Advisory Further TTPs associated with SVR cyber actors.pdf
ID: a85e296a-97da-477f-a622-91c53db99825
STIX ID: report--a85e296a-97da-477f-a622-91c53db99825
Threat Score
90/100
Uploaded: 2026-08-11
Published Date: 2021-05-06
Last Modified Date: 2021-05-06
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This NCSC-led advisory details Tactics, Techniques and Procedures (TTPs) associated with SVR (APT29), describing widespread exploitation of publicly disclosed CVEs (including Exchange vulnerabilities), supply-chain compromises (SolarWinds, Mimecast), use of offensive frameworks (Sliver, Cobalt Strike) and custom malware (GoldFinder, GoldMax, Sibot), and provides detection signatures (Snort, YARA) and mitigation guidance for defenders.
