logo

APT41__2021__Big_airline_heist_APT41_likely_behind_massive_supply_chain_attack.pdf

ID: 4584a7a5-a3b8-4696-a4e9-b43bf3344f7d

STIX ID: report--4584a7a5-a3b8-4696-a4e9-b43bf3344f7d

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2021-06-12

Last Modified Date: 2021-06-12

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Group-IB details a sophisticated supply-chain campaign (ColumnTK) linked with moderate confidence to APT41 that used a compromised SITA server to infiltrate Air India and other airline customers, exfiltrated passenger data (millions of records reported, tens to hundreds of megabytes of stolen files), and employed Cobalt Strike, DNS tunneling, credential theft (Mimikatz, hashdump), privilege escalation (BadPotato), and service DLL persistence; the post includes timelines, beacon configurations, file hashes, network IOCs, and mitigation guidance.