APT27__2020__Investigation_with_a_twist_an_accidental_APT_attack_and_averted_data_destruction.pdf
ID: fb50d836-f2bc-4ef4-8906-1d0c8f1b0f6c
STIX ID: report--fb50d836-f2bc-4ef4-8906-1d0c8f1b0f6c
Threat Score
85/100
Uploaded: 2026-08-07
Published Date: 2020-11-30
Last Modified Date: 2020-11-30
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive summary:** Positive Technologies investigated a multi-year compromise of a media company's infrastructure that began with a foreign-office web-server compromise in early 2018 and persisted until an April 2020 mass deployment of Polar ransomware; attackers used web shells, ChinaChopper/TwoFace, SysUpdate and HyperBro backdoors, credential theft (Mimikatz/memory dumps), lateral movement (NBTScan, PsExec, EternalBlue), and cryptocurrency miners, but a flaw in the ransomware key generation plus SCCM uptime records enabled recovery of encrypted files and containment.
