{"id":163021,"date":"2025-09-02T07:19:03","date_gmt":"2025-09-02T14:19:03","guid":{"rendered":"https:\/\/unit42.paloaltonetworks.com\/?p=163021"},"modified":"2025-10-28T05:33:04","modified_gmt":"2025-10-28T12:33:04","slug":"threat-brief-compromised-salesforce-instances","status":"publish","type":"post","link":"https:\/\/unit42.paloaltonetworks.com\/ko\/threat-brief-compromised-salesforce-instances\/","title":{"rendered":"\uc704\ud611 \ube0c\ub9ac\ud551: Salesloft Drift \ud1b5\ud569 \uae30\ub2a5\uc744 \uc545\uc6a9\ud55c Salesforce \uc778\uc2a4\ud134\uc2a4 \uce68\ud574"},"content":{"rendered":"<h2><a id=\"post-163021-_69lcig1cvel5\"><\/a><strong>\uc694\uc57d<\/strong><\/h2>\n<p><span style=\"font-weight: 400;\">Unit 42\ub294 \ud2b9\uc815 \uc704\ud611 \ud589\uc704\uc790\uac00 Salesloft Drift \ud1b5\ud569 \uae30\ub2a5\uc744 \uc545\uc6a9\ud558\uc5ec \uace0\uac1d\uc758 Salesforce \uc778\uc2a4\ud134\uc2a4\ub97c \uce68\ud574\ud558\ub294 \ud65c\ub3d9\uc744 \uad00\ucc30\ud588\uc2b5\ub2c8\ub2e4. \ubcf8 \ube0c\ub9ac\ud551\uc740 Unit 42\uc758 \uad00\ucc30 \ub0b4\uc6a9\uacfc \uc7a0\uc7ac\uc801 \ud53c\ud574 \uc870\uc9c1\uc744 \uc704\ud55c \uc9c0\uce68\uc744 \uc81c\uacf5\ud569\ub2c8\ub2e4.<\/span><\/p>\n<p><a href=\"https:\/\/trust.salesloft.com\/?uid=Drift%2FSalesforce+Security+Notification\" target=\"_blank\" rel=\"noopener\">\ucd5c\uadfc Salesloft\uc758 \uacf5\uc9c0\uc5d0 \ub530\ub974\uba74<\/a>, 2025\ub144 8\uc6d4 8\uc77c\ubd80\ud130 18\uc77c\uae4c\uc9c0 \ud55c \uc704\ud611 \ud589\uc704\uc790\uac00 \ud0c8\ucde8\ud55c OAuth \ud06c\ub9ac\ub374\uc15c\uc744 \uc0ac\uc6a9\ud558\uc5ec \uc601\ud5a5\uc744 \ubc1b\ub294 \uace0\uac1d\uc758 Salesforce \ud658\uacbd\uc5d0\uc11c \ub370\uc774\ud130\ub97c \uc720\ucd9c\ud588\uc2b5\ub2c8\ub2e4.<\/p>\n<p>Unit 42\uc758 \uad00\ucc30\uc5d0 \ub530\ub974\uba74, \uc704\ud611 \ud589\uc704\uc790\ub294 Account, Contact, Case, Opportunity \ub808\ucf54\ub4dc \ub4f1 \ub2e4\uc591\ud55c Salesforce \uac1d\uccb4\uc5d0\uc11c \ubbfc\uac10\ud55c \ub370\uc774\ud130\uc758 \ub300\ub7c9 \uc720\ucd9c\uc744 \uc218\ud589\ud588\uc2b5\ub2c8\ub2e4. \ub370\uc774\ud130 \uc720\ucd9c \ud6c4, \uc774 \ud589\uc704\uc790\ub294 \ucd94\uac00 \uacf5\uaca9\uc744 \uc6a9\uc774\ud558\uac8c \ud558\uac70\ub098 \uc811\uadfc \uad8c\ud55c\uc744 \ud655\uc7a5\ud560 \ubaa9\uc801\uc73c\ub85c \ud68d\ub4dd\ud55c \ub370\uc774\ud130\uc5d0\uc11c \ud06c\ub9ac\ub374\uc15c\uc744 \uc801\uadf9\uc801\uc73c\ub85c \uc2a4\uce94\ud55c \uac83\uc73c\ub85c \ubcf4\uc785\ub2c8\ub2e4. \ub610\ud55c, \ud3ec\ub80c\uc2dd \ubc29\ud574 \uae30\uc220(anti-forensics)\uc758 \uc77c\ud658\uc73c\ub85c \uc790\uc2e0\ub4e4\uc774 \uc2e4\ud589\ud55c \uc791\uc5c5\uc758 \uc99d\uac70\ub97c \uc228\uae30\uae30 \uc704\ud574 \ucffc\ub9ac\ub97c \uc0ad\uc81c\ud55c \uc815\ud669\ub3c4 \ud3ec\ucc29\ud588\uc2b5\ub2c8\ub2e4.<\/p>\n<p>Salesloft\ub294 \uc601\ud5a5\uc744 \ubc1b\uc740 \ubaa8\ub4e0 \uace0\uac1d\uc5d0\uac8c \uacf5\uc9c0\ud588\uc73c\uba70, \uc2dc\uc2a4\ud15c\uc744 \ubcf4\ud638\ud558\uace0 \uc0ac\uace0\ub97c \uc5b5\uc81c \ubc0f \uc644\ud654\ud558\uae30 \uc704\ud55c \uc989\uac01\uc801\uc778 \uc870\uce58\ub97c \ucde8\ud588\uc74c\uc744 \ud655\uc778\ud588\uc2b5\ub2c8\ub2e4. \uc5ec\uae30\uc5d0\ub294 Drift \uc560\ud50c\ub9ac\ucf00\uc774\uc158\uc5d0 \ub300\ud55c \ubaa8\ub4e0 \ud65c\uc131 \uc561\uc138\uc2a4 \ud1a0\ud070\uacfc \ub9ac\ud504\ub808\uc2dc \ud1a0\ud070\uc744 \uc120\uc81c\uc801\uc73c\ub85c \ud3d0\uae30\ud558\uc5ec, \uc601\ud5a5\uc744 \ubc1b\ub294 \uad00\ub9ac\uc790\uac00 \uc7ac\uc778\uc99d\uc744 \ud558\ub3c4\ub85d \uc694\uad6c\ud558\ub294 \uc870\uce58\uac00 \ud3ec\ud568\ub429\ub2c8\ub2e4.<\/p>\n<p>Palo Alto Networks\ub294 \uc870\uc9c1\ub4e4\uc774 Salesforce \ubc0f Salesloft\uc758 \uc5c5\ub370\uc774\ud2b8\ub97c \uc9c0\uc18d\uc801\uc73c\ub85c \ubaa8\ub2c8\ud130\ub9c1\ud558\uace0, \uc544\ub798\uc5d0 \uacf5\uc720\ub41c \uad8c\uc7a5 \uc0ac\ud56d\uc744 \ub530\ub97c \uac83\uc744 \uad8c\uace0\ud569\ub2c8\ub2e4.