<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:media="http://search.yahoo.com/mrss/"><channel><title><![CDATA[Cisco Talos Blog]]></title><description><![CDATA[Talos intelligence and world-class threat research team better protects you and your organization against known and emerging cybersecurity threats.]]></description><link>https://blog.talosintelligence.com/</link><image><url>https://blog.talosintelligence.com/favicon.png</url><title>Cisco Talos Blog</title><link>https://blog.talosintelligence.com/</link></image><generator>Ghost 6.34</generator><lastBuildDate>Thu, 30 Apr 2026 18:43:20 GMT</lastBuildDate><atom:link href="https://blog.talosintelligence.com/rss/" rel="self" type="application/rss+xml"/><ttl>60</ttl><item><title><![CDATA[Great responsibility, without great power]]></title><description><![CDATA[In this week’s newsletter, Hazel uses International Superhero Day as a springboard to explore why empathy — rather than just technical prowess — is the most essential, underrated superpower for navigating the human side of cybersecurity.]]></description><link>https://blog.talosintelligence.com/great-responsibility-without-great-power/</link><guid isPermaLink="false">69f351e2d2ad2b00012dcad6</guid><category><![CDATA[Threat Source newsletter]]></category><dc:creator><![CDATA[Hazel Burton]]></dc:creator><pubDate>Thu, 30 Apr 2026 18:00:07 GMT</pubDate><media:content url="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/threat_source-4.jpg" medium="image"/><content:encoded><![CDATA[<img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/threat_source-4.jpg" alt="Great responsibility, without great power"><p>Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xA0;</p><p>As&#xA0;I&#x2019;m&#xA0;writing this, today (April 28) is International Superhero Day. If you&#xA0;don&#x2019;t&#xA0;know the origin story behind this,&#xA0;perhaps you&#xA0;would assume that this day was dreamed up by Marvel. And&#x2026; you would be correct.&#xA0;</p><p>However,&#xA0;it&#x2019;s&#xA0;not a pure marketing ploy. It all started in 1995, when colleagues in Marvel asked a group of school children what superpower&#xA0;they&#x2019;d&#xA0;want the most.&#xA0;&#xA0;</p><p>Through the discussion, it became clear that the people in the children&#x2019;s lives were already doing&#xA0;pretty heroic&#xA0;things, without the benefit of Hindsight Lad. (He&#x2019;s&#xA0;a real Marvel invention &#x2014; Carlton&#xA0;LaFroyge&#xA0;&#x2014; whose superpower was to make aggressively obvious observations, delivered too late to matter.&#xA0;I&#x2019;m&#xA0;sure we all have a real-life Carlton&#xA0;LaFroyge&#xA0;in our lives&#x2026; heck, some of us ARE Carlton&#xA0;LaFroyge.)&#xA0;</p><p>Ok, before I get to my next point, I need to take you down the same internet wormhole I just disappeared into. Here are some of the weirdest superpowers ever committed to comic book lore:&#xA0;</p><ol><li>Eye-Scream. His one power is to become ice cream (soft serve, apparently). Not to be confused with another Marvel character, Soft Serve, whose body acts as a portal to an ice cream dimension.&#xA0;</li><li>Doorman. Recently seen sending Josh Gad into the Dark Dimension (where there&#xA0;presumably is&#xA0;no ice cream) in the Marvel TV show &#x201C;WonderMan.&#x201D; Because his body is a door. Man.&#xA0;&#xA0;</li><li>The Wall. Has the ability to turn himself into a brick wall. I would genuinely love this ability during socially awkward networking events.&#xA0;</li></ol><p>Now&#xA0;I&#x2019;m&#xA0;thinking how awesome a character called &#x201C;Internet Wormhole&#x201D; would be. I just looked it up, and such a character&#xA0;doesn&#x2019;t&#xA0;exist yet (call me, Marvel).&#xA0;&#xA0;</p><p>Right,&#xA0;let&#x2019;s&#xA0;get back on topic. Ooh&#x2026; &#x201C;On topic&#x201D; would be another&#xA0;good idea&#xA0;for a super&#x2026; no,&#xA0;Hazel, no.&#xA0;</p><p>Anyway, the children&#x2019;s ability to&#xA0;identify&#xA0;the people closest to them &#x2014; parents, grandparents, teachers, uncles, and aunts &#x2014; as heroes is a comforting thought for me. Having someone&#x2019;s back is more about showing up than anything else. Being there for them when they need it (and when they&#xA0;don&#x2019;t&#xA0;even realise they need it). Helping to make someone&#x2019;s situation a little bit less bad.