APT trends report Q2 2021

2021-07-26 Kaspersky

https://securelist.com/apt-trends-report-q2-2021/103517/

Thumbnail for APT trends report Q2 2021

Kaspersky's Q2 2021 APT trends material includes no DPRK-linked section in the provided excerpt, so the supported content is limited to other regional intrusion clusters. The excerpt describes Exchange exploitation tied to FourteenHi and possible ShadowPad overlap, Nobelium/APT29-style diplomatic phishing activity, and several Chinese-speaking campaigns including GhostEmperor, APT31, EdwardsPheasant, BountyGlad, and QSC. Reported TTPs include Exchange server exploitation, VLC abuse for loader execution, ISO/LNK phishing chains, Cobalt Strike deployment, compromised SOHO routers used as relay infrastructure, supply-chain compromise, spear-phishing, and public exploit use. Because no North Korea, Lazarus, Kimsuky, Andariel, APT37, or APT38 activity appears in the excerpt, it should not be treated as DPRK evidence beyond broad APT trend context.

Related Reports

« Back