<\/p>\n<p><a href=\"https:\/\/start.paloaltonetworks.com\/contact-unit42.html\" target=\"_blank\" rel=\"noopener\">Unit 42 \uce68\ud574 \uc0ac\uace0 \ub300\uc751<\/a>\ud300\uc740 \uce68\ud574 \uc0ac\uace0 \uc9c0\uc6d0 \ub610\ub294 \uc704\ud5d8\uc744 \ub0ae\ucd94\uae30 \uc704\ud55c \uc120\uc81c\uc801 \ud3c9\uac00\ub97c \uc81c\uacf5\ud560 \uc218 \uc788\uc2b5\ub2c8\ub2e4.<\/p>\n<table style=\"width: 97.6564%;\">\n<thead>\n<tr>\n<td style=\"width: 35%;\"><b>\uad00\ub828 Unit 42 \ud1a0\ud53d<\/b><\/td>\n<td style=\"width: 203.448%;\"><a href=\"https:\/\/unit42.paloaltonetworks.com\/ko\/category\/top-cyberthreats-ko\/\" target=\"_blank\" rel=\"noopener\"><b>\uc8fc\uc694 \uc704\ud611<\/b><\/a><b>, <\/b><a href=\"https:\/\/unit42.paloaltonetworks.com\/ko\/tag\/data-exfiltration-ko\/\" target=\"_blank\" rel=\"noopener\"><b>\ub370\uc774\ud130 \uc720\ucd9c<\/b><\/a><\/td>\n<\/tr>\n<\/thead>\n<\/table>\n<h2><a id=\"post-163021-_kfyb2yy1qskc\"><\/a><strong>\uc870\uc9c1\uc744 \uc704\ud55c \uad8c\uc7a5 \uc0ac\ud56d<\/strong><\/h2>\n<p>Salesforce\uc640 Salesloft Drift \ud1b5\ud569 \uae30\ub2a5\uc744 \uc0ac\uc6a9\ud558\ub294 \uc870\uc9c1\uc740 \uc774\ubc88 \uc0ac\uace0\ub97c \uc989\uac01\uc801\uc778 \uc704\ud611\uc73c\ub85c \uac04\uc8fc\ud558\uace0 \ub300\uc751\ud574\uc57c \ud569\ub2c8\ub2e4. Salesloft\uac00 \ud1a0\ud070 \ud3d0\uae30 \ub4f1 \ud50c\ub7ab\ud3fc \ubcf4\uc548\uc744 \uc704\ud574 \ucde8\ud55c \uc120\uc81c\uc801\uc778 \uc870\uce58 \uc678\uc5d0\ub3c4, \uc7a0\uc7ac\uc801\uc778 \uc601\ud5a5\uc744 \ud3c9\uac00\ud558\uace0 \ucd94\uac00 \uc704\ud5d8\uc744 \uc644\ud654\ud558\uae30 \uc704\ud574 \ub2e4\uc74c \uad8c\uc7a5 \uc0ac\ud56d\uc744 \ub530\ub974\ub294 \uac83\uc774 \uc911\uc694\ud569\ub2c8\ub2e4.<\/p>\n<p><strong>\uc989\uac01\uc801\uc778 \uc870\uc0ac \ubc0f \ub85c\uadf8 \uac80\ud1a0:<\/strong><\/p>\n<ul>\n<li><strong>Drift API \ud1b5\ud569:<\/strong> \ubaa8\ub4e0 Drift \ud1b5\ud569 \uae30\ub2a5\uc744 \ucca0\uc800\ud788 \uac80\ud1a0\ud558\uace0, \uc758\uc2ec\uc2a4\ub7ec\uc6b4 \uc5f0\uacb0, \ud06c\ub9ac\ub374\uc15c \ud0c8\ucde8, \ub370\uc774\ud130 \uc720\ucd9c \uc9d5\ud6c4\uac00 \uc788\ub294\uc9c0 \uc11c\ub4dc\ud30c\ud2f0 \uc2dc\uc2a4\ud15c \ub0b4\uc758 \ubaa8\ub4e0 \uc778\uc99d \ud65c\ub3d9\uc744 \uac80\ud1a0\ud569\ub2c8\ub2e4.<\/li>\n<li><strong>Salesforce \ub85c\uadf8:<\/strong> 8\uc6d4 8\uc77c\ubd80\ud130 \ud604\uc7ac\uae4c\uc9c0\uc758 Salesforce \ub85c\uadf8\uc778 \uae30\ub85d, \uac10\uc0ac \ucd94\uc801(audit trails), API \uc811\uadfc \ub85c\uadf8\ub97c \uba74\ubc00\ud788 \uac80\ud1a0\ud569\ub2c8\ub2e4. \ud2b9\ud788, Salesforce \uc774\ubca4\ud2b8 \ubaa8\ub2c8\ud130\ub9c1 \ub85c\uadf8(\ud65c\uc131\ud654\ub41c \uacbd\uc6b0)\uc5d0\uc11c Drift \uc5f0\uacb0 \uc0ac\uc6a9\uc790\uc640 \uad00\ub828\ub41c \ube44\uc815\uc0c1\uc801\uc778 \ud65c\ub3d9\uc774 \uc788\ub294\uc9c0, Drift \uc5f0\uacb0 \uc571(Connected App)\uc758 \uc778\uc99d \ud65c\ub3d9\uc744 \uac80\ud1a0\ud569\ub2c8\ub2e4. \uc758\uc2ec\uc2a4\ub7ec\uc6b4 \ub85c\uadf8\uc778 \uc2dc\ub3c4, \ube44\uc815\uc0c1\uc801\uc778 \ub370\uc774\ud130 \uc811\uadfc \ud328\ud134, \uadf8\ub9ac\uace0 '\ud5cc\ud305 \uac00\uc774\ub358\uc2a4' \uc139\uc158\uc5d0\uc11c \uc5b8\uae09\ub41c <span style=\"font-family: 'courier new', courier, monospace;\">Python\/3.11 aiohttp\/3.12.15<\/span> \uc0ac\uc6a9\uc790 \uc5d0\uc774\uc804\ud2b8 \ubb38\uc790\uc5f4 \ubc0f \uc54c\ub824\uc9c4 \uc704\ud611 \ud589\uc704\uc790 IP \uc8fc\uc18c \ud65c\ub3d9\uacfc \uac19\uc740 \uc9c0\ud45c\ub97c \ucc3e\uc2b5\ub2c8\ub2e4. \ub610\ud55c, <span style=\"font-family: 'courier new', courier, monospace;\">UniqueQuery<\/span> \uc774\ubca4\ud2b8\ub97c \uac80\ud1a0\ud558\uc5ec \uacf5\uaca9\uc790\uac00 \uc5b4\ub5a4 Salesforce \uac1d\uccb4(\uc608: <span style=\"font-family: 'courier new', courier, monospace;\">Account, Contact, Opportunity, Case<\/span> \ub4f1)\uc640 \ud574\ub2f9 \uac1d\uccb4 \ub0b4\uc758 \uc5b4\ub5a4 \ud544\ub4dc\ub97c \ucffc\ub9ac\ud588\ub294\uc9c0 \uc2dd\ubcc4\ud558\uae30 \uc704\ud574 \uc2e4\ud589\ub41c Salesforce Object Query Language (SOQL) \ucffc\ub9ac\ub97c \ud655\uc778\ud569\ub2c8\ub2e4. \ud544\uc694\ud55c \uacbd\uc6b0, Salesforce \uc9c0\uc6d0 \ucf00\uc774\uc2a4\ub97c \uc5f4\uc5b4 \uc704\ud611 \ud589\uc704\uc790\uac00 \uc0ac\uc6a9\ud55c \ud2b9\uc815 \ucffc\ub9ac\ub97c \ud655\ubcf4\ud558\ub294 \uac83\uc744 \uace0\ub824\ud558\uc2ed\uc2dc\uc624.