logo

Data Dump From APT Actor Yields Clues to Attacker Capabilities

ID: 22d703d5-ffae-526f-9ed7-85e5fdad2184

STIX ID: report--22d703d5-ffae-526f-9ed7-85e5fdad2184

Feed Name: Dark Reading

Threat Score
82/100

Date Published: 2025-08-08

Date Updated: 2026-04-21

Author: Robert Lemos, Contributing Writer

...
...

Phrack-published analysis and accompanying data dumps detail a large breach in which two hackers claim to have compromised a virtual workstation and VPS used by a nation-state-aligned operator (dubbed “KIM”), exposing nearly 20,000 browser history entries, backdoor manuals, credentials, C2 infrastructure, and tool artifacts (including a TomCat backdoor, a private Cobalt Strike beacon, and an Ivanti backdoor). Analysts reviewed the files and found indicators suggesting the operator may be Chinese or mimicking the North Korean Kimsuky group; the disclosure reveals TTPs and targeting that will significantly affect CTI research and detection efforts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.