logo

APT27__2020__Investigation_with_a_twist_an_accidental_APT_attack_and_averted_data_destruction.pdf

ID: fb50d836-f2bc-4ef4-8906-1d0c8f1b0f6c

STIX ID: report--fb50d836-f2bc-4ef4-8906-1d0c8f1b0f6c

Threat Score

85/100

Uploaded: 2026-08-07

Published Date: 2020-11-30

Last Modified Date: 2020-11-30

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive summary:** Positive Technologies investigated a multi-year compromise of a media company's infrastructure that began with a foreign-office web-server compromise in early 2018 and persisted until an April 2020 mass deployment of Polar ransomware; attackers used web shells, ChinaChopper/TwoFace, SysUpdate and HyperBro backdoors, credential theft (Mimikatz/memory dumps), lateral movement (NBTScan, PsExec, EternalBlue), and cryptocurrency miners, but a flaw in the ransomware key generation plus SCCM uptime records enabled recovery of encrypted files and containment.