<\/li>\n<li><strong>ID \uacf5\uae09\uc790(IdP) \ub85c\uadf8:<\/strong> \uc0ac\uace0 \uae30\uac04 \ub3d9\uc548 Salesforce \ub610\ub294 \uae30\ud0c0 \ud1b5\ud569 \uc560\ud50c\ub9ac\ucf00\uc774\uc158\uc5d0 \ub300\ud55c \ube44\uc815\uc0c1\uc801\uc778 \uc778\uc99d \uc2dc\ub3c4\ub098 \uc131\uacf5\uc801\uc778 \ub85c\uadf8\uc778\uc774 \uc788\ub294\uc9c0 IdP \ub85c\uadf8\ub97c \uac80\ud1a0\ud569\ub2c8\ub2e4.<\/li>\n<li><strong>\ub124\ud2b8\uc6cc\ud06c \ub85c\uadf8:<\/strong> \uc758\uc2ec\uc2a4\ub7ec\uc6b4 IP\ub85c\ubd80\ud130\uc758 Salesforce \uc5f0\uacb0\uc774\ub098 \ube44\uc815\uc0c1\uc801\uc778 \ub370\uc774\ud130 \uc804\uc1a1\ub7c9\uc774 \uc788\ub294\uc9c0 \ub124\ud2b8\uc6cc\ud06c \ud50c\ub85c\uc6b0 \ub85c\uadf8\uc640 \ud504\ub85d\uc2dc \ub85c\uadf8\ub97c \ubd84\uc11d\ud569\ub2c8\ub2e4.<\/li>\n<\/ul>\n<p><strong>\ub178\ucd9c\ub41c \ud06c\ub9ac\ub374\uc15c \uac80\ud1a0 \ubc0f \uad50\uccb4:<\/strong><\/p>\n<ul>\n<li><strong>\uc790\ub3d9\ud654 \ub3c4\uad6c:<\/strong> Trufflehog, GitLeaks\uc640 \uac19\uc740 \uc790\ub3d9\ud654 \ub3c4\uad6c\ub97c \ud65c\uc6a9\ud558\uc5ec \ucf54\ub4dc \uc800\uc7a5\uc18c, \uc124\uc815 \ud30c\uc77c \ub610\ub294 \uc720\ucd9c \uac00\ub2a5\uc131\uc774 \uc788\ub294 \ub370\uc774\ud130 \ub0b4\uc758 \uc2dc\ud06c\ub9bf(secrets) \ubc0f \ud558\ub4dc\ucf54\ub529\ub41c \ud06c\ub9ac\ub374 (\ud558\ub4dc\ucf54\ub529\ub41c \ud06c\ub9ac\ub374\uc15c)\uc744 \ud6a8\uc728\uc801\uc73c\ub85c \uc2a4\uce94\ud569\ub2c8\ub2e4.<\/li>\n<li><strong>\ub370\uc774\ud130 \uc815\ubc00 \uac80\uc0ac:<\/strong> \ub370\uc774\ud130 \uc720\ucd9c\uc774 \ud655\uc778\ub418\uac70\ub098 \uc758\uc2ec\ub418\ub294 \uacbd\uc6b0, \ubbfc\uac10\ud55c \ud06c\ub9ac\ub374\uc15c\uc774 \ud3ec\ud568\ub418\uc5b4 \uc788\ub294\uc9c0 \ub370\uc774\ud130\ub97c \uac80\ud1a0\ud569\ub2c8\ub2e4. \uc5ec\uae30\uc5d0\ub294 AWS \uc561\uc138\uc2a4 \ud0a4 ID(\uc608: <span style=\"font-family: 'courier new', courier, monospace;\">AKIA<\/span>), Snowflake \ud06c\ub9ac\ub374\uc15c(\uc608: <span style=\"font-family: 'courier new', courier, monospace;\">Snowflake<\/span> \ub610\ub294 <span style=\"font-family: 'courier new', courier, monospace;\">snowflakecomputing[.]com<\/span>)\uacfc \uac19\uc740 \ud328\ud134, <span style=\"font-family: 'courier new', courier, monospace;\">password<\/span>, <span style=\"font-family: 'courier new', courier, monospace;\">secret<\/span> \ub610\ub294 <span style=\"font-family: 'courier new', courier, monospace;\">key<\/span>\uc640 \uac19\uc740 \uc77c\ubc18\uc801\uc778 \ud0a4\uc6cc\ub4dc, \uadf8\ub9ac\uace0 \uc870\uc9c1\ubcc4 \ub85c\uadf8\uc778 URL(\uc608: VPN \ub610\ub294 SSO \ub85c\uadf8\uc778 \ud398\uc774\uc9c0)\uacfc \uad00\ub828\ub41c \ubb38\uc790\uc5f4 \uac80\uc0c9\uc774 \ud3ec\ud568\ub429\ub2c8\ub2e4.<\/li>\n<li><strong>\uc989\uac01\uc801\uc778 \uad50\uccb4:<\/strong> \uc720\ucd9c\ub41c \ub370\uc774\ud130 \ub0b4\uc5d0\uc11c \uc2dd\ubcc4\ub41c \ubaa8\ub4e0 \ud06c\ub9ac\ub374\uc15c\uc744 \uc989\uc2dc \uad50\uccb4\ud569\ub2c8\ub2e4. \uc5ec\uae30\uc5d0\ub294 Salesforce API \ud0a4, \uc5f0\uacb0 \uc571 \ud06c\ub9ac\ub374\uc15c \ubc0f \uce68\ud574\ub41c \ub370\uc774\ud130 \ub0b4\uc5d0\uc11c \ubc1c\uacac\ub41c \uae30\ud0c0 \ubaa8\ub4e0 \uc2dc\uc2a4\ud15c \ud06c\ub9ac\ub374\uc15c\uc774 \ud3ec\ud568\ub418\uba70 \uc774\uc5d0 \uad6d\ud55c\ub418\uc9c0 \uc54a\uc2b5\ub2c8\ub2e4.