logo

Big airline heist

ID: 9ad60a6f-1ff5-5d8f-97f7-59858cce91f0

STIX ID: report--9ad60a6f-1ff5-5d8f-97f7-59858cce91f0

Feed Name: Group-IB Blog

Threat Score
88/100

Date Published: 2021-06-10

Date Updated: 2026-04-27

...
...

Group-IB details the ColunmTK campaign against Air India, attributing the intrusion with moderate confidence to APT41; attackers used Cobalt Strike, credential theft (Mimikatz/hashdump), BadPotato privilege escalation, DNS tunneling (ns1/2.colunm.tk) and exfiltrated ~233 MB from multiple hosts, providing IOCs (IPs, domains, file hashes) and MITRE ATT&CK mappings to help detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.