logo

APT10__2020__Japan-Linked_Organizations_Targeted_in_Long-Running_and_Sophisticated_Attack_Campaign_Symantec_Blogs.pdf

ID: e6fc7ed9-8c64-4a0b-9f43-6145c15c9a22

STIX ID: report--e6fc7ed9-8c64-4a0b-9f43-6145c15c9a22

Threat Score

88/100

Uploaded: 2026-08-07

Published Date: 2020-11-19

Last Modified Date: 2020-11-19

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
- Symantec reports a wide-ranging, long-running espionage campaign (mid‑Oct 2019 through Oct 2020) attributed to Cicada/APT10 targeting Japan-linked organizations and MSPs across many countries; attackers used DLL side‑loading, living‑off‑the‑land tools, a custom backdoor (Backdoor.Hartip), QuasarRAT, and a tool to exploit the ZeroLogon (CVE-2020-1472) vulnerability to compromise domain controllers and exfiltrate sensitive files. Indicators of compromise and mitigation advice are provided.