Introduction
The groupβs existence came to light during Contextβs investigation of a number of attacks against multinational enterprises that compromise smaller engineering services and consultancies working in their supply chains.
Activities and Tactics
Country of Origin: π¨π³ China
Notable Campaigns
- Airbus Attack
Tactics, Techniques, and Procedures (TTPs)
Information pending cataloguing.
Notable Indicators of Compromise (IOCs)
No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.
Malware and Tools
- Small-Net
- PlugX:
- Mimikatz:
- WmiExec:
Attribution and Evidence
Country of Origin: China Additional attribution information pending cataloguing.
References
References pending cataloguing.