Big airline heist
ID: 9ad60a6f-1ff5-5d8f-97f7-59858cce91f0
STIX ID: report--9ad60a6f-1ff5-5d8f-97f7-59858cce91f0
Feed Name: Group-IB Blog
Threat Score
Group-IB details the ColunmTK campaign against Air India, attributing the intrusion with moderate confidence to APT41; attackers used Cobalt Strike, credential theft (Mimikatz/hashdump), BadPotato privilege escalation, DNS tunneling (ns1/2.colunm.tk) and exfiltrated ~233 MB from multiple hosts, providing IOCs (IPs, domains, file hashes) and MITRE ATT&CK mappings to help detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
