APT41__2022__Mandiant_Summary-APT41-Targeting-US-State-Governments_03-08-2022.pdf
ID: 35ec5c68-bb52-4945-b935-6622860fbc21
STIX ID: report--35ec5c68-bb52-4945-b935-6622860fbc21
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2022-03-10
Last Modified Date: 2022-03-10
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Mandiant details a persistent APT41 campaign that exploited Internet-facing web applications (notably a USAHerds zero-day and Log4j) to compromise at least six U.S. state government networks; the report describes deserialization-based initial access, deployment of malware families (KEYPLUG, DUSTPAN, DEADEYE, LOWKEY), credential harvesting, Cloudflare-proxied C2 and DNS-based exfiltration, and provides IoCs and detection rules.
