Skip to main content

Evidence Register: Real APT Campaigns and Documented Anomaly Patterns

Atlas home · Research path · Operational families · Anomaly models · Visual index

Consolidated 27 September 2026 from the revised publication. Source-reported incidents, proposed models, functional tests, and synthetic results remain separate evidence classes. Provenance and review scope.

These investigations illustrate opportunities and limitations. Source-reported means the named investigator reports the activity; inferred means a detection hypothesis developed here. None of the following accounts represents a replay of a victim's private telemetry.

SUNBURST / UNC2452 (2020)​

Source-reported: Mandiant documented a trojanized SolarWinds component, delayed activation and encoded information in DNS names. Its initial investigation also described TEARDROP reading a file with a likely fake JPEG header before loading a payload; the executable itself should not be described as a JPEG. Initial investigation, technical follow-up.

Inferred: investigate DNS-label structure, destination novelty and the originating process together. Dormancy complicates short lookbacks but does not itself supply an outbound-network observation. Neither the source nor this research establishes a universal entropy cutoff, an above-baseline entropy measurement at victims, or inevitable detection by a DNS analytic. Sysmon image-load telemetry is not a guarantee of visibility into manual or reflective loading.

SUNBURST: encoded DNS is evidence, not a verdict. Source-reported SUNBURST behavior, with a separate proposed detection hypothesis. The arrows summarize a mechanism, not a replay of one victim’s timeline. No measured entropy cutoff or validation of the author’s proposed detector is implied. No measured victim entropy range or universal DNS cutoff is established here.
Figure 24. SUNBURST: encoded DNS is evidence, not a verdict. Source-reported SUNBURST behavior, with a separate proposed detection hypothesis. The arrows summarize a mechanism, not a replay of one victim’s timeline. No measured entropy cutoff or validation of the author’s proposed detector is implied.SOURCE-REPORTED + AUTHOR INFERENCE · USER-SUPPLIEDSources: S01 · Mandiant: SUNBURST technical details · Supplied source key: S01–S14.
Text equivalent and full-size diagram

No measured victim entropy range or universal DNS cutoff is established here.

Reported activity: a trojanized SolarWinds component activated after a delay and communicated encoded information through DNS names. The solid panel describes public reporting, not newly collected telemetry.

Proposed hypothesis: investigate the combination of DNS-label structure, destination novelty and originating-process context. These features require locally defined baselines and collection coverage.

Technical boundary: missing image-load records do not rule out manual loading. An executable name, a long label or an entropy value alone does not identify SUNBURST.

Interpretation: combine evidence and test benign alternatives. The dashed hypothesis panel is an analytical proposal, not a measured detector result.

Open original full-size asset

HAFNIUM / Exchange ProxyLogon (2021)​

Source-reported: Microsoft described exploitation of Exchange vulnerabilities followed by webshell deployment. Its separate post-exploitation investigation described multiple actors and tools; observations from that broader set must not all be attributed to HAFNIUM. HAFNIUM investigation, post-exploitation analysis.

Inferred: correlate unusual web requests, ASPX writes, and shell execution descending from a web worker. Ordinary IIS logs do not contain arbitrary request bodies. Process fields differ between native 4688, Sysmon and EDR schemas; normalize them explicitly. Custom applications may legitimately invoke shells, so role and change context matter. Later native IIS-module campaigns are a separate evidence set; no claim about them is derived from the original HAFNIUM report here.

Exchange: distinguish HAFNIUM from broader exploitation. The initial Microsoft report attributes Exchange exploitation and webshells to HAFNIUM; the separately linked post-exploitation report covers multiple actors. Do not assign every later observation to HAFNIUM. The detection panel is a proposal, not a reproduced intrusion. Do not assign every post-exploitation observation to HAFNIUM. Standard IIS logs do not expose arbitrary request bodies.
Figure 25. Exchange: distinguish HAFNIUM from broader exploitation. The initial Microsoft report attributes Exchange exploitation and webshells to HAFNIUM; the separately linked post-exploitation report covers multiple actors. Do not assign every later observation to HAFNIUM. The detection panel is a proposal, not a reproduced intrusion.SOURCE-REPORTED + AUTHOR INFERENCE · USER-SUPPLIEDSources: S02 · Microsoft: initial HAFNIUM investigation · Supplement · Microsoft: broader Exchange post-exploitation · Supplied source key: S01–S14.
Text equivalent and full-size diagram

Do not assign every post-exploitation observation to HAFNIUM. Standard IIS logs do not expose arbitrary request bodies.

