National Cyber Warfare Foundation (NCWF)

InkySquid


0 user ratings
2024-06-18 15:21:21
blscott

 - archive -- 
InkySquid is an alternate name for the group known as APT37

InkySquid is an advanced persistent threat (APT) that has been active since at least 2016 and targets government, military, defense contractors, and other organizations involved in national security. It uses a variety of techniques to evade detection by antivirus software and firewalls, including the use of stealth malware and custom-built tools for specific tasks such as fileless execution or memory injection. InkySquid has been linked to several high-profile attacks on government agencies in various countries, including the United States, China, Russia, and Iran.

Techniques, tactics and practices: 

InkySquid uses a variety of techniques to evade detection by antivirus software and firewalls. These include using stealth malware, which is designed to hide from security tools and avoid being detected or removed; custom-built tools for specific tasks such as fileless execution or memory injection; exploiting vulnerabilities in operating systems and applications; conducting extensive research on target organizations before launching attacks; and employing sophisticated techniques such as spear phishing, watering hole attacks, and zero-day exploits. InkySquid also uses a variety of tools to maintain persistence within compromised networks, including rootkits, backdoors, and keyloggers.



Comments
new comment
Nobody has commented yet. Will you be the first?


Primary Names
APT37
 




This link is from a restricted area of the forums.
Forum



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.