APT32__2020__Threat_actor_leverages_coin_miner_techniques_to_stay_under_the_radar_here_s_how_to_spot_them_-_Microsoft_Security.pdf
ID: c3811e67-1bbf-4200-b5a4-9499230e23f9
STIX ID: report--c3811e67-1bbf-4200-b5a4-9499230e23f9
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2020-12-01
Last Modified Date: 2020-12-01
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Microsoft Threat Intelligence details BISMUTH (a nation-state APT) campaigns that used targeted spear-phishing with malicious Word documents to sideload DLLs and create scheduled tasks for persistence; attackers then conducted extensive discovery and lateral movement, deployed Monero coin miners to distract defenders, installed Cobalt Strike beacons, and used Mimikatz for credential theft and exfiltration. The report includes observed filenames and artifacts, a mapped attack lifecycle with MITRE ATT&CK techniques, and practical mitigation and detection guidance for defenders.
