APT trends report Q1 2024
ID: cc3403ff-ea7b-5404-96a5-0a78f58bffc0
STIX ID: report--cc3403ff-ea7b-5404-96a5-0a78f58bffc0
Feed Name: Securelist by Kaspersky
Kaspersky GReAT Q1 2024 quarterly summary details multiple APT groups, malware families and hacktivist operations observed globally: server-side exploits and webshells by Gelsemium; renewed Careto activity with complex implants; DuneQuixote droppers and CR4T backdoors in the Middle East; Kimsuky supply-chain use of the Golang Durian backdoor in South Korea; various RATs and loaders (Spyder, Remcos, ThreatNeedle) used by groups like DroppingElephant, Lazarus and SideWinder; and an uptick in hacktivist operations (SiegedSec) tied to geopolitical events. The report highlights regional targeting, diverse sectors (government, ISP, gaming, maritime logistics, crypto), evasive TTPs, and recommendations for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