<\/li>\n<\/ul>\n<h2><b>\ud5cc\ud305 \uc9c0\uce68<\/b><\/h2>\n<p>Salesloft Drift \ud1b5\ud569 \uae30\ub2a5 \uad00\ub828 \uce68\ud574 \uac00\ub2a5\uc131\uc774 \uc6b0\ub824\ub418\ub294 \uc870\uc9c1\uc740 \uc989\uc2dc Salesforce \ud658\uacbd \ub0b4\uc5d0\uc11c \uc120\uc81c\uc801\uc778 \uc704\ud611 \ud5cc\ud305 \ud65c\ub3d9\uc744 \uc2dc\uc791\ud574\uc57c \ud569\ub2c8\ub2e4. (<a href=\"https:\/\/trust.salesloft.com\/?uid=Drift%2FSalesforce+Security+Notification\" target=\"_blank\" rel=\"noopener\">Salesforce\ub294 Salesforce \ubcf4\uc548 \uc0ac\uace0 \uc870\uc0ac\ub97c \uc704\ud55c \uba87 \uac00\uc9c0 \ub9ac\uc18c\uc2a4\ub97c \uc81c\uacf5\ud558\uace0 \uc788\uc2b5\ub2c8\ub2e4.<\/a>) \uc911\uc694\ud55c \uccab \ubc88\uc9f8 \ub2e8\uacc4\ub294 \uc704\ud611 \ud589\uc704\uc790\uc640 \uad00\ub828\ub41c \ud2b9\uc815 \uce68\ud574 \uc9c0\ud45c(IoC)\uc5d0 \ub300\ud574 Salesforce \ub85c\uadf8\uc778 \ubc0f \ud65c\ub3d9 \ub85c\uadf8\ub97c \ucca0\uc800\ud788 \uac80\ud1a0\ud558\ub294 \uac83\uc785\ub2c8\ub2e4.<\/p>\n<p>\ubc29\uc5b4 \ub2f4\ub2f9\uc790\ub294 \uc54c\ub824\uc9c4 \uc704\ud611 \ud589\uc704\uc790 IP \uc8fc\uc18c\ub97c \ud3ec\ud568\ud558\ub418 \uc774\uc5d0 \uad6d\ud55c\ub418\uc9c0 \uc54a\ub294 \uc758\uc2ec\uc2a4\ub7ec\uc6b4 IP \uc8fc\uc18c\uc5d0\uc11c \ubc1c\uc0dd\ud55c \ub85c\uadf8\uc778\uc744 \ucc3e\uc544\uc57c \ud569\ub2c8\ub2e4(\uc815\ubcf4 \ubc0f \uc870\uc5b8\uc740 \ubcf8 \ubcf4\uace0\uc11c\uc758 '\uce68\ud574 \uc9c0\ud45c' \uc139\uc158 \ucc38\uc870).<\/p>\n<p>\ud2b9\ud788 \uc8fc\ubaa9\ud574\uc57c \ud560 \uc810\uc740 \uc774\ub7ec\ud55c \ub85c\uadf8\uc778 \uc774\ubca4\ud2b8\uc640 \uad00\ub828\ub41c <span style=\"font-family: 'courier new', courier, monospace;\">Python\/3.11 aiohttp\/3.12.15<\/span> \uc0ac\uc6a9\uc790 \uc5d0\uc774\uc804\ud2b8 \ubb38\uc790\uc5f4\uc758 \uc874\uc7ac\uc785\ub2c8\ub2e4. \uc774 \ud2b9\uc815 \ubb38\uc790\uc5f4\uc740 \uadf8 \uc790\uccb4\ub85c \uc545\uc758\uc801\uc774\uc9c0 \uc54a\uc740 \uc720\ud6a8\ud55c \uc0ac\uc6a9\uc790 \uc5d0\uc774\uc804\ud2b8\uc77c \uc218 \uc788\uc9c0\ub9cc, \uc774\ubc88 \ucea0\ud398\uc778\uc5d0\uc11c \uad00\ucc30\ub41c \uc790\ub3d9\ud654\ub41c \ub300\ub7c9 \ub370\uc774\ud130 \uc720\ucd9c\uc744 \ub098\ud0c0\ub0b4\ub294 \uc9c0\ud45c\uc774\uae30\ub3c4 \ud569\ub2c8\ub2e4.<\/p>\n<p>\uc774 \ubb38\uc790\uc5f4\uc758 \uc874\uc7ac\uac00 \uc911\uc694\ud55c \uc774\uc720\ub294 \uc704\ud611 \ud589\uc704\uc790\uac00 <span style=\"font-family: 'courier new', courier, monospace;\">aiohttp<\/span>\uc640 \uac19\uc740 \ube44\ub3d9\uae30\uc2dd Python \ub77c\uc774\ube0c\ub7ec\ub9ac\ub97c Salesforce\uc758 Bulk API\uc640 \uacb0\ud569\ud558\uc5ec \ube60\ub974\uace0 \ub192\uc740 \ucc98\ub9ac\ub7c9\uc758 \ub370\uc774\ud130 \uc720\ucd9c\uc744 \uc218\ud589\ud560 \uc218 \uc788\uae30 \ub54c\ubb38\uc785\ub2c8\ub2e4. \uc774\ub7ec\ud55c \uc870\ud569\uc744 \ud1b5\ud574 <span style=\"font-family: 'courier new', courier, monospace;\">Account, Contact, Case, Opportunity<\/span>\uc640 \uac19\uc740 Salesforce \uac1d\uccb4\uc5d0\uc11c \ub300\ub7c9\uc758 \ub370\uc774\ud130\ub97c \ud6a8\uc728\uc801\uc73c\ub85c \ucd94\ucd9c\ud558\uc5ec \uacf5\uaca9 \ub300\uc0c1 \uc2dc\uc2a4\ud15c\uc5d0\uc11c\uc758 \uccb4\ub958 \uc2dc\uac04(time on target)\uc744 \ucd5c\uc18c\ud654\ud560 \uc218 \uc788\uc2b5\ub2c8\ub2e4.<\/p>\n<h2><a id=\"post-163021-_w04jrvlfwkko\"><\/a><strong>\uacb0\ub860<\/strong><\/h2>\n<p>Palo Alto Networks\ub294 \ud06c\ub9ac\ub374\uc15c\uc744 \uad50\uccb4\ud558\uace0 \uc704\uc758 \uac00\uc774\ub4dc\ub77c\uc778\uc5d0 \ub530\ub77c Drift \ud1b5\ud569 \uae30\ub2a5\uc758 \uc778\uc99d \ud65c\ub3d9\uc744 \uac80\uc99d\ud560 \uac83\uc744 \uac15\ub825\ud788 \uad8c\uace0\ud569\ub2c8\ub2e4. \uacbd\uacc4\uc640 \uac80\uc99d\uc774 \ud575\uc2ec\uc785\ub2c8\ub2e4.<\/p>\n<p>\uc870\uc9c1\uc740 \uc774\ubc88 \ub610\ub294 \uae30\ud0c0 \ub370\uc774\ud130 \uc720\ucd9c \uc774\ubca4\ud2b8\ub85c \uc778\ud574 \ubc1c\uc0dd\ud560 \uc218 \uc788\ub294 \uc0ac\ud68c \uacf5\ud559\uc801 \uacf5\uaca9 \uc2dc\ub3c4\uc5d0 \uc8fc\uc758\ud574\uc57c \ud569\ub2c8\ub2e4.<\/p>\n<p>\ubaa8\ubc94 \uc0ac\ub840\ub294 \ub2e4\uc74c\uacfc \uac19\uc2b5\ub2c8\ub2e4.