Kasperskyβs report reveals a sophisticated cyberespionage campaign by APT41 targeting African government IT systems, showcasing their advanced TTPs. The attack involved credential harvesting, lateral movement, and the use of custom and open-source tools for stealthy data exfiltration. #APT41 #Cyberespionage
Keypoints
- APT41 targeted government infrastructure in Africa using a variety of TTPs.
- The intrusion began with unmonitored hosts via Impacket modules like WmiExec and Atexec.
- Attackers exploited credential harvesting and compromised domain admin accounts.
- They deployed Cobalt Strike, C# Trojans, and HTA files for command and control communication.
- Kaspersky emphasizes the need for comprehensive monitoring, full endpoint protection, and privileged account audits.
Read More: https://securityonline.info/apt41-unleashes-full-arsenal-in-rare-african-cyberespionage-campaign/