Shuckworm is an advanced persistent threat (APT) that has been active since at least 2017 and primarily targets government entities, defense contractors, research institutions, and other organizations with sensitive information. The group uses a variety of tactics to gain access to their target's networks, including spear-phishing emails, social engineering attacks, and exploiting vulnerabilities in software or systems. Once inside the network, Shuckworm is able to steal sensitive data such as classified documents, research information, and other confidential materials. The group has been linked to several high-profile breaches of government agencies and defense contractors, including the US Department of Defense (DoD) and Boeing.
Techniques, tactics and practices:
Shuckworm uses a variety of techniques to gain access to their target's networks, including spear-phishing emails that contain malicious attachments or links. They also use social engineering attacks such as impersonating legitimate organizations in order to trick employees into giving them sensitive information like login credentials. Additionally, they exploit vulnerabilities in software and systems by using known security holes or creating their own vulnerabilities through the use of zero-day exploits. Once inside a network, Shuckworm is able to steal sensitive data such as classified documents, research information, and other confidential materials.