&#xA0;&#xA0;</p><p>I can think of a few people in my life who have done, and continue to do, exactly that for me, which makes me feel incredibly lucky. And in an industry like cybersecurity, where&#xA0;bad things&#xA0;happen every single day, it matters more than we tend to admit. You need people around you who can steady things, who can sense you need support, who can listen to you, and who can tell you a silly story on a bleak day.&#xA0;</p><p>Empathy&#xA0;doesn&#x2019;t&#xA0;usually get listed as a specific skillset within cybersecurity, but I think I, and many of my Talos colleagues, would agree that&#xA0;it&#x2019;s&#xA0;absolutely essential. Users make decisions for reasons that make sense to them. Attackers take advantage of that. If you&#xA0;can&#x2019;t&#xA0;see both sides of that equation,&#xA0;you&#x2019;re&#xA0;probably not&#xA0;helping as many people as you could.&#xA0;&#xA0;</p><p>I&#x2019;ll&#xA0;end by answering the ultimate question &#x2014; who is the greatest superhero of all time?&#xA0;&#xA0;</p><p>It&#x2019;s&#xA0;obviously Squirrel Girl. She bested&#xA0;Galactus&#xA0;with a cup of tea and a chat. And though my mum has never been in the same room as&#xA0;Galactus, I have no doubt&#xA0;she&#x2019;d&#xA0;handle him in&#xA0;exactly the sameway.&#xA0;</p><h2 id="the-one-big-thing">The one&#xA0;big thing&#xA0;</h2><p>Cisco Talos is wrapping up Year in Review coverage by giving&#xA0;<a href="https://blog.talosintelligence.com/five-defender-priorities-from-the-talos-year-in-review/" rel="noreferrer noopener"><strong><u>five critical priorities</u></strong></a>&#xA0;to help defenders navigate an increasingly automated threat landscape. While AI and readily available exploit code have drastically lowered the barrier to entry for threat actors, these adversaries still rely on predictable patterns. Identity infrastructure, exposed legacy systems, and platforms that broker trust&#xA0;remain&#xA0;the primary battlegrounds.&#xA0;Ultimately, even&#xA0;the fastest automated attacks generate anomalous behavior that stands out from normal user activity.&#xA0;</p><h3 id="why-do-i-care">Why do I care?&#xA0;</h3><p>The speed at which attackers weaponize vulnerabilities and target identity systems &#x2014; highlighted by a 178 percent spike in device compromise &#x2014; can feel overwhelming. But there is&#xA0;a silver lining&#xA0;for security teams. Because adversaries inevitably reuse infrastructure and&#xA0;fail to&#xA0;mimic legitimate user behavior, defenders&#xA0;maintain&#xA0;a distinct advantage if they know exactly where to look.&#xA0;</p><h3 id="so-now-what">So now what?&#xA0;</h3><p>Security teams need to focus on what they can control right now by treating identity infrastructure as a top-tier critical asset. Secure your MFA workflows with strict verification and build baseline detections around what users&#xA0;actually do&#xA0;after they log in. Prioritize patching vulnerabilities based on internet exposure rather than only severity&#xA0;scores, and&#xA0;actively hunt down the long tail of legacy risks hiding in your network. Finally, apply enhanced monitoring to management-plane systems and focus your detection efforts on anomalous events to cut through the noise of alert fatigue.&#xA0;</p><h2 id="top-security-headlines-of-the-week">Top security headlines of the week&#xA0;</h2><p><strong>Home security giant ADT data breach affects</strong>&#xA0;<strong>5.5 million people</strong>&#xA0;<br>The extortion group told&#xA0;BleepingComputer&#xA0;that they had allegedly breached the company after compromising an employee&apos;s Okta single sign-on (SSO) account in a voice phishing (vishing) attack.