APT Group Trends in October 2024
ID: 83fa4d8e-9223-546d-91fe-97f1f9aba6f4
STIX ID: report--83fa4d8e-9223-546d-91fe-97f1f9aba6f4
Feed Name: ASEC
This report summarizes multiple October 2024 APT activities: Andariel executed financially motivated intrusions using Preft and newly observed Nukebot backdoors, keyloggers, credential theft, and leveraged Play ransomware infrastructure; APT28 deployed multi-stage LNK/DLL-hijack and PowerShell-based campaigns (Headlace, Masepie) and exploited Roundcube to harvest and forward emails; APT29 ran broad spear-phishing using signed RDP configuration files to gain persistent access. The incidents involve credential harvesting, C2 frameworks (Sliver, Metasploit), exploitation of CVE-2023-43770, and cross-border targeting of government, defense, private, and academic sectors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