Reported activity: exploitation of on-premises Exchange servers enabled webshell deployment and subsequent access. Original HAFNIUM reporting and broader Exchange exploitation are distinct evidence scopes.

Proposed hypothesis: correlate unusual HTTP activity, ASPX file writes and a web-worker process spawning a shell or a later descendant, using the server role and application context.

Technical boundary: ordinary IIS access logs do not capture arbitrary request bodies. Security 4688, Sysmon process-creation events and EDR records have different schemas and collection requirements.

Interpretation: verify process ancestry and legitimate administration. The same process names or HTTP status do not establish an intrusion or actor attribution.

Open original full-size asset

Conti Ransomware (2021–2022)​

Source-reported: the selected BazarCall investigation describes a progression through Trickbot and Cobalt Strike to Conti. It is one intrusion account, not a composite timeline for every Conti affiliate. The earlier IcedID-proxy detail and unmatched elapsed-time claims are not retained as facts of this incident. The DFIR Report.

Inferred: correlate enumeration, remote administration, share access, service creation and security-setting changes by identity and host. AdFind prevalence must be measured locally; its execution does not guarantee that every EDR alerts. Shadow-copy deletion can occur during legitimate administration. For Defender, collect its own Operational channel: event 5001 reports disabled real-time protection and 5007 a configuration change. Registry telemetry can supplement these records but does not replace them. Defender event reference.

BazarCall to Conti: one documented investigation. The illustrated BazarCall, Trickbot, Cobalt Strike and Conti activity belongs to the selected investigation, not a universal affiliate playbook. Defender 5001 reports disabled real-time protection; 5007 reports configuration changes. Neither event alone proves malicious intent. This is not every affiliate’s timeline. Administrative tools and backup changes can be legitimate.
Figure 26. BazarCall to Conti: one documented investigation. The illustrated BazarCall, Trickbot, Cobalt Strike and Conti activity belongs to the selected investigation, not a universal affiliate playbook. Defender 5001 reports disabled real-time protection; 5007 reports configuration changes. Neither event alone proves malicious intent.SOURCE-REPORTED + AUTHOR INFERENCE · USER-SUPPLIEDSources: S03 · The DFIR Report: BazarCall to Conti · Supplement · Microsoft: Defender event meanings · Supplied source key: S01–S14.
Text equivalent and full-size diagram

This is not every affiliate’s timeline. Administrative tools and backup changes can be legitimate.

Reported activity: The DFIR Report documented a BazarCall intrusion involving Trickbot, Cobalt Strike and eventual Conti ransomware activity. This is one investigation, not an aggregate sequence observed in every Conti case.

Proposed hypothesis: join enumeration, remote administration, share access, security changes and subsequent activity using the relevant host and account, with bounded event time.

Technical boundary: Defender event 5001 concerns real-time protection being disabled; event 5007 concerns configuration changes. The provider, event fields and before/after state matter.

Interpretation: approved administrative tools, maintenance and backup changes can resemble parts of the pattern. The hypothesis has not been replayed against the private victim environment.

Open original full-size asset

APT34 / OilRig DNS Tunneling (2018–2024)​

Source-reported: Unit 42's RDAT investigation describes OilRig-associated tooling with several communication mechanisms and an email/steganography variant. Mechanisms differ by sample and version. The separate Talos DNSpionage investigation does not, by itself, establish an OilRig attribution. RDAT investigation, DNSpionage investigation.

Inferred: evaluate label structure, unique-label counts, record types, timing, destinations and process context. TXT-heavy legitimate workloads exist; a TXT:A ratio above one is not intrinsically malicious. Full labels are necessary for label-entropy analysis, not for every possible endpoint, traffic-volume or DNS-behavior detector. No universal label-length, entropy or cadence threshold is validated here.

