logo

Mapping MITRE ATT&CK to the Equifax Indictment

ID: 09cec05a-a7ed-5b27-acd3-1acf504af12c

STIX ID: report--09cec05a-a7ed-5b27-acd3-1acf504af12c

Feed Name: ReliaQuest Blog

Threat Score
95/100

Date Published: 2020-02-24

Date Updated: 2026-04-29

...
...

This report revisits the 2017 Equifax breach and maps the intrusion to MITRE ATT&CK: alleged PLA operators exploited Apache Struts (CVE-2017-5638) to upload web shells, performed extensive SQL reconnaissance (thousands of queries) to find PII (names, addresses, SSNs, DOBs), compressed and exfiltrated data over HTTP, and removed logs and artifacts; the analysis enumerates the TTPs used and provides mitigation and detection recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.