇùÀ» »ý»êÇØ ³»´Â »çÀ̹ö °ø°Ý ¹æ¹ýÀÔ´Ï´Ù.
¾Õ¼ Çѱ¹³» ¶Ç ´Ù¸¥ ¹Î°£ º¸¾È¾÷ü ¡®¾È·¦½ÃÅ¥¸®Æ¼´Â¡¯ Áö³ 8ÀÏ ¶óÀڷ罺°¡ ¹Ì±¹¿Í ¿µ±¹ÀÇ ¹æ»ê¾÷ü·Î À§ÀåÇØ Æ¯Á¤ °ü°èÀÚÀÇ Á¤º¸¸¦ ³ë¸° APT¸¦ ½ÇÇàÇÑ »ç½ÇÀÌ Æ÷ÂøµÆ´Ù°í ¹àÈù ¹Ù ÀÖ½À´Ï´Ù.
À̽ºÆ® ½ÃÅ¥¸®Æ¼´Â À̳¯ »õ·Î¿î APT ¾Ç¼º ¹®¼ ÆÄÀÏ 3°³°¡ È®ÀεÆÀ¸¸ç, Áö³ 5¿ù ÃÊ¿¡ ¶óÀڷ罺°¡ ¹Ì±¹°ú ¿µ±¹ ¹æÀ§»ê¾÷ü¸¦ °Ü³ÉÇß´ø ¾Ç¼º ¹®¼µé°ú À̸§¸¸ ´Ù¸¦ »Ó µ¿ÀÛ ¹æ½ÄÀÌ °°´Ù°í ¹àÇû½À´Ï´Ù.
±×·¯¸é¼ ¹Ì±¹ ¹æ»ê¾÷üÀÎ ·ÏÈ÷µå ¸¶Æ¾(Lockheed Martain), º¸À×(Boeing) ±×¸®°í ¿µ±¹ ºñ¿¡ÀÌÀÌ ½Ã½ºÅÛÁî(BAE Systems)ÀÇ ÀÎ»ç ´ã´çÀÚ µîÀÌ º¸³½ °Íó·³ °¡ÀåÇÑ ¹®¼ ÆÄÀÏÀÌ ÀÌ °ø°Ý¿¡ »ç¿ëµÆ´Ù°í µ¡ºÙ¿´½À´Ï´Ù.
À̾î ÇÇÇØÀÚ°¡ ÇØ´ç ¹®¼¸¦ ½ÇÇàÇÏ°Ô µÇ¸é, °ø°ÝÀÚ°¡ ¼³Á¤ÇÑ ÀÎÅÍ³Ý ÁּҷκÎÅÍ ÇÇÇØÀÚÀÇ ÄÄÇ»ÅÍ¿¡ ¾Ç¼º Äڵ尡 ³»·Á ¹Þ¾ÆÁ® ½ÇÇàµÇ´Â °ø°Ý ¹æ½ÄÀ» ¼³¸íÇß½À´Ï´Ù.
¶ÇÇÑ ¾Ç¼º ÄÚµå´Â ÇÇÇØÀÚ°¡ ÄÄÇ»Å͸¦ ÄÓ ¶§¸¶´Ù ÀÚµ¿ ½ÇÇàµÇµµ·Ï ½ÃÀÛ ÇÁ·Î±×·¥ °æ·Î¿¡ ¡®OneDrive.Ink¡¯ ÆÄÀÏ·Î µî·ÏµÇ´Â °ÍÀÌ Æ¯Â¡À̶ó°í ¹àÇû½À´Ï´Ù.
À̸¦ ÅëÇØ °¨¿°µÈ ÄÄÇ»ÅÍÀÇ À̸§, »ç¿ëÀÚ¸í, ÀúÀå ÀåÄ¡ Á¤º¸, ÇÁ·Î¼¼½º ¸®½ºÆ® µîÀÌ ºüÁ®³ª°¡°Ô µÈ´Ù´Â °Ì´Ï´Ù.
±×·¯¸é¼ ¶óÀڷ罺°¡ ÃÖ±Ù ¾Ç¼º ¹®¼ ÆÄÀÏÀ» ¹Ì³¢·Î ÇØ¿Ü ¹æÀ§»ê¾÷ü Ÿ±ê °ø°ÝÀ» ¼öÇàÇÏ°í ÀÖ°í, ÃÖ±Ù 1´Þ³»¿¡ ±²ÀåÈ÷ È°¹ßÇÑ È°µ¿À» º¸ÀÌ°í ÀÖ´Ù°í ¹àÇû½À´Ï´Ù.
