한 회사에 대한 sophisticaledged attack
cryptomonnaies의 포트폴리오를 11,8백만 달러에 달하는 한 회사에 대한 sophisticaledged attack이發生했다. 피어스가 사용한 false recruitment interview을 통해 공격자가 개발자의 컴퓨터를 해킹했다.
공격 방법
공격은 linkdin에 대한 false recruitment message와 code test를 통해 시작되었다. 개발자는 여러 google meet에 participation을 하였지만, ALWAYS 카메라가 off 상태였다. 이후 그는 linkdin에서 받은 link을 통해 test를 하였고, 이때 attack가 개발자의 account에 access를 하게 되었다.
faille
해킹의 faille는 development의 computer에 대한 attack에 있다. attack가 development의 Bitbucket account에 access를 하게 되었기 때문에, company의 automated deployment logiciels의 instruction을 modify할 수 있었다.
consequence
damage는 11.8 백만 달러에 달하는 것으로, Singapour police와 cybersecurity agency는 each recruitment channel을 official channel을 통해 verification을 하도록 reminder을 주었다.
lesson learned
이 attack은 simple test of recruitment을 통해 system finance의 company에 access가 possible해, company가 API key, multi-factor authentication, code repository, deployment procedure를 strong하게 protect해야 한다.
action to take
doubt이 있으면, immediately isolate the computer, revoke all active sessions, change the credentials, and check access logs. 또한, never execute technical test on a professional machine that is connected to the internal systems.
