APT41__2021__Big_airline_heist_APT41_likely_behind_massive_supply_chain_attack.pdf
ID: 4584a7a5-a3b8-4696-a4e9-b43bf3344f7d
STIX ID: report--4584a7a5-a3b8-4696-a4e9-b43bf3344f7d
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2021-06-12
Last Modified Date: 2021-06-12
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Group-IB details a sophisticated supply-chain campaign (ColumnTK) linked with moderate confidence to APT41 that used a compromised SITA server to infiltrate Air India and other airline customers, exfiltrated passenger data (millions of records reported, tens to hundreds of megabytes of stolen files), and employed Cobalt Strike, DNS tunneling, credential theft (Mimikatz, hashdump), privilege escalation (BadPotato), and service DLL persistence; the post includes timelines, beacon configurations, file hashes, network IOCs, and mitigation guidance.
