APT98 is a sophisticated advanced persistent threat (APT) actor with a focus on targeting government entities and critical infrastructure organizations across multiple sectors, including energy, transportation, and finance. This article explores their tactics, targets, and mitigation strategies.
Tactics and Techniques:
- Watering hole attacks: Infecting legitimate websites frequently visited by targeted organization employees with malicious code or redirecting them to malicious sites, APT98 gains initial access through trusted sources.
- Spear-phishing campaigns: Sending highly targeted phishing emails that appear to come from trusted sources to trick users into revealing credentials or downloading malicious attachments, APT98 achieves initial foothold within the target network.
- Living off the land (LoLBAS): Leveraging legitimate system tools and processes for malicious purposes, APT98 evades detection while maintaining persistence within targeted environments.
- Credential harvesting: Stealing user credentials through various means such as phishing or exploiting weak authentication practices, APT98 moves laterally across networks and gains access to sensitive data repositories.
- Data exfiltration: Extracting valuable information from targeted organizations, APT98 exposes confidential data, trade secrets, and other intelligence to advance their objectives or sell on the dark web.
- Multi-stage attacks: Employing multi-step infection chains involving multiple exploits or payloads, APT98 bypasses security measures at different stages of the attack process while remaining undetected.
- Exploiting zero-day vulnerabilities: Taking advantage of previously unknown software vulnerabilities, APT98 gains initial access or bypasses security controls undetected.
- Supply chain attacks: Infiltrating third-party software suppliers and integrating backdoors or other malware into legitimate products, APT98 compromises multiple organizations simultaneously through their supply chains.
Target Sector: APT98 primarily targets government entities and critical infrastructure organizations across sectors such as energy, transportation, finance, and others due to the potential impact on national security and economic stability. The stolen data can be used for espionage purposes or disrupting critical services within these sectors.
APT98 is a sophisticated and highly skilled hacking group that has been active since at least 2016. They are believed to be based in China but have targeted organizations around the world with their attacks. The group\'s primary focus appears to be on stealing sensitive information, including intellectual property, trade secrets, and personal data of individuals.
APT98 has been known to use a variety of tactics to gain access to its targets, such as spear-phishing emails or exploiting vulnerabilities in software systems. Once inside the network, they are able to move laterally across the system undetected for extended periods of time, allowing them to gather sensitive information and exfiltrate it back to their own servers without being detected.
APT98 has been linked to several high-profile attacks over the years,
Techniques, tactics and practices:
Sure! Here\'s a brief summary of some common TTPs used by APT98:
1. Spear-phishing emails - This is one of their most commonly used techniques, where they send targeted and highly personalized email messages to employees within the organization they are targeting. The goal is to trick them into opening a malicious attachment or clicking on a link that leads to a compromised website.
2. Exploiting vulnerabilities - APT98 has been known to exploit security weaknesses in software systems, such as outdated versions of Adobe Flash Player and Microsoft Office. They also use other methods like SQL injection attacks to gain access to sensitive data.
3. Lateral movement within the network - Once inside a targeted organization\'s network, APT98 is able to move laterally across the system undetected for extended periods of time. This allows them to gather sensitive information and exfiltrate
