Crouching Yeti is an advanced persistent threat (APT) that has been active since at least 2014, targeting various industries and sectors such as finance, government, energy, and aerospace. It is known for its stealthy behavior, use of multiple techniques to evade detection, and ability to remain undetected in the victim\'s network for extended periods of time. The group has been linked to various attacks on organizations worldwide, including Russia, Ukraine, China, and the United States.
Techniques, tactics and practices:
Crouching Yeti is a highly sophisticated threat actor that employs various techniques to evade detection. Some of these include:
1. Stealthy behavior - The group uses stealth tactics such as avoiding suspicious activity, using legitimate tools and software, and staying within the boundaries of acceptable network usage to remain undetected for extended periods of time.
2. Use of multiple techniques - Crouching Yeti employs a variety of methods to gain access to their targets\' networks, including spear-phishing emails, watering hole attacks, exploiting vulnerabilities in software and systems, and using social engineering tactics such as impersonation or baiting.
3. Ability to remain undetected - The group is known for its ability to evade detection by hiding their activities within legitimate network traffic, avoiding suspicious activity, and staying within the boundaries of acceptable network usage.
