logo

APT41__2022__Mandiant_Summary-APT41-Targeting-US-State-Governments_03-08-2022.pdf

ID: 35ec5c68-bb52-4945-b935-6622860fbc21

STIX ID: report--35ec5c68-bb52-4945-b935-6622860fbc21

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2022-03-10

Last Modified Date: 2022-03-10

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Mandiant details a persistent APT41 campaign that exploited Internet-facing web applications (notably a USAHerds zero-day and Log4j) to compromise at least six U.S. state government networks; the report describes deserialization-based initial access, deployment of malware families (KEYPLUG, DUSTPAN, DEADEYE, LOWKEY), credential harvesting, Cloudflare-proxied C2 and DNS-based exfiltration, and provides IoCs and detection rules.