OilRig-associated RDAT: identify the actual channel. Read the HTTP, DNS and email/EWS branches as available mechanisms, not mandatory successive stages or mutually exclusive variants: Unit 42 reports that the same EWS sample also supported HTTP and DNS tunneling. The channel must be established for the actual sample and activity. Do not collapse every variant into DNS tunneling or treat a TXT:A ratio as a verdict.
Figure 27. OilRig-associated RDAT: identify the actual channel. Read the HTTP, DNS and email/EWS branches as available mechanisms, not mandatory successive stages or mutually exclusive variants: Unit 42 reports that the same EWS sample also supported HTTP and DNS tunneling. The channel must be established for the actual sample and activity.SOURCE-REPORTED + AUTHOR INFERENCE · USER-SUPPLIEDSources: S04 · Unit 42: RDAT channels and steganography · Supplied source key: S01–S14.
Text equivalent and full-size diagram

Do not collapse every variant into DNS tunneling or treat a TXT:A ratio as a verdict.

Reported activity: Unit 42 investigated OilRig-associated RDAT at a telecommunications organization. The graphic separates HTTP, DNS and email/EWS communication, including a BMP steganography mechanism.

Clarification to the graphic’s different-variants shorthand: these are not mutually exclusive capabilities. Unit 42 explicitly reports HTTP and DNS support in the same EWS-capable sample. Available capabilities do not prove every channel was used in one intrusion.

Proposed hypothesis: inspect the relevant protocol structure, timing, destinations and endpoint evidence for that sample. A DNS-only analytic does not cover an email channel.

Technical boundary: a TXT-to-A query ratio is not a verdict, and DNSpionage is not interchangeable with this RDAT attribution. The hypothesis panel does not establish a measured threshold.

Open original full-size asset

MOVEit / Cl0p Campaign (2023)​

Source-reported: Mandiant described exploitation of MOVEit Transfer and LEMURLOOT, including its custom HTTP headers, database interaction and creation of a MOVEit application account named HealthCheckService / Health Check Service. It also described retrieval of Azure storage settings from the database. This is not evidence that a Windows user was created or that a particular configuration file was read. Mandiant investigation.

Inferred: correlate webshell writes/access, application account and session changes, database activity and exports. Windows event 4720 does not represent this SQL-backed account operation. A familiar-looking name alone is not proof of a malicious account, and a normal HTTP status does not establish benign use.

MOVEit: follow application and database evidence. LEMURLOOT’s Health Check Service account is a MOVEit application account, not a Windows local account. Windows Security 4720 does not represent this SQL-backed operation. Access to Azure settings in the application database is not evidence of a particular configuration-file read. Windows Security 4720 does not describe this SQL-backed application-account creation.
Figure 28. MOVEit: follow application and database evidence. LEMURLOOT’s Health Check Service account is a MOVEit application account, not a Windows local account. Windows Security 4720 does not represent this SQL-backed operation. Access to Azure settings in the application database is not evidence of a particular configuration-file read.SOURCE-REPORTED + AUTHOR INFERENCE · USER-SUPPLIEDSources: S05 · Mandiant: MOVEit and LEMURLOOT · Supplied source key: S01–S14.
Text equivalent and full-size diagram

Windows Security 4720 does not describe this SQL-backed application-account creation.

Reported activity: Mandiant described exploitation of MOVEit Transfer and the LEMURLOOT webshell, database interactions, an application account and data theft.

Proposed hypothesis: correlate webshell access, application-account or session changes, database activity and exports. Establish the entity joins rather than assuming one HTTP request explains every later event.

Technical boundary: Health Check Service is the application-account name in this account of the intrusion. A familiar-looking name is not independently malicious, and Windows account-creation event 4720 is the wrong expected source.

Interpretation: use MOVEit and database records for application changes. Distinguish application settings, actual exports and destination ownership; no query performance or victim replay is claimed.

Open original full-size asset

Midnight Blizzard / Cozy Bear (2023–2024)​

Source-reported: Microsoft described password spraying against a legacy test account without MFA, residential proxies, malicious applications and Exchange full_access_as_app permission abuse. Generic Microsoft Graph mail scopes must not be substituted for the incident's actual permission. January 25 investigation.

Microsoft's March update separately reported that some activity, including password sprays, increased by as much as tenfold in February relative to January. This is not a January observation or a measurement of total attack volume. March update.

