APT · Russia
Sophisticated APT known for SolarWinds supply chain intrusion and cloud identity targeting across Western governments.
Псевдонимы: Cozy Bear, The Dukes, NOBELIUM
Мотивация: Long-term espionage and supply chain compromise
Разведка
Field telemetry from Seoul correlates with Microsoft Patches Actively Exploited Edge Zero-Day.
Первичный доступ
Field telemetry from London correlates with APT29 Targets Cloud Identity Providers in NATO States.
Ликвидация инцидента
Field telemetry from Stockholm correlates with Play Ransomware Exploits Fortinet Zero-Day in Government Sector.
Первичный доступ
Field telemetry from Seoul correlates with Microsoft Patches Actively Exploited Edge Zero-Day.
Повышение привилегий
Field telemetry from London correlates with APT29 Targets Cloud Identity Providers in NATO States.
Разведка
Field telemetry from Stockholm correlates with Play Ransomware Exploits Fortinet Zero-Day in Government Sector.
Боковое перемещение
Field telemetry from London correlates with APT29 Targets Cloud Identity Providers in NATO States.
Первичный доступ
Field telemetry from Stockholm correlates with Play Ransomware Exploits Fortinet Zero-Day in Government Sector.
Повышение привилегий
Field telemetry from Seoul correlates with Microsoft Patches Actively Exploited Edge Zero-Day.