logo

APT32__2020__Threat_actor_leverages_coin_miner_techniques_to_stay_under_the_radar_here_s_how_to_spot_them_-_Microsoft_Security.pdf

ID: c3811e67-1bbf-4200-b5a4-9499230e23f9

STIX ID: report--c3811e67-1bbf-4200-b5a4-9499230e23f9

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2020-12-01

Last Modified Date: 2020-12-01

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Microsoft Threat Intelligence details BISMUTH (a nation-state APT) campaigns that used targeted spear-phishing with malicious Word documents to sideload DLLs and create scheduled tasks for persistence; attackers then conducted extensive discovery and lateral movement, deployed Monero coin miners to distract defenders, installed Cobalt Strike beacons, and used Mimikatz for credential theft and exfiltration. The report includes observed filenames and artifacts, a mapped attack lifecycle with MITRE ATT&CK techniques, and practical mitigation and detection guidance for defenders.