China-Backed APT41 Cyberattack Surfaces in Africa
ID: 40c030ca-e3f4-5663-8a4f-18254200c847
STIX ID: report--40c030ca-e3f4-5663-8a4f-18254200c847
Feed Name: Dark Reading
Kaspersky researchers documented an APT41 campaign against a government IT services provider in Africa in which attackers used both custom and public tools—Impacket (WmiExec/Atexec), Cobalt Strike, Mimikatz, Pillager, RawCopy, and Neo-reGeorg—to harvest credentials and exfiltrate data; the adversary embedded victim-specific service names/IPs and even used a compromised internal SharePoint server as a C2 to improve persistence and evade detection, illustrating high sophistication and adaptability amid rising regional cybercrime.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
