logo

The SOC files: Rumble in the jungle or APT41’s new target in Africa

ID: e2451e96-0f1d-5f86-b70d-ea4c90df5d34

STIX ID: report--e2451e96-0f1d-5f86-b70d-ea4c90df5d34

Feed Name: Securelist by Kaspersky

Threat Score
90/100

Date Published: 2025-07-21

Date Updated: 2026-04-29

Author: Denis Kulik, Daniil Pogorelov

...
...

Kaspersky MDR investigated a targeted APT41 campaign against government IT services in Africa in which attackers used compromised hosts and internal services (including a captive SharePoint server) as C2, leveraged Impacket modules (WmiExec/Atexec) for lateral movement, performed registry dumps and credential harvesting (Mimikatz, RawCopy), deployed Cobalt Strike via DLL sideloading and custom C# agents for command execution and exfiltration, and used stealers (Pillager, Checkout) to collect sensitive data; the report provides IOCs (file hashes, domains, IPs), detection rules (YARA, Sigma), attribution to APT41 with high confidence, and mitigations emphasizing full endpoint coverage and least-privilege account management.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.