Leveraging CALDERA to emulate various adversarial activities for detection capability testing.
APT41, also known as Double Dragon, is a hacking organization that has been active since 2012 and is believed to have alleged ties to the Chinese Ministry of State Security (MSS). The group has been known to engage in cyber espionage and individual financial gain, hence the origin of the moniker "Double Dragon".
Download Macro-Enabled Phishing Attachment
Create a Process using obfuscated Win32_Process
Execute a Command as a Service
Powershell Cmdlet Scheduled Task
Create a new user in a command prompt
Clear Logs (using wevtutil)
File and Directory Discovery (PowerShell)
Find files
Task 7: Case Study: Emulating APT41
https://tryhackme.com/room/caldera
#tryhackme