<\/p>\n<ul>\n<li><strong>\uc694\uccad\ud558\uc9c0 \uc54a\uc740 \ud1b5\uc2e0\uc5d0 \ub300\ud55c \ud68c\uc758\uc801 \ud0dc\ub3c4:<\/strong> \uc2e0\ub8b0\ud560 \uc218 \uc788\ub294 \ucd9c\ucc98\uc5d0\uc11c \uc628 \uac83\ucc98\ub7fc \ubcf4\uc774\ub354\ub77c\ub3c4, \uc694\uccad\ud558\uc9c0 \uc54a\uc558\uac70\ub098 \ube44\uc815\uc0c1\uc801\uc778 \uc774\uba54\uc77c, \uc804\ud654 \ub610\ub294 \uba54\uc2dc\uc9c0\ub97c \uc8fc\uc758 \uae4a\uac8c \uac80\ud1a0\ud558\ub3c4\ub85d \ud300\uc5d0 \uad8c\uace0\ud569\ub2c8\ub2e4.<\/li>\n<li><strong>\uc694\uccad \uac80\uc99d:<\/strong> \ubbfc\uac10\ud55c \ub370\uc774\ud130\ub098 \ud06c\ub9ac\ub374\uc15c \uc694\uccad\uc5d0 \ub300\ud574\uc11c\ub294 \uc870\uce58\ub97c \ucde8\ud558\uae30 \uc804\uc5d0 \ud56d\uc0c1 \ubcc4\ub3c4\uc758 \uacf5\uc2dd\uc801\uc778 \ud1b5\uc2e0 \ucc44\ub110\uc744 \ud1b5\ud574 \ud655\uc778\ud569\ub2c8\ub2e4. \uc608\ub97c \ub4e4\uc5b4, \ub3d9\ub8cc\ub85c\ubd80\ud130 \uc758\uc2ec\uc2a4\ub7ec\uc6b4 \uc774\uba54\uc77c\uc744 \ubc1b\uc73c\uba74 \ud574\ub2f9 \ub3d9\ub8cc\uc5d0\uac8c \uc9c1\uc811 \uc804\ud654\ud558\uc5ec \uc694\uccad\uc774 \ud569\ubc95\uc801\uc778\uc9c0 \ud655\uc778\ud558\uc2ed\uc2dc\uc624. \uc815\ubcf4 \ubc0f \ud30c\uc77c \uad50\ud658\uc740 \uc774\uba54\uc77c\uc774 \uc544\ub2cc \uace0\uac1d \uc9c0\uc6d0 \ud3ec\ud138\uc744 \ud1b5\ud574\uc11c\ub9cc \uc218\ud589\ud558\uc2ed\uc2dc\uc624.<\/li>\n<li><strong>\uc81c\ub85c \ud2b8\ub7ec\uc2a4\ud2b8 \uc6d0\uce59 \uad6c\ud604:<\/strong> \uc870\uac74\ubd80 \uc561\uc138\uc2a4 \uc815\ucc45\uacfc \ucd5c\uc18c \uad8c\ud55c \uc6d0\uce59\uc744 \uac16\ucd98 \uc81c\ub85c \ud2b8\ub7ec\uc2a4\ud2b8(Zero Trust) \ud0dc\uc138\ub97c \uc2dc\ud589\ud558\uba74, \uacf5\uaca9\uc790\uac00 \uc9c1\uc6d0\uc744 \uc131\uacf5\uc801\uc73c\ub85c \uc18d\uc774\ub354\ub77c\ub3c4 \ub124\ud2b8\uc6cc\ud06c \ub0b4\uc5d0\uc11c \uce21\uba74 \uc774\ub3d9(lateral movement)\ud558\ub294 \ub2a5\ub825\uc744 \ud06c\uac8c \uc81c\ud55c\ud560 \uc218 \uc788\uc2b5\ub2c8\ub2e4.<\/li>\n<\/ul>\n<p>\uc0ac\ud68c \uacf5\ud559\uc801 \uacf5\uaca9 \ubc0f \uc644\ud654 \ubc29\ubc95\uc5d0 \ub300\ud55c \uc790\uc138\ud55c \ub0b4\uc6a9\uc740 \ucd5c\uadfc \ubc1c\uac04\ub41c '<a href=\"https:\/\/unit42.paloaltonetworks.com\/2025-unit-42-global-incident-response-report-social-engineering-edition\/\" target=\"_blank\" rel=\"noopener\">2025 Unit 42 \uae00\ub85c\ubc8c \uce68\ud574 \uc0ac\uace0 \ub300\uc751 \ubcf4\uace0\uc11c: \uc0ac\ud68c \uacf5\ud559 \uc5d0\ub514\uc158'\uc744 \ucc38\uc870\ud558\uc2ed\uc2dc\uc624<\/a>.<\/p>\n<p>Palo Alto Networks\uc640 Unit 42\ub294 \uc5c5\ub370\uc774\ud2b8\ub41c \uc815\ubcf4\ub97c \uc5bb\uae30 \uc704\ud574 \uc0c1\ud669\uc744 \uc9c0\uc18d\uc801\uc73c\ub85c \ubaa8\ub2c8\ud130\ub9c1\ud560 \uac83\uc774\uba70, \ucd94\uac00 \uc815\ubcf4\uac00 \uc785\uc218\ub418\uba74 \ubcf8 \uc704\ud611 \ube0c\ub9ac\ud551\uc744 \uc5c5\ub370\uc774\ud2b8\ud560 \uac83\uc785\ub2c8\ub2e4.<\/p>\n<p>Salesforce\ub294 <a href=\"https:\/\/help.salesforce.com\/s\/articleView?id=005134951&amp;type=1\" target=\"_blank\" rel=\"noopener\">\uace0\uac1d\uc5d0\uac8c \uc5c5\ub370\uc774\ud2b8\uc640 \ub9ac\uc18c\uc2a4\ub97c \uc81c\uacf5\ud560 \uc608\uc815\uc785\ub2c8\ub2e4<\/a>.<\/p>\n<p>\uce68\ud574\uac00 \uc758\uc2ec\ub418\uac70\ub098 \uae34\uae09\ud55c \ubb38\uc81c\uac00 \uc788\ub294 \uacbd\uc6b0, <a href=\"https:\/\/start.paloaltonetworks.com\/contact-unit42.html\" target=\"_blank\" rel=\"noopener\">Unit 42 \uce68\ud574 \uc0ac\uace0 \ub300\uc751\ud300\uc5d0 \uc5f0\ub77d\ud558\uac70<\/a>\ub098 \ub2e4\uc74c \ubc88\ud638\ub85c \uc804\ud654\ud558\uc2ed\uc2dc\uc624.