logo

Identifying an Existing APT Intrusion

ID: d880d215-f47a-5588-8409-3c02344fb76e

STIX ID: report--d880d215-f47a-5588-8409-3c02344fb76e

Feed Name: WatchGuard Secplicity Blog

Threat Score
85/100

Date Published: 2020-10-02

Date Updated: 2026-05-01

Author: The Editor

...
...

WatchGuard Threat Lab discovered and investigated an APT intrusion on a customer network in which attackers acquired valid local and domain accounts, attempted VBS/PowerShell-based payload delivery, executed PowerSploit and Cobalt Strike components for lateral movement and command-and-control, used PsExec and Mimikatz, and exfiltrated data to Dropbox via RClone; the report provides TTP mapping, IOCs (including an MD5), and recommendations such as MFA and robust EDR.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.