Inferred: combine tenant/account-level failures with consent, application ownership, credentials and EWS access. Provider-wide visibility can add context that a tenant lacks; this does not establish that tenant-local analytics cannot detect distributed activity. Missing prior history is a cold-start problem, not proof of innocence.

Midnight Blizzard: preserve identity and permission context. Microsoft reported password spraying against a legacy test account without MFA, residential proxies and abuse of Exchange full_access_as_app access. This is not a generic Graph mail-scope example. Missing account history is a cold-start limitation, not evidence that activity is benign. Do not substitute generic Graph mail scopes. Missing history is a cold start, not evidence of innocence.
Figure 29. Midnight Blizzard: preserve identity and permission context. Microsoft reported password spraying against a legacy test account without MFA, residential proxies and abuse of Exchange full_access_as_app access. This is not a generic Graph mail-scope example. Missing account history is a cold-start limitation, not evidence that activity is benign.SOURCE-REPORTED + AUTHOR INFERENCE · USER-SUPPLIEDSources: S06 · Microsoft: Midnight Blizzard responder guidance · Supplied source key: S01–S14.
Text equivalent and full-size diagram

Do not substitute generic Graph mail scopes. Missing history is a cold start, not evidence of innocence.

Reported activity: the investigation connects a compromised legacy test account, password spraying and residential proxy infrastructure to application-mediated mailbox access.

Permission detail: the relevant Exchange permission was full_access_as_app, with EWS activity. Do not silently substitute a Microsoft Graph permission with a similar-looking purpose.

Proposed hypothesis: correlate authentication failures, application consent, ownership and credential changes with subsequent mailbox actions using real tenant and account identifiers.

Interpretation: sparse account history limits anomaly baselines. A new network location is not proof of the person’s physical location, and the graphic does not independently resolve vendor actor-name equivalence.

Open original full-size asset

Scattered Spider / UNC3944 (2023)​

Source-reported: Mandiant's June 2024 investigation describes help-desk social engineering, identity abuse and SaaS data theft involving legitimate integration tools. Its cluster label should not be treated as identical membership across every vendor name or as proof of attribution for every publicly named victim. UNC3944 investigation.

Inferred: join factor changes to subsequent sessions and sensitive application actions using actual account and tenant keys. A failed MFA event is not necessarily a denied push or a fraud report. Provider-side transfers may bypass the customer's endpoint and perimeter monitoring, but visibility varies: identity, application, connector, provider and destination records may still exist. Do not claim that an extortion demand is the only possible discovery path.

UNC3944: correlate identity changes and SaaS activity. This graphic summarizes Mandiant’s June 2024 campaign reporting, which includes 2023 observations; it is not a single dated victim timeline. Scattered Spider and UNC3944 naming does not establish identical cluster membership. Cloud-to-cloud transfers may bypass endpoint visibility while leaving identity, application or provider records. A transfer can bypass endpoint sensors without leaving every provider or application blind.
Figure 30. UNC3944: correlate identity changes and SaaS activity. This graphic summarizes Mandiant’s June 2024 campaign reporting, which includes 2023 observations; it is not a single dated victim timeline. Scattered Spider and UNC3944 naming does not establish identical cluster membership. Cloud-to-cloud transfers may bypass endpoint visibility while leaving identity, application or provider records.SOURCE-REPORTED + AUTHOR INFERENCE · USER-SUPPLIEDSources: S07 · Mandiant: UNC3944 targets SaaS · Supplied source key: S01–S14.
Text equivalent and full-size diagram

A transfer can bypass endpoint sensors without leaving every provider or application blind.

Reported activity: Mandiant described help-desk social engineering, identity abuse and SaaS data theft, including use of legitimate integration services such as Airbyte and Fivetran.

Proposed hypothesis: join factor changes, authenticated sessions, new application relationships and sensitive actions with verified tenant, identity and resource keys.

Technical boundary: a provider-mediated transfer need not cross a monitored workstation. This does not mean every provider, identity or application audit source is blind.

Interpretation: approved recovery, migration and integration can create similar records. Vendor threat-cluster labels are not automatically exact membership equivalents, and this is not a measured detection result.

