logo

Advisory Further TTPs associated with SVR cyber actors.pdf

ID: a85e296a-97da-477f-a622-91c53db99825

STIX ID: report--a85e296a-97da-477f-a622-91c53db99825

Threat Score

90/100

Uploaded: 2026-08-11

Published Date: 2021-05-06

Last Modified Date: 2021-05-06

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This NCSC-led advisory details Tactics, Techniques and Procedures (TTPs) associated with SVR (APT29), describing widespread exploitation of publicly disclosed CVEs (including Exchange vulnerabilities), supply-chain compromises (SolarWinds, Mimecast), use of offensive frameworks (Sliver, Cobalt Strike) and custom malware (GoldFinder, GoldMax, Sibot), and provides detection signatures (Snort, YARA) and mitigation guidance for defenders.