APT10__2020__APT10_Report.pdf
ID: ce20ad50-978a-46be-8dff-751178d96192
STIX ID: report--ce20ad50-978a-46be-8dff-751178d96192
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2026-02-13
Last Modified Date: 2026-02-13
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
# Executive summary
This ADEO DFIR report analyzes APT10 activity targeting Turkish organizations from 2016–2019, describing initial access via exploited public-facing web applications and webshells, use of backdoors (PlugX, QuasarRAT), credential theft (Mimikatz, DCSync, Chrome-dumping tools), lateral movement (WMIC, PsExec, Impacket), C2 mechanisms (SMB beacons, HTTP beacons, hTran bridging, Dropbox exfiltration) and provides extensive IOCs (IPs, domains, file paths, hashes) and mapped MITRE ATT&CK TTPs.
