MITRE ATT&CK @attack.mitre.org · Aug 28

So, APT41 is in a network, they’ve accessed sensitive data, and now they want to exfiltrate. How? Why not just use what the rest of us already use?: APT41 copies data and then smuggles it out via Microsoft OneDrive.

0 likes 1 replies

?

Replies

MITRE ATT&CK · Aug 28

This maps right to T1567.002 attack.mitre.org/techniques/T... Taking this route is advantageous for numerous reasons including that the ready-built C2 often looks familiar compared to a threat actor’s primary command and control infrastructure.