Open original full-size asset

Storm-0558 and OAuth Abuse Campaigns (2023)​

Source-reported — Storm-0558: the actor used an acquired Microsoft account consumer signing key to forge tokens. The key was not itself forged. The CSRB documents the State Department's June 2023 discovery and alerts from its custom Big Yellow Taxi rule using MailItemsAccessed. Customer-side detection did work; failure by the provider to discover the compromise independently is a different claim. CSRB investigation, incident narrative.

This is an important positive example of the article's thesis: available audit data, a contextual analytic and analyst investigation contributed to discovery. However, the public account does not provide the complete production query, thresholds, negative corpus or denominator needed to reproduce its performance. This article does not reconstruct the private rule or assign it precision/recall. Historical licensing constraints must not be presented as current product requirements. Current mailbox-audit guidance.

Source-reported — Storm-1283: this separate financially motivated activity involved OAuth applications and Azure compute used for cryptomining. It is not part of the Storm-0558 intrusion. Microsoft, December 12, 2023.

Inferred: unexpected application-to-resource relationships can guide investigation. VM creation by a service principal is also normal automation; principal ownership, role, change history and workload purpose are essential.

Storm campaigns: keep token abuse and OAuth cases separate. Storm-0558 forged tokens using an acquired signing key; it did not forge the key. The CSRB account of Big Yellow Taxi and MailItemsAccessed is linked separately from S08/S09. Storm-1283 OAuth cryptomining is a separate campaign, not a later attack stage. No validation of the author’s proposed detector is implied. The private rule and performance denominator are not published here. Storm-1283 OAuth cryptomining is a separate campaign.
Figure 31. Storm campaigns: keep token abuse and OAuth cases separate. Storm-0558 forged tokens using an acquired signing key; it did not forge the key. The CSRB account of Big Yellow Taxi and MailItemsAccessed is linked separately from S08/S09. Storm-1283 OAuth cryptomining is a separate campaign, not a later attack stage. No validation of the author’s proposed detector is implied.SOURCE-REPORTED + AUTHOR INFERENCE · USER-SUPPLIEDSources: S08 · Microsoft: Storm-0558 email intrusion · S09 · Microsoft: separate OAuth campaigns · Supplement · CSRB: customer-side detection account · Supplied source key: S01–S14.
Text equivalent and full-size diagram

The private rule and performance denominator are not published here. Storm-1283 OAuth cryptomining is a separate campaign.

Reported Storm-0558 activity: access to a signing key enabled forged tokens and mailbox access. The graphic distinguishes the attacker workflow from the customer-side detection account.

Source-attributed detection account: the CSRB describes State Department discovery involving Big Yellow Taxi and MailItemsAccessed. Its PDF could not be retrieved for a fresh full-text review during this integration; this account is retained from the sourced article, not newly independently verified here.

Separate report: Microsoft’s Storm-1283 OAuth-abuse account concerns a financially motivated campaign including Azure cryptomining. It is not a continuation of the Storm-0558 intrusion.

Proposed hypothesis: combine workload audit events, identity context and application activity. The private customer query and its performance denominator are not published here; no benchmark or victim replay is asserted.

Open original full-size asset

Volt Typhoon (2023–2024)​

Source-reported: Microsoft describes credential extraction with ntdsutil IFM against domain controllers, alongside living-off-the-land activity and proxy infrastructure. The execution host and any remote initiation host must be distinguished. Microsoft, May 24, 2023.

Inferred: examine IFM creation on a domain controller by an unexpected principal or outside approved backup activity, particularly with subsequent staging and movement. A non-DC-only filter misses the relevant execution context. Process arguments are useful but not the only evidence: file, authentication, network and change records can contribute.

For log clearing, distinguish Security event 1102 from 104 in the System channel from the Eventlog provider. Record which channel was cleared; do not map wevtutil cl System to Security 1102. Collection gaps require independent health evidence before attributing intentional impairment. Legitimate maintenance remains a competing explanation. Security 1102 reference.

Volt Typhoon: distinguish initiation and execution hosts. IFM means Install From Media: creating domain-controller installation media, not a complete recovery backup. The execution host for the illustrated ntdsutil operation is the domain controller; remote initiation can occur elsewhere. A non-DC-only filter would miss that execution context. A non-DC-only filter misses this execution context. A remote initiation host is not necessarily the execution host.
Figure 32. Volt Typhoon: distinguish initiation and execution hosts. IFM means Install From Media: creating domain-controller installation media, not a complete recovery backup. The execution host for the illustrated ntdsutil operation is the domain controller; remote initiation can occur elsewhere. A non-DC-only filter would miss that execution context.SOURCE-REPORTED + AUTHOR INFERENCE · USER-SUPPLIEDSources: S10 · Microsoft: Volt Typhoon investigation · Supplement · Microsoft: IFM command · Supplied source key: S01–S14.
Text equivalent and full-size diagram

A non-DC-only filter misses this execution context. A remote initiation host is not necessarily the execution host.

