logo

The Scent of Stealth: Cyber-espionage Intrusion Analysis

ID: 0223c769-1f46-55f0-aa63-a220531e3b41

STIX ID: report--0223c769-1f46-55f0-aa63-a220531e3b41

Feed Name: ReliaQuest Blog

Threat Score
85/100

Date Published: 2023-06-09

Date Updated: 2026-04-29

...
...

ReliaQuest investigated an April–May 2023 intrusion at a manufacturing client (KILO-32325) attributed to PRC-aligned state-sponsored actors who likely gained initial access via a compromised SOHO Fortinet router and service accounts, harvested Active Directory credentials (NTDS.dit snapshot exposing >1,200 accounts and LAPS-managed local admin passwords), conducted living-off-the-land discovery and lateral movement, staged targeted R&D and operational data into passworded WinRAR archives on file servers for exfiltration, and avoided malware or C2 implants; the report documents IOCs, TTPs, impact, and recommended mitigations including edge device patching, MFA for all accounts, improved EDR/logging, and account hygiene.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.