ITG14 is an advanced persistent threat (APT) that has been active since at least 2015 and targets organizations in various industries, including government agencies, financial institutions, and defense contractors. The group uses a variety of tactics to gain access to their target networks, such as spear-phishing emails or exploiting vulnerabilities in software. Once inside the network, ITG14 can steal sensitive information, install backdoors for future access, and conduct other malicious activities.
Techniques, tactics and practices:
ITG14 uses a variety of techniques to gain unauthorized access to their target networks. Some common methods include spear-phishing emails that contain malicious attachments or links, exploiting vulnerabilities in software such as Adobe Flash Player and Microsoft Office, using social engineering tactics like impersonation, and conducting reconnaissance activities on the network before launching an attack. They also use various tools to maintain access to their targets over time, including backdoor programs that allow them to return at a later date without being detected.
