APT29 Adversary Simulation
by 34585 - Monday April 22, 2024 at 04:02 PM
#1
APT29 Adversary Simulation
(untested)

This is a simulation of attack by the Cozy Bear group (APT-29) targeting diplomatic missions. The campaign began with an innocuous and legitimate event. In mid-April 2023, a diplomat within the Polish Ministry of Foreign Affairs emailed his legitimate flyer to various embassies advertising the sale of a used BMW 5-series sedan located in Kyiv. The file was titled BMW 5 for sale in Kyiv - 2023.docx. I relied on palo alto to figure out the details to make this simulation: https://unit42.paloaltonetworks.com/cloa...-phishing/

1.DOCX file: created DOCX file includes a Hyperlink that leads to downloading further HTML (HTML smuggling file).
2.HTML Smuggling: The attackcers use the of HTML smuggling to obscure the ISO file.
3.LNK files: When the LNK files (shortcut) are executed they run a legitimate EXE and open a PNG file. However, behind the scenes, encrypted shellcode is read into memory and decrypted.
4.ISO file: The ISO file contains a number of LNK files that are masquerading as images. These LNK files are used to execute the malicious payload.
5.DLL hijacking: The EXE file loads a malicious DLL via DLL hijacking, which allows the attacker to execute arbitrary code in the context of the infected process.
6.Shellcode injection: The decrypted shellcode is then injected into a running Windows process, giving the attacker the ability to execute code with the privileges of the infected process.
7.Payload execution: The shellcode decrypts and loads the final payload inside the current process.
8.Dropbox C2: This payload beacons to Dropbox and Primary/Secondary C2s based on the Microsoft Graph API.

https://github.com/S3N4T0R-0X0/APT29-Adv...Simulation
Reply
#2
really great man
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  A collection of deepweb sites [2025] dg7ka 112 3,387 Yesterday, 07:57 PM
Last Post: IsItReal
  Hacking forums and their links 2026 onionlinks 1 254 Yesterday, 05:01 PM
Last Post: phas3lock
  What is your most efficent way to gain initial access? likju 1 183 Yesterday, 04:47 PM
Last Post: phas3lock
  FREE 3 UNCENSORED HACKING LLM QaboosbinSaidAlSaid 69 1,990 Yesterday, 04:37 PM
Last Post: phas3lock
  Largest Discord User History Archive - 10m+ Users Mega 319 40,820 May 03, 2026, 09:41 PM
Last Post: AlexDoe

Forum Jump:


 Users browsing this forum: 1 Guest(s)