APT31__2021__APT31_new_dropper._Target_destinations_Mongolia_Russia_the_U.S._and_elsewhere.pdf
ID: 81f98a8e-221a-47d4-8318-0781d07a0111
STIX ID: report--81f98a8e-221a-47d4-8318-0781d07a0111
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2021-08-04
Last Modified Date: 2021-08-04
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Positive Technologies' PT ESC analyzed dropper and RAT samples attributed to APT31 (Judgment Panda), detailing how droppers create C:\ProgramData\Apache (and variants), sideload a malicious MSVCR100.dll, download and decrypt payloads from unencrypted C2 servers, achieve persistence via registry Run keys, and implement a command set for reconnaissance, file operations, process creation and exfiltration; the report includes IOCs (file hashes, domains, IPs), network diagrams, MITRE technique mappings, and notes stolen code-signing and multi-country targeting (Mongolia, Russia, US, etc.).
