logo

APT10__2021__APT10_sophisticated_multi-layered_loader_Ecipekac_discovered_in_A41APT_campaign_Securelist.pdf

ID: 77e87c79-4794-4c57-b172-7a6263272e5b

STIX ID: report--77e87c79-4794-4c57-b172-7a6263272e5b

Threat Score

90/100

Uploaded: 2026-08-07

Published Date: 2021-04-01

Last Modified Date: 2021-04-01

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
A Kaspersky GReAT technical analysis of APT10’s A41APT campaign describing Ecipekac — a sophisticated, multi-layer, fileless x64 loader that embeds encrypted shellcode inside digitally signed DLLs to bypass detection and deliver payloads (P8RAT, SodaMaster, FYAnti/QuasarRAT and Cobalt Strike staggers). The report details the four-layer loading/decryption chain, bespoke cryptographic implementations, anti-VM and evasion techniques, use of Pulse Connect Secure vulnerabilities and stolen credentials for initial access, observed IOCs (hashes, IPs, domains), and maps observed TTPs to MITRE ATT&CK.