APT29 Adversary Simulation
by 34585 - Monday April 22, 2024 at 04:02 PM
#1
APT29 Adversary Simulation
(untested)

This is a simulation of attack by the Cozy Bear group (APT-29) targeting diplomatic missions. The campaign began with an innocuous and legitimate event. In mid-April 2023, a diplomat within the Polish Ministry of Foreign Affairs emailed his legitimate flyer to various embassies advertising the sale of a used BMW 5-series sedan located in Kyiv. The file was titled BMW 5 for sale in Kyiv - 2023.docx. I relied on palo alto to figure out the details to make this simulation: https://unit42.paloaltonetworks.com/cloa...-phishing/

1.DOCX file: created DOCX file includes a Hyperlink that leads to downloading further HTML (HTML smuggling file).
2.HTML Smuggling: The attackcers use the of HTML smuggling to obscure the ISO file.
3.LNK files: When the LNK files (shortcut) are executed they run a legitimate EXE and open a PNG file. However, behind the scenes, encrypted shellcode is read into memory and decrypted.
4.ISO file: The ISO file contains a number of LNK files that are masquerading as images. These LNK files are used to execute the malicious payload.
5.DLL hijacking: The EXE file loads a malicious DLL via DLL hijacking, which allows the attacker to execute arbitrary code in the context of the infected process.
6.Shellcode injection: The decrypted shellcode is then injected into a running Windows process, giving the attacker the ability to execute code with the privileges of the infected process.
7.Payload execution: The shellcode decrypts and loads the final payload inside the current process.
8.Dropbox C2: This payload beacons to Dropbox and Primary/Secondary C2s based on the Microsoft Graph API.

https://github.com/S3N4T0R-0X0/APT29-Adv...Simulation
Reply
#2
really great man
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  OSINT repositories by country browdbrowniebread 0 129 10 hours ago
Last Post: browdbrowniebread
  A collection of deepweb sites [2025] dg7ka 107 2,881 Yesterday, 03:27 PM
Last Post: Jeracix
  FREE 3 UNCENSORED HACKING LLM QaboosbinSaidAlSaid 68 1,635 Yesterday, 02:22 AM
Last Post: Microban
  Telegram Opsec Guide Synaptic 47 1,823 Apr 29, 2026, 07:59 PM
Last Post: thebinarymonk
  Looking for experienced hacker 99992 0 170 Apr 28, 2026, 10:59 PM
Last Post: 99992

Forum Jump:


 Users browsing this forum: 1 Guest(s)