<\/p>\n<ul>\n<li>\ubd81\ubbf8: \ubb34\ub8cc \uc804\ud654: +1 (866) 486-4842 (866.4.unit42)<\/li>\n<li>\uc601\uad6d: +44.20.3743.3660<\/li>\n<li>\uc720\ub7fd \ubc0f \uc911\ub3d9: +31.20.299.3130<\/li>\n<li>\uc544\uc2dc\uc544: +65.6983.8730<\/li>\n<li>\uc77c\ubcf8: +81.50.1790.0200<\/li>\n<li>\ud638\uc8fc: +61.2.4062.7950<\/li>\n<li>\uc778\ub3c4: 00080005045107<\/li>\n<\/ul>\n<h2><a id=\"post-163021-_hjmpkbwf3p5y\"><\/a><strong>\uce68\ud574 \uc9c0\ud45c (Indicators of Compromise)<\/strong><\/h2>\n<p>Salesloft\ub294 \ud5cc\ud305\uc5d0 \uc0ac\uc6a9\ud560 \uc218 \uc788\ub294 \uc77c\ubd80 <a href=\"https:\/\/trust.salesloft.com\/?uid=Drift%2FSalesforce+Security+Notification\" target=\"_blank\" rel=\"noopener\">IoC<\/a>\ub97c \uacf5\uac1c\ud588\uc2b5\ub2c8\ub2e4. \uc774 \uacf5\uc9c0\uc5d0 \ub098\uc5f4\ub41c IP \uc8fc\uc18c \uc911 \ub2e4\uc218\ub294 Tor \uc885\ub8cc \ub178\ub4dc(exit nodes)\uc774\uba70, Tor \uc5f0\uacb0\uc744 \ud5c8\uc6a9\ud558\ub294 \uc870\uc9c1\uc5d0\uc11c\ub294 \ub192\uc740 \uc624\ud0d0(false positive) \ube44\uc728\uc744 \ubcf4\uc77c \uc218 \uc788\ub2e4\ub294 \uc810\uc5d0 \uc720\uc758\ud574\uc57c \ud569\ub2c8\ub2e4.<\/p>\n<h2><a id=\"post-163021-_d2lzokt9jjf6\"><\/a><strong>\ucd94\uac00 \ub9ac\uc18c\uc2a4<\/strong><\/h2>\n<ul>\n<li><a href=\"https:\/\/www.paloaltonetworks.com\/blog\/2025\/09\/salesforce-third-party-application-incident-response\/\" target=\"_blank\" rel=\"noopener\">Salesforce\uc5d0 \uc5f0\uacb0\ub41c \uc11c\ub4dc\ud30c\ud2f0 Drift \uc560\ud50c\ub9ac\ucf00\uc774\uc158 \uce68\ud574 \uc0ac\uace0 \ub300\uc751<\/a> \u2013 Palo Alto Networks<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>\ubcf8 \uc704\ud611 \ube0c\ub9ac\ud504\uc5d0\uc11c\ub294 Salesloft Drift \uc5f0\ub3d9 \uae30\ub2a5\uc744 \uc545\uc6a9\ud558\uc5ec, \ud0c8\ucde8\ub41c OAuth \uc790\uaca9 \uc99d\uba85\uc744 \ud1b5\ud574 \ub370\uc774\ud130\ub97c \uc720\ucd9c\ud558\ub294 \ucea0\ud398\uc778\uc5d0 \ub300\ud55c \uad00\ucc30 \ub0b4\uc6a9\uc744 \ub2e4\ub8f9\ub2c8\ub2e4.<\/p>\n","protected":false},"author":23,"featured_media":155480,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[8772,8853],"tags":[9721,9722,9723,9724],"product_categories":[9150],"coauthors":[1025],"class_list":["post-163021","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-top-cyberthreats-ko","category-vulnerabilities-ko","tag-credential-based-attacks-ko","tag-data-exfiltration-ko","tag-salesforce-ko","tag-salesloft-ko","product_categories-unit-42-incident-response-ko"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.0 (Yoast SEO v27.0) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>\uc704\ud611 \ube0c\ub9ac\ud551: Salesloft Drift \ud1b5\ud569 \uae30\ub2a5\uc744 \uc545\uc6a9\ud55c Salesforce \uc778\uc2a4\ud134\uc2a4 \uce68\ud574<\/title>\n<meta name=\"description\" content=\"\ubcf8 \uc704\ud611 \ube0c\ub9ac\ud504\uc5d0\uc11c\ub294 Salesloft Drift \uc5f0\ub3d9 \uae30\ub2a5\uc744 \uc545\uc6a9\ud558\uc5ec, \ud0c8\ucde8\ub41c OAuth \uc790\uaca9 \uc99d\uba85\uc744 \ud1b5\ud574 \ub370\uc774\ud130\ub97c \uc720\ucd9c\ud558\ub294 \ucea0\ud398\uc778\uc5d0 \ub300\ud55c \uad00\ucc30 \ub0b4\uc6a9\uc744 \ub2e4\ub8f9\ub2c8\ub2e4.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/unit42.paloaltonetworks.com\/ko\/threat-brief-compromised-salesforce-instances\/\" \/>\n<meta property=\"og:locale\" content=\"ko_KR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\uc704\ud611 \ube0c\ub9ac\ud551: Salesloft Drift \ud1b5\ud569 \uae30\ub2a5\uc744 \uc545\uc6a9\ud55c Salesforce \uc778\uc2a4\ud134\uc2a4 \uce68\ud574\" \/>\n<meta property=\"og:description\" content=\"\ubcf8 \uc704\ud611 \ube0c\ub9ac\ud504\uc5d0\uc11c\ub294 Salesloft Drift \uc5f0\ub3d9 \uae30\ub2a5\uc744 \uc545\uc6a9\ud558\uc5ec, \ud0c8\ucde8\ub41c OAuth \uc790\uaca9 \uc99d\uba85\uc744 \ud1b5\ud574 \ub370\uc774\ud130\ub97c \uc720\ucd9c\ud558\ub294 \ucea0\ud398\uc778\uc5d0 \ub300\ud55c \uad00\ucc30 \ub0b4\uc6a9\uc744 \ub2e4\ub8f9\ub2c8\ub2e4.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/unit42.paloaltonetworks.com\/ko\/threat-brief-compromised-salesforce-instances\/\" \/>\n<meta property=\"og:site_name\" content=\"Unit 42\" \/>\n<meta property=\"article:published_time\" content=\"2025-09-02T14:19:03+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-10-28T12:33:04+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2025\/08\/7_Category_1616x600.