Reported activity: Microsoft described living-off-the-land operations, including ntdsutil IFM use to obtain sensitive Active Directory data on domain controllers.

Proposed hypothesis: review IFM creation on the DC, the principal, approved maintenance purpose and subsequent movement of generated data. Distinguish where remote activity is initiated from where the process actually runs.

Technical clarification: the graphic’s backup-capability shorthand refers to IFM installation media, not a full recovery backup. It is a legitimate administrative capability whose purpose and handling must be established.

Telemetry boundary: Security event 1102 and System / Eventlog event 104 are channel-specific log-clear records, not interchangeable universal evidence of all clearing. Approved maintenance is a competing explanation.

Open original full-size asset

Source-reported — MESSAGETAP: Mandiant describes a 64-bit ELF data miner on Linux SMS servers. It checks for configuration files, reads and removes them after loading, then uses libpcap to inspect traffic and save selected content. The polling phase is not a continuing configuration refresh, and the report does not describe the program as a shared library. Mandiant, October 2019.

Inferred: investigate unexpected packet-capture capability, process provenance and sensitive output files. Merely loading libpcap is not proof of malicious behavior; capturing packets can be part of legitimate operations.

Source-reported — database theft: Mandiant's July 2024 APT41 investigation describes SQLULDR2 for Oracle data export and PINEGROVE for transfer to OneDrive. This directly supports the account; a generic M-Trends citation is insufficient. APT41 Has Arisen From the DUST.

Inferred: evaluate unexpected exports and new storage destinations against the database server's role and approved jobs. Both an export utility and cloud storage can be legitimate.

APT41: two investigations, not one constructed chain. The 2019 MESSAGETAP and 2024 SQLULDR2/PINEGROVE reports describe separate investigations, not consecutive stages. MESSAGETAP’s configuration files were read and then removed; their later absence would not disprove execution. Neither libpcap loading nor cloud-storage use alone proves theft. Loading libpcap or using cloud storage is not proof of theft. These are separate reports, not sequential stages.
Figure 33. APT41: two investigations, not one constructed chain. The 2019 MESSAGETAP and 2024 SQLULDR2/PINEGROVE reports describe separate investigations, not consecutive stages. MESSAGETAP’s configuration files were read and then removed; their later absence would not disprove execution. Neither libpcap loading nor cloud-storage use alone proves theft.SOURCE-REPORTED + AUTHOR INFERENCE · USER-SUPPLIEDSources: S11 · Mandiant: MESSAGETAP (2019) · S12 · Mandiant: APT41 database theft (2024) · Supplied source key: S01–S14.
Text equivalent and full-size diagram

Loading libpcap or using cloud storage is not proof of theft. These are separate reports, not sequential stages.

2019 account: MESSAGETAP was an ELF data-mining tool on Linux SMS servers, using packet capture and configured selection criteria. Its configuration was consumed and then removed.

2024 account: a separate investigation described SQLULDR2 exports from Oracle databases and PINEGROVE transfers to OneDrive. Do not combine these accounts into a single observed intrusion sequence.

Proposed hypotheses: for the first case, inspect process provenance, capture activity and outputs; for the second, correlate database exports, staging and destination-account evidence.

Interpretation: legitimate capture libraries, database export tools and cloud storage need context. APT41 and Winnti naming is not independent proof of exact group membership, and no detector benchmark is shown.

Open original full-size asset

CISA AA22–277A — Impacket Lateral Movement in Defense Industrial Base Compromise (2022)​

The advisory reports Impacket and data theft without assigning a named actor. Tool names do not identify an execution mode: secretsdump.py is not synonymous with DCSync, and ordinary wmiexec.py execution is not a permanent WMI event subscription. CISA AA22–277A.

