CyberzSOC

Publication detail
← Back to advisories & guidance

APT40 Advisory: PRC MSS Tradecraft in Action ↗ source

July 8, 2024 NSA Advisory
Co-sealed by: ASD/ACSC, CCCS, FBI, NCSC-NZ, NCSC-UK, NIS, NPA, NSA

Summary

Background The following Advisory provides a sample of significant case studies of this adversary’s techniques in action This advisory, authored by the Australian Signals against two victim networks. The case studies are Directorate’s Australian Cyber Security Centre consequential for cybersecurity practitioners to identify, (ASD’s ACSC), the United States Cybersecurity and prevent and remediate APT40 intrusions against their Infrastructure Security Agency (CISA), the United own networks. The selected case studies are those States National Security Agency (NSA), the United where appropriate remediation has been undertaken States Federal Bureau of Investigation (FBI), the United reducing the risk of re-exploitation by this threat actor, Kingdom National Cyber Security Centre (NCSC-UK), or others.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2021-44228 10.0 Critical Apache Log4j2 Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote cod…
CVE-2021-26084 9.8 Critical Atlassian Confluence Server and Data Center Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthentica…
CVE-2021-34473 9.1 Critical Microsoft Exchange Server Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution.
CVE-2021-34523 9.0 Critical Microsoft Exchange Server Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-31207 6.6 Medium Microsoft Exchange Server Microsoft Exchange Server contains an unspecified vulnerability that allows for security feature bypass.

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.