&#xA0;(<a href="https://www.bleepingcomputer.com/news/security/home-security-giant-adt-data-breach-affects-55-million-people/" rel="noreferrer noopener"><u>BleepingComputer</u></a>)&#xA0;</p><p><strong>U.S. companies hit with record fines for privacy in 2025</strong>&#xA0;<br>The increase is driven in part by stronger, more established privacy laws in states like California, new interstate partnerships built around enforcing laws across state lines, and a renewed focus&#xA0;to&#xA0;how AI and automation affect privacy. (<a href="https://cyberscoop.com/privacy-companies-hit-with-record-fines-2025-gartner/" rel="noreferrer noopener"><u>CyberScoop</u></a>)&#xA0;</p><p><strong>PyPI</strong>&#xA0;<strong>package with 1.1M monthly downloads hacked to push infostealer</strong>&#xA0;<br>The dangerous release is 0.23.3, and it extended to the Docker image due to the&#xA0;package&apos;s&#xA0;workflow that creates the image from the code and uploads it to a container registry for deployment. (<a href="https://www.bleepingcomputer.com/news/security/pypi-package-with-11m-monthly-downloads-hacked-to-push-infostealer/" rel="noreferrer noopener"><u>BleepingComputer</u></a>)&#xA0;</p><p><strong>LiteLLM</strong>&#xA0;<strong>CVE-2026-42208 SQL injection exploited within 36 hours of disclosure</strong>&#xA0;<br>A newly disclosed critical security flaw in&#xA0;BerriAI&apos;s&#xA0;LiteLLM&#xA0;Python package has come under active exploitation in the wild within&#xA0;36 hours&#xA0;of the bug becoming public knowledge.&#xA0;(<a href="https://thehackernews.com/2026/04/litellm-cve-2026-42208-sql-injection.html" rel="noreferrer noopener"><u>The Hacker News</u></a>)&#xA0;</p><p><strong>Feuding ransomware groups leak each other&apos;s data</strong>&#xA0;<br>In response to its data leaking,&#xA0;KryBit&#xA0;breached and exfiltrated 0APT&apos;s infrastructure, listed the latter as a victim, and left a message on 0APT&apos;s leak site: &quot;Next time, don&apos;t play with the big boys.&quot; (<a href="https://www.darkreading.com/threat-intelligence/feuding-ransomware-groups-leak-data" rel="noreferrer noopener"><u>Dark Reading</u></a>)&#xA0;</p><h2 id="can%E2%80%99t-get-enough-talos">Can&#x2019;t&#xA0;get enough Talos?&#xA0;</h2><p><a href="https://blog.talosintelligence.com/ai-powered-honeypots-turning-the-tables-on-malicious-ai-agents/" rel="noreferrer noopener"><strong><u>AI-powered honeypots: Turning the tables on malicious AI agents</u></strong></a>&#xA0;<br>Because AI systems generate plausible responses&#xA0;within&#xA0;a given&#xA0;context&#xA0;and set of&#xA0;inputs, they can be tricked into responding&#xA0;inappropriately through prompt injection or into interacting with systems that are not what they appear to be.&#xA0;This Tool Talk&#xA0;shows how&#xA0;generative AI can be used to rapidly deploy adaptive honeypots.&#xA0;</p><p><a href="https://blog.talosintelligence.com/ir-trends-q1-2026/" rel="noreferrer noopener"><strong><u>Talos IR Trends Q1 2026: Phishing reemerges</u></strong></a>&#xA0;<br>Phishing is back as the top&#xA0;initial&#xA0;access vector for attackers targeting the health care and public administration sectors. We did not&#xA0;observe&#xA0;any ransomware deployment thanks to early and swift mitigation from Talos IR.&#xA0;</p><p><a href="https://www.buzzsprout.com/2033817/episodes/19097848" rel="noreferrer noopener"><strong><u>25 years of uninterrupted persistence</u></strong></a>&#xA0;<br>Hazel,&#xA0;Dave,&#xA0;and Joe&#xA0;cover&#xA0;Bill&#x2019;s 25 years at Talos&#xA0;and&#xA0;the&#xA0;latest security headlines, including AI-assisted vulnerability research, and why attackers still&#xA0;can&#x2019;t&#xA0;resist abusing trusted systems (or Roblox).&#xA0;</p><h2 id="upcoming-events-where-you-can-find-talos">Upcoming events where you can find Talos&#xA0;</h2><ul><li><a href="https://pivotcon.org/" rel="noreferrer noopener"><u>PIVOTcon</u></a>&#xA0;(May 6 &#x2013; 8) M&#xE1;laga, Spain&#xA0;</li><li><a href="https://www.offensivecon.org/" rel="noreferrer noopener"><u>OffensiveCon</u></a>&#xA0;(May 15 &#x2013; 16)&#xA0;Berlin, Germany&#xA0;</li><li><a href="https://www.ciscolive.com/global.html?zid=pp" rel="noreferrer noopener"><u>Cisco Live U.S.