Operation Soft Cell — APT Profile
In 2018, the Cybereason Nocturnus team identified an advanced, persistent attack targeting global telecommunications providers carried out by a threat actor using tools and techniques commonly associated with Chinese-affiliated threat actors, such as APT10. This multi-wave attacks focused on obtaining data of specific, high-value targets and resulted in a complete takeover of the network.
Tools & malware
- elf.pingpull Backdoor
- elf.sword2033 Backdoor
- win.chinachopper Web Shell
- win.htran Tunneling Tool
- win.mim221 Credential Harvesting
- win.mimikatz Credential Harvesting
- win.poison_ivy Backdoor
- win.reshell Backdoor
- win.trochilus_rat Remote Access Trojan
Vendor research
Read the full analysis on IntelFusions