Lucky Mouse: Incident Response to Detection Engineering
ID: 3244a1f6-dbb9-554e-bc05-55e0743ee546
STIX ID: report--3244a1f6-dbb9-554e-bc05-55e0743ee546
Feed Name: Sekoia.com
Threat Score
This blogpost reviews an Intrinsec incident attributed to APT27 (Lucky Mouse) and provides SIGMA/ECS-based detection logic and telemetry notes for key attacker techniques—command execution via wmiexec/wmic, PowerShell disabling of Windows Defender, Exchange mailbox export, credential dumping via ProcDump and ntdsutil, RAR-based archiving/encryption, and Chisel SOCKS tunneling—along with practical false-positive mitigations and rule-tuning guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
