National Cyber Warfare Foundation (NCWF)

Group123


0 user ratings
2024-06-18 15:21:21
blscott

 - archive -- 
Group123 is an alternate name for the group known as APT37

Group123 is an advanced persistent threat (APT) that has been active since at least 2014 and targets government agencies, military organizations, defense contractors, and other high-value entities in various countries around the world. The group uses a variety of tactics to gain access to their target networks, including spear phishing emails, watering hole attacks, and exploiting vulnerabilities in software and systems. Once inside, Group123 is known for its persistence and ability to remain undetected on compromised machines for extended periods of time. The group has been linked to several high-profile cyber espionage campaigns, including the 2017 WannaCry ransomware attack that affected over 200,000 computers worldwide.

Techniques, tactics and practices:

Group123 is an advanced persistent threat that uses a variety of techniques to gain access to their target networks. Some of these include spear phishing emails, watering hole attacks, and exploiting vulnerabilities in software and systems. Once inside the network, Group123 employs persistence tactics such as installing backdoors, using rootkits to hide malware from detection, and creating multiple layers of encryption for their data exfiltration activities. They also use techniques like stealthy command-and-control (C&C) infrastructure that is hard to detect by security researchers or analysts. Additionally, Group123 has been known to conduct targeted attacks against specific individuals within organizations and exploit social engineering tactics such as pretexting to gain access to sensitive information.



Comments
new comment
Nobody has commented yet. Will you be the first?


Primary Names
APT37
 




This link is from a restricted area of the forums.
Forum



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.