Inferred: correlate remote logons and WMI-related process ancestry; examine replication-specific evidence where DCSync is suspected. WMI Operational 5861 concerns permanent subscription activity, not every remote WMI execution. TCP/135 followed by dynamic RPC ports is not sufficient to identify DRSUAPI. Event 4662 also needs configured auditing and source enrichment, discussed below.

CISA AA22-277A: tool use is not attribution. A source-attributed summary of AA22-277A, not a named-actor attribution or exact causal timeline. The official advisory and PDF returned access errors during this integration, so its full text was not independently re-read. The proposed analytic still requires mode-specific evidence: secretsdump does not always mean DCSync. secretsdump is not synonymous with DCSync. Ordinary wmiexec is not a permanent WMI subscription.
Figure 34. CISA AA22-277A: tool use is not attribution. A source-attributed summary of AA22-277A, not a named-actor attribution or exact causal timeline. The official advisory and PDF returned access errors during this integration, so its full text was not independently re-read. The proposed analytic still requires mode-specific evidence: secretsdump does not always mean DCSync.SOURCE-REPORTED + AUTHOR INFERENCE · USER-SUPPLIEDSources: S13 · CISA / FBI / NSA: AA22-277A · Supplied source key: S01–S14.
Text equivalent and full-size diagram

secretsdump is not synonymous with DCSync. Ordinary wmiexec is not a permanent WMI subscription.

Source-attributed activity: the article’s CISA AA22-277A account concerns Impacket use and data theft at a defense-industrial-base organization without assigning a named threat actor.

The diagram groups reported observations for teaching; it does not prove that every observation occurred in the illustrated order or shares a single causal chain. Full advisory access was unavailable for this integration review.

Proposed hypothesis: correlate remote logons, process ancestry and credential-access or export evidence for the actual execution mode and host.

Technical boundary: secretsdump can operate without DCSync. Ordinary wmiexec does not imply a permanent WMI subscription, and WMI 5861 subscription evidence is not a generic wmiexec event. Ports alone do not prove DRSUAPI use.

Open original full-size asset

Lazarus Group / DPRK — 3CX Supply Chain (2023)​

Source-reported: SentinelOne reported behavioral detections starting March 22, before public disclosure of the compromised 3CX application. In the Windows chain, GitHub-hosted icon files carried encoded C2 information; they should not be described as executable content downloaded from GitHub. SentinelOne investigation.

Inferred: investigate unusual destinations and subsequent execution associated with a normally trusted application. A valid signature is not a benign verdict. Vendor-reported detection is evidence of those observations, not an independent comparison of all EDR products or proof that a proposed destination-rarity rule would perform equally well.

3CX: a valid signature is not a benign verdict. SentinelOne reported behavioral detections from 22 March 2023, before its 29 March disclosure. In the Windows chain, GitHub-hosted icons carried encoded C2 information, not executable payloads. That initial report did not settle actor attribution; the article’s DPRK/Lazarus label is not independently established by this graphic. The icons were not described as executable payloads. Vendor-reported detection is not an independent EDR benchmark.
Figure 35. 3CX: a valid signature is not a benign verdict. SentinelOne reported behavioral detections from 22 March 2023, before its 29 March disclosure. In the Windows chain, GitHub-hosted icons carried encoded C2 information, not executable payloads. That initial report did not settle actor attribution; the article’s DPRK/Lazarus label is not independently established by this graphic.SOURCE-REPORTED + AUTHOR INFERENCE · USER-SUPPLIEDSources: S14 · SentinelOne: 3CX investigation · Supplied source key: S01–S14.
Text equivalent and full-size diagram

The icons were not described as executable payloads. Vendor-reported detection is not an independent EDR benchmark.

Reported activity: the trojanized 3CX desktop application participated in a supply-chain attack despite signed binaries. SentinelOne reported behavioral detections before its public write-up.

Windows mechanism: icon files hosted on GitHub contained appended encoded information that the malware decoded into command-and-control addresses. The icons were not themselves the later executable payloads.

Proposed hypothesis: investigate changes in destinations and later execution associated with a normally trusted application, retaining signer, process and network context.

Interpretation: a signature validates a signing relationship, not benign behavior. The initial vendor investigation left attribution open; its detection account is not an independently reproduced comparison of EDR products.

Open original full-size asset