APT41 Infiltrates Networks in Italy, Spain, Taiwan, Turkey, and the U.K.
ID: d15d0ca4-e2dc-5e01-8f10-3c4771beee3f
STIX ID: report--d15d0ca4-e2dc-5e01-8f10-3c4771beee3f
Feed Name: The Hacker News
Mandiant reports a sustained APT41 cyber-espionage campaign since 2023 targeting organizations across shipping, media, technology, and automotive sectors in multiple countries using web shells (ANTSWORD, BLUEBEAM), droppers (DUSTPAN/StealthVector and DUSTTRAP), Cobalt Strike, SQLULDR2 and PINEGROVE for data theft and exfiltration (including OneDrive and Oracle DB abuse), with components signed by presumably stolen certificates; separately, Sygnia attributes a sophisticated GhostEmperor campaign that installs the Demodex kernel rootkit using Cheat Engine to bypass driver signature enforcement, employing multi-stage implants and anti-analysis techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
