Just Another Blue Teamer · @LeeArchinal
128 followers · 193 posts · Server ioc.exchange

Good day everyone! The Microsoft Threat Intelligence team has discovered activity from a group known as . They are a nation-state group from China that targeted organizations in Taiwan. While the group leverages tools that are commonly used, like , , and , they also rely on abusing , or Living-off-the-land binaries and scripts (tools that exist and come with the native operating system). Some of their TTPs include using registry key modification for persistence, using , , or to download tools, and accessing process memory and Security Account Manager registry hive for credential access. This is a great article that not only provides high-level details but it provides a starting point for any organization to start threat hunting by using the technical details provided! Enjoy your weekend and !

#powershell #certutil #bitsadmin #Lsass #happyhunting #cybersecurity #itsecurity #infosec #blueteam #threatintel #threathunting #ThreatDetection #readoftheday #flaxtyphoon #ChinaChopper #metasploit #mimikatz #lolbins

Last updated 1 year ago

Mr.Trunk · @mrtrunk
10 followers · 17803 posts · Server dromedary.seedoubleyou.me
Mr.Trunk · @mrtrunk
10 followers · 17701 posts · Server dromedary.seedoubleyou.me
Mr.Trunk · @mrtrunk
9 followers · 16971 posts · Server dromedary.seedoubleyou.me
Mr.Trunk · @mrtrunk
9 followers · 16870 posts · Server dromedary.seedoubleyou.me
Anonymous :anarchism: 🏴 · @YourAnonRiots
6052 followers · 37713 posts · Server mstdn.social

nation-state "" hacker group suspected in cyber espionage across Taiwanese organizations. They rely on living-off-the-land techniques for persistence, lateral movement, and gaining credentials.

thehackernews.com/2023/08/chin

#InfoSec #CyberSecurity #flaxtyphoon #chinese

Last updated 1 year ago

Mr.Trunk · @mrtrunk
9 followers · 16774 posts · Server dromedary.seedoubleyou.me