logo

Lucky Mouse: Incident Response to Detection Engineering

ID: 3244a1f6-dbb9-554e-bc05-55e0743ee546

STIX ID: report--3244a1f6-dbb9-554e-bc05-55e0743ee546

Feed Name: Sekoia.com

Threat Score
85/100

Date Published: 2022-12-01

Date Updated: 2026-07-20

...
...

This blogpost reviews an Intrinsec incident attributed to APT27 (Lucky Mouse) and provides SIGMA/ECS-based detection logic and telemetry notes for key attacker techniques—command execution via wmiexec/wmic, PowerShell disabling of Windows Defender, Exchange mailbox export, credential dumping via ProcDump and ntdsutil, RAR-based archiving/encryption, and Chisel SOCKS tunneling—along with practical false-positive mitigations and rule-tuning guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.