</u></a>&#xA0;(May 31&#xA0;&#x2013;&#xA0;June 4) Las Vegas, Nevada&#xA0;</li></ul><h2 id="most-prevalent-malware-files-from-talos-telemetry-over-the-past-week">Most prevalent malware files from Talos telemetry over the past week&#xA0;</h2><p><strong>SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507</strong>&#xA0;&#xA0;<br>MD5: 2915b3f8b703eb744fc54c81f4a9c67f&#xA0;<br>Talos Rep:&#xA0;<a href="https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507" rel="noreferrer noopener"><u>https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507</u></a>&#xA0;<br>Example Filename:VID001.exe&#xA0;<br>Detection Name:&#xA0;Win.Worm.Coinminer::1201&#xA0;</p><p><strong>SHA256: 96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974</strong>&#xA0;&#xA0;<br>MD5: aac3165ece2959f39ff98334618d10d9&#xA0;&#xA0;<br>Talos Rep:&#xA0;<a href="https://talosintelligence.com/talos_file_reputation?s=96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974" rel="noreferrer noopener"><u>https://talosintelligence.com/talos_file_reputation?s=96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974</u></a>&#xA0;&#xA0;<br>Example Filename:&#xA0;d4aa3e7010220ad1b458fac17039c274_63_Exe.exe&#xA0;&#xA0;<br>Detection Name:&#xA0;W32.Injector:Gen.21ie.1201&#xA0;</p><p><strong>SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59</strong>&#xA0;&#xA0;<br>MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a&#xA0;&#xA0;<br>Talos Rep:&#xA0;<a href="https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59" rel="noreferrer noopener"><u>https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59</u></a>&#xA0;&#xA0;<br>Example Filename:&#xA0;APQ9305.dll&#xA0;&#xA0;<br>Detection Name: Auto.90B145.282358.in02&#xA0;</p><p><strong>SHA256: 38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55</strong>&#xA0;&#xA0;<br>MD5: 41444d7018601b599beac0c60ed1bf83&#xA0;&#xA0;<br>Talos Rep:&#xA0;<a href="https://talosintelligence.com/talos_file_reputation?s=38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55" rel="noreferrer noopener"><u>https://talosintelligence.com/talos_file_reputation?s=38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55</u></a>&#xA0;&#xA0;<br>Example Filename:&#xA0;content.js&#xA0;&#xA0;<br>Detection Name: W32.38D053135D-95.SBX.TG&#xA0;</p><p><strong>SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91</strong>&#xA0;&#xA0;<br>MD5: 7bdbd180c081fa63ca94f9c22c457376&#xA0;&#xA0;<br>Talos Rep:&#xA0;<a href="https://talosintelligence.com/talos_file_reputation?s=a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91" rel="noreferrer noopener"><u>https://talosintelligence.com/talos_file_reputation?s=a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91</u></a>&#xA0;&#xA0;<br>Example Filename:&#xA0;d4aa3e7010220ad1b458fac17039c274_62_Exe.exe&#xA0;&#xA0;<br>Detection Name:&#xA0;Win.Dropper.Miner::95.sbx.tg**&#xA0;</p><p><strong>SHA256: e60ab99da105ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba</strong>&#xA0;&#xA0;<br>MD5: dbd8dbecaa80795c135137d69921fdba&#xA0;&#xA0;<br>Talos Rep:&#xA0;<a href="https://talosintelligence.com/talos_file_reputation?s=e60ab99da105ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba" rel="noreferrer noopener"><u>https://talosintelligence.com/talos_file_reputation?s=e60ab99da105ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba</u></a>&#xA0;&#xA0;<br>Example&#xA0;Filename:&#xA0;u992574.dll&#xA0;&#xA0;<br>Detection Name:&#xA0;W32.Variant:MalwareXgenMisc.29d4.1201&#xA0;</p>]]></content:encoded></item><item><title><![CDATA[AI-powered honeypots: Turning the tables on malicious AI agents]]></title><description><![CDATA[Just as AI brings time-saving advantages to our lives, it brings similar advantages to threat actors. We can take the advantage back. This blog shows how generative AI can be used to rapidly deploy adaptive honeypot systems.]]></description><link>https://blog.talosintelligence.com/ai-powered-honeypots-turning-the-tables-on-malicious-ai-agents/</link><guid isPermaLink="false">69ef6227d2ad2b00012dca41</guid><category><![CDATA[Tool Talk]]></category><category><![CDATA[AI]]></category><dc:creator><![CDATA[Martin Lee]]></dc:creator><pubDate>Wed, 29 Apr 2026 10:00:42 GMT</pubDate><media:content url="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/tool_talk.jpg" medium="image"/><content:encoded><![CDATA[<ul><li>Generative AI allows defenders to instantly create diverse honeypots, like Linux shells or Internet of Things (IoT)&#xA0;devices, using&#xA0;simple text&#xA0;prompts. This makes deploying complex, convincing deceptive environments much easier and more scalable than traditional methods.