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1616\" \/>\n\t<meta property=\"og:image:height\" content=\"600\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Unit 42\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"\uc704\ud611 \ube0c\ub9ac\ud551: Salesloft Drift \ud1b5\ud569 \uae30\ub2a5\uc744 \uc545\uc6a9\ud55c Salesforce \uc778\uc2a4\ud134\uc2a4 \uce68\ud574","description":"\ubcf8 \uc704\ud611 \ube0c\ub9ac\ud504\uc5d0\uc11c\ub294 Salesloft Drift \uc5f0\ub3d9 \uae30\ub2a5\uc744 \uc545\uc6a9\ud558\uc5ec, \ud0c8\ucde8\ub41c OAuth \uc790\uaca9 \uc99d\uba85\uc744 \ud1b5\ud574 \ub370\uc774\ud130\ub97c \uc720\ucd9c\ud558\ub294 \ucea0\ud398\uc778\uc5d0 \ub300\ud55c \uad00\ucc30 \ub0b4\uc6a9\uc744 \ub2e4\ub8f9\ub2c8\ub2e4.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/unit42.paloaltonetworks.com\/ko\/threat-brief-compromised-salesforce-instances\/","og_locale":"ko_KR","og_type":"article","og_title":"\uc704\ud611 \ube0c\ub9ac\ud551: Salesloft Drift \ud1b5\ud569 \uae30\ub2a5\uc744 \uc545\uc6a9\ud55c Salesforce \uc778\uc2a4\ud134\uc2a4 \uce68\ud574","og_description":"\ubcf8 \uc704\ud611 \ube0c\ub9ac\ud504\uc5d0\uc11c\ub294 Salesloft Drift \uc5f0\ub3d9 \uae30\ub2a5\uc744 \uc545\uc6a9\ud558\uc5ec, \ud0c8\ucde8\ub41c OAuth \uc790\uaca9 \uc99d\uba85\uc744 \ud1b5\ud574 \ub370\uc774\ud130\ub97c \uc720\ucd9c\ud558\ub294 \ucea0\ud398\uc778\uc5d0 \ub300\ud55c \uad00\ucc30 \ub0b4\uc6a9\uc744 \ub2e4\ub8f9\ub2c8\ub2e4.","og_url":"https:\/\/unit42.paloaltonetworks.com\/ko\/threat-brief-compromised-salesforce-instances\/","og_site_name":"Unit 42","article_published_time":"2025-09-02T14:19:03+00:00","article_modified_time":"2025-10-28T12:33:04+00:00","og_image":[{"width":1616,"height":600,"url":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2025\/08\/7_Category_1616x600.jpg","type":"image\/jpeg"}],"author":"Unit 42","twitter_card":"summary_large_image","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/unit42.paloaltonetworks.com\/ko\/threat-brief-compromised-salesforce-instances\/#article","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ko\/threat-brief-compromised-salesforce-instances\/"},"author":{"name":"Unit 42","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/a891f81d18648a1e0bab742238d31a63"},"headline":"\uc704\ud611 \ube0c\ub9ac\ud551: Salesloft Drift \ud1b5\ud569 \uae30\ub2a5\uc744 \uc545\uc6a9\ud55c Salesforce \uc778\uc2a4\ud134\uc2a4 \uce68\ud574","datePublished":"2025-09-02T14:19:03+00:00","dateModified":"2025-10-28T12:33:04+00:00","mainEntityOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ko\/threat-brief-compromised-salesforce-instances\/"},"wordCount":141,"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ko\/threat-brief-compromised-salesforce-instances\/#primaryimage"},"thumbnailUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2025\/08\/7_Category_1616x600.jpg","keywords":["credential-based attacks","data exfiltration","Salesforce","Salesloft"],"articleSection":["\uc8fc\uc694 \uc704\ud611","\ucde8\uc57d\uc810"],"inLanguage":"ko-KR"},{"@type":"WebPage","@id":"https:\/\/unit42.paloaltonetworks.com\/ko\/threat-brief-compromised-salesforce-instances\/","url":"https:\/\/unit42.paloaltonetworks.com\/ko\/threat-brief-compromised-salesforce-instances\/","name":"\uc704\ud611 \ube0c\ub9ac\ud551: Salesloft Drift \ud1b5\ud569 \uae30\ub2a5\uc744 \uc545\uc6a9\ud55c Salesforce \uc778\uc2a4\ud134\uc2a4 \uce68\ud574","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ko\/threat-brief-compromised-salesforce-instances\/#primaryimage"},"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ko\/threat-brief-compromised-salesforce-instances\/#primaryimage"},"thumbnailUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2025\/08\/7_Category_1616x600.jpg","datePublished":"2025-09-02T14:19:03+00:00","dateModified":"2025-10-28T12:33:04+00:00","author":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/a891f81d18648a1e0bab742238d31a63"},"description":"\ubcf8 \uc704\ud611 \ube0c\ub9ac\ud504\uc5d0\uc11c\ub294 Salesloft Drift \uc5f0\ub3d9 \uae30\ub2a5\uc744 \uc545\uc6a9\ud558\uc5ec, \ud0c8\ucde8\ub41c OAuth \uc790\uaca9 \uc99d\uba85\uc744 \ud1b5\ud574 \ub370\uc774\ud130\ub97c \uc720\ucd9c\ud558\ub294 \ucea0\ud398\uc778\uc5d0 \ub300\ud55c \uad00\ucc30 \ub0b4\uc6a9\uc744 \ub2e4\ub8f9\ub2c8\ub2e4.","breadcrumb":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ko\/threat-brief-compromised-salesforce-instances\/#breadcrumb"},"inLanguage":"ko-KR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/unit42.paloaltonetworks.com\/ko\/threat-brief-compromised-salesforce-instances\/"]}]},{"@type":"ImageObject","inLanguage":"ko-KR","@id":"https:\/\/unit42.paloaltonetworks.com\/ko\/threat-brief-compromised-salesforce-instances\/#primaryimage","url":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2025\/08\/7_Category_1616x600.jpg","contentUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2025\/08\/7_Category_1616x600.jpg","width":1616,"height":600,"caption":"Pictorial representation of Salesforce compromised by attackers. Colorful abstract digital artwork featuring a gradient of red to blue hues with a raised, spike-like texture pattern resembling a city skyline."},{"@type":"BreadcrumbList","@id":"https:\/\/unit42.paloaltonetworks.com\/ko\/threat-brief-compromised-salesforce-instances\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/unit42.paloaltonetworks.com\/"},{"@type":"ListItem","position":2,"name":"\uc704\ud611 \ube0c\ub9ac\ud551: Salesloft Drift \ud1b5\ud569 \uae30\ub2a5\uc744 \uc545\uc6a9\ud55c Salesforce \uc778\uc2a4\ud134\uc2a4 \uce68\ud574"}]},{"@type":"WebSite","@id":"https:\/\/unit42.paloaltonetworks.com\/#website","url":"https:\/\/unit42.paloaltonetworks.com\/","name":"Unit 42","description":"Palo Alto Networks","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/unit42.paloaltonetworks.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"ko-KR"},{"@type":"Person","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/a891f81d18648a1e0bab742238d31a63","name":"Unit 42","image":{"@type":"ImageObject","inLanguage":"ko-KR","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/image\/24dfba25c0e71d4de1836b78795bc2e5","url":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2025\/09\/Insights_headshot-placeholder-300x300.jpg","contentUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2025\/09\/Insights_headshot-placeholder-300x300.jpg","caption":"Unit 42"},"url":"https:\/\/unit42.paloaltonetworks.com\/ko\/author\/unit42\/"}]}},"_links":{"self":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ko\/wp-json\/wp\/v2\/posts\/163021","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ko\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ko\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ko\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ko\/wp-json\/wp\/v2\/comments?post=163021"}],"version-history":[{"count":3,"href":"https:\/\/unit42.paloaltonetworks.com\/ko\/wp-json\/wp\/v2\/posts\/163021\/revisions"}],"predecessor-version":[{"id":163061,"href":"https:\/\/unit42.paloaltonetworks.com\/ko\/wp-json\/wp\/v2\/posts\/163021\/revisions\/163061"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ko\/wp-json\/wp\/v2\/media\/155480"}],"wp:attachment":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ko\/wp-json\/wp\/v2\/media?parent=163021"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ko\/wp-json\/wp\/v2\/categories?post=163021"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ko\/wp-json\/wp\/v2\/tags?post=163021"},{"taxonomy":"product_categories","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ko\/wp-json\/wp\/v2\/product_categories?post=163021"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ko\/wp-json\/wp\/v2\/coauthors?post=163021"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}