¸ÅÆ© ÇÏ ¹ÎÁÖÁÖÀǼöÈ£Àç´Ü »çÀ̹ö ¾Èº¸ ´ã´ç ¿¬±¸¿øÀº 15ÀÏ VOA¿¡, ¹Ì±¹³» ¹æ»ê¾÷üµéÀº ¿¹ÀüºÎÅÍ ºÏÇÑÀÇ Ç¥ÀûÀÌ µÇ¾î ¿Ô´Ù°í ÁöÀûÇß½À´Ï´Ù.
[³ìÃë:ÇÏ ¿¬±¸¿ø] ¡°American defense companies like Lockheed Martin and Boeing, these are companies that have been targeted by North Korea in the past for espionage purposes. I think there was enough evidence in the malware in the cyber forensics within the various structure in decoding the Lazarus group. And thats a group that has already been tied multiple times to the North Korean regime, and these other underlying things to point to these other facts so there might not be a clear smoking gun but there are several indicators of compromise that point us to that direction.¡±
ÀÌ¾î ¶óÀڷ罺 ±×·ìÀÇ ¾Ç¼º ÇÁ·Î±×·¥¿¡ ´ëÇÑ °¨½ÄÀ» ÅëÇØ ¹àÇôÁø ´Ù¾çÇÑ ±¸Á¶ ºÐ¼®À» ÅëÇØ, (ºÏÇÑ°úÀÇ ¿¬°ü¼º¿¡) ÃæºÐÇÑ Áõ°Å°¡ È®º¸µÆÀ» °ÍÀ¸·Î »ý°¢ÇÑ´Ù°í ¼³¸íÇß½À´Ï´Ù.
ƯÈ÷ ¶óÀڷ罺´Â ºÏÇÑ Á¤±Ç°ú ÀÌ¹Ì ¼öÂ÷·Ê ¿¬°ü¼ºÀÌ Á¦±âµÆ´Ù¸ç, À̹ø Áõ°ÅµéÀÌ ºñ·Ï È®ÁõÀûÀÎ °ÍÀº ¾Æ´ÒÁö¶óµµ, ¿©·¯ ´Ù¸¥ Áõ°Åµé°ú ÇÔ²² ºÏÇÑ°úÀÇ ¿¬°ü¼ºÀ» °¡¸®Å°´Â ÁöÇ¥°¡ µÉ °ÍÀ̶ó°í µ¡ºÙ¿´½À´Ï´Ù.
¹Ì±¹ À繫ºÎ´Â Áö³ÇØ 9¿ù ÇØÅ·±×·ì ¶óÀڷ罺¸¦ ¡®ºí·ç³ë·ÎÇÁ¡¯, ¡®¾È´Ù¸®¿¤¡¯¿Í ÇÔ²² Á¦Àç ´ë»óÀ¸·Î ÁöÁ¤Çϸé¼, ÀÌ ´Üü°¡ ¹Ì±¹°ú À¯¿£ Á¦Àç ´ë»óÀÎ ºÏÇÑ Á¤ÂûÃѱ¹ÀÇ ÅëÁ¦¸¦ ¹Þ°í ÀÖ´Ù°í ¹àÈù ¹Ù ÀÖ½À´Ï´Ù.
»çÀ̹ö ¾Èº¸Àü·« Àü¹®°¡ÀÎ ¸®Â÷µå ÇÏÅ©³Ý ¹Ì±¹ ½Å½Ã³»Æ¼´ë ±³¼ö´Â 15ÀÏ VOA¿¡ ¡°°ø°³µÈ Á¤º¸¿¡ ÀÇÇÏ¸é ¶óÀڷ罺 ±×·ìÀÇ »çÀ̹ö ÀÛÀüÀº ´ëºÏ Á¦ÀçÀÇ È¿°ú¸¦ ¾àȽÃÅ°±â À§ÇØ ÀÚ±ÝÀ» Á¶´ÞÇÏ·Á´Â ¸ñÀûÀÇ »çÀ̹ö ±ÝÀ¶ »ç±â¡±°¡ Å« ºñÁßÀ» Â÷ÁöÇÑ´Ù°í ÁöÀûÇß½À´Ï´Ù.
±×·¯¸é¼ ¶óÀڷ罺 ±×·ìÀÌ ¹Ì ¹æ»ê¾÷ü¸¦ °Ü³ÉÇß´Ù¸é, ¹Ì±¹ÀÇ ÇÙ½É ¿¬±¸ ȤÀº ±â¹ÐÀ» ÈÉÃÄ ´Ù¸¥ ±¹°¡³ª ´Üüµé¿¡°Ô ÆÈ¾Æ µ·À» ¹ú¾úÀ» °¡´É¼ºÀÌ ÀÖ´Ù°í, ÇÏÅ©³Ý ±³¼ö´Â µ¡ºÙ¿´½À´Ï´Ù.
VOA´º½º ±è½Ã¿µÀÔ´Ï´Ù.