&#xA0;</li><li>AI-driven attacks often prioritize speed over stealth, making them highly vulnerable to being tricked by these simulated systems. This is critical because it allows defenders to catch and study automated threats that might otherwise overwhelm human teams.&#xA0;</li><li>This method shifts the strategy from merely detecting attacks to actively manipulating and misleading threat actors. Organizations can safely&#xA0;observe&#xA0;attacker methodologies in real-time within a controlled &quot;hall of mirrors.&quot;&#xA0;</li><li>Ultimately, by&#xA0;exploiting the inherent lack of awareness in AI agents, defenders can level the playing field and turn an attacker&apos;s automation into a liability.</li></ul><hr><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/tool_talk.jpg" alt="AI-powered honeypots: Turning the tables on malicious AI agents"><p>Just as AI brings time-saving advantages to our lives, it&#xA0;brings similar advantages to threat actors. The laborious,&#xA0;time-consuming&#xA0;tasks of finding potentially vulnerable systems,&#xA0;identifying&#xA0;their vulnerabilities, and executing exploit code can be automated and orchestrated using AI.&#xA0;</p><p>Clearly, these&#xA0;new capabilities put defenders at a disadvantage,&#xA0;as they expose&#xA0;new vulnerabilities for the threat actor. Attackers seek to minimize exposure.&#xA0;The more that a defender knows about a potential attack, the better they can prepare to repel or detect an attack.&#xA0;Using AI-orchestrated tooling to gain access to systems trades stealth for capability. That trade-off increases attacker visibility, and increased visibility is something defenders can exploit.</p><p>AI systems do not&#xA0;possess&#xA0;awareness. They&#xA0;generate plausible responses&#xA0;within&#xA0;a given&#xA0;context&#xA0;and set of&#xA0;inputs. As such they can be tricked or fooled into responding&#xA0;inappropriately through prompt injection or into interacting with systems that are not what they appear to be.&#xA0;</p><p>Honeypot systems have long been&#xA0;deployed&#xA0;as a method for gathering information about malicious activities.&#xA0;There are many software&#xA0;projects providing&#xA0;honeypots&#xA0;which can be installed and configured. However, the advent of generative AI systems provides us with the possibility to use AI to masquerade as vulnerable systems and&#xA0;allowing them to be deployed widely and with minimal effort.&#xA0;</p><p>In this post, I show how generative AI can be used to rapidly deploy adaptive honeypot systems.&#xA0;</p><h2 id="getting-started">Getting started</h2><p>The implementation consists of three components:&#xA0;a listener that will accept network connections, a&#xA0;simulated&#xA0;vulnerability that will grant access to the attacker&#xA0;once triggered, and an AI framework that will respond to the attacker&#x2019;s instructions.&#xA0;</p><p>The listener opens a TCP port, accepts incoming connections, and forwards traffic&#xA0;to&#xA0;<code>handle_client</code>. I set HOST to be &#x201C;0.0.0.0&#x201D; to accept any incoming connections to any local IPv4 addresses that my device is assigned.</p>
<!--kg-card-begin: html-->
<pre>def start_server(): 
    &quot;&quot;&quot;Starts the TCP server.&quot;&quot;&quot; 
    server = socket.socket(socket.AF_INET, socket.SOCK_STREAM) 
    server.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)  
    server.bind((HOST, PORT))  
    server.listen(3) # max number of concurrent connections 
    print(f&quot;[*] Listening on {HOST}:{PORT}&quot;) 
 
    while True: 
        try: 
            conn, addr = server.accept()  
            client_handler = threading.Thread(target=handle_client, args=(conn, addr,)) 
            client_handler.start() 
        except KeyboardInterrupt: 
            print(&quot;\n[*] Shutting down server...&quot;) 
            break 
        except Exception as e: 
            print(f&quot;[-] Server error: {e}&quot;) 
             
    server.close() 
 
if __name__ == &quot;__main__&quot;: 
    start_server()</pre>
<!--kg-card-end: html-->
<p>Within&#xA0;<code>handle_client</code>&#xA0;I have created&#xA0;a very basic&#xA0;vulnerability that must be exploited before further access is granted.&#xA0;In this case, the attacker must supply the username&#xA0;&#x201C;admin&#x201D;with the password&#xA0;&#x201C;password123&#x201D;&#xA0;before they are authenticated.</p><p>The nature of the vulnerability need not be this simple.&#xA0;We could respond only to attempts to exploit Shellshock (CVE-2014-6271) or masquerade as a&#xA0;web&#xA0;shell&#xA0;that is only activated in response to&#xA0;<a href="https://attack.mitre.org/techniques/T1205/001/" rel="noreferrer noopener"><u>port knocking</u></a>.</p>
<!--kg-card-begin: html-->
<pre>def handle_client(conn, addr): 
    print(f&quot;[*] Accepted connection from {addr}:{addr}&quot;) 
    # Store conversation history for this client to maintain context  
    conversation_history = [SYSTEM_PROMPT] 
    try: 
        authenticated = False 
      	 while not authenticated: 
            conn.sendall(b&quot;Username: &quot;) 
            username = conn.recv(BUFFER_SIZE).decode(&apos;utf-8&apos;).strip() 
            conn.sendall(b&quot;Password: &quot;) 
            password = conn.recv(BUFFER_SIZE).decode(&apos;utf-8&apos;).strip() 
 
            if username == &quot;admin&quot; and password == &quot;password123&quot;: 
                authenticated = True 
                conn.sendall(b&quot;Authentication successful.\n&quot;) 
                print(f&quot;[*] Client {addr[0]}:{addr[1]} authenticated successfully.&quot;) 
            else: 
                conn.sendall(b&quot;Invalid credentials. Try again.\n&quot;) </pre>
<!--kg-card-end: html-->
<p>The&#xA0;remainder&#xA0;of the&#xA0;<code>handle_client</code>&#xA0;code&#xA0;accepts the attacker&#x2019;s input, forwards it to the ChatGPT instance,&#xA0;and outputs the message and response to the console.</p>
<!--kg-card-begin: html-->
<pre>        while True: 
            conn.sendall(b&apos;&gt;&apos;) 
            data = conn.recv(BUFFER_SIZE) 
            if not data: 
                print(f&quot;[*] Client {addr}:{addr} disconnected.&quot;) 
                break 
 
            command = data.decode(&apos;utf-8&apos;).strip() 
            print(f&quot;[*] Received command from {addr}:{addr}: &apos;{command}&apos;&quot;) 
 
            if command.lower() == &apos;exit&apos;: 
                print(f&quot;[*] Client {addr}:{addr} requested exit.&quot;) 
                break 
            conversation_history.append({&quot;role&quot;: &quot;user&quot;, &quot;content&quot;: command}) 
 
            # Call ChatGPT API 
            try: 
                chat_completion = client.chat.completions.create( 
                    model=MODEL_NAME, 
                    messages=conversation_history, 
                    temperature=0.1, # Keep responses less creative, more factual/direct 
                    max_tokens=500 # Limit response length 
                ) 
                 
                # Extract AI&apos;s response 
                ai_response = chat_completion.choices[0].message.content.strip() 
                print(f&quot;[*] ChatGPT response: &apos;{ai_response}&apos;&quot;) 
                # Append AI&apos;s response to history for continued context 
                conversation_history.append({&quot;role&quot;: &quot;assistant&quot;, &quot;content&quot;: ai_response}) 
                # Send AI&apos;s response back to the client 
                conn.sendall(ai_response.encode(&apos;utf-8&apos;) + b&apos;\n&apos;) 
 
            except Exception as e: 
                error_message = f&quot;Error communicating with ChatGPT: {e}&quot; 
                print(error_message) 
                conn.sendall(error_message.encode(&apos;utf-8&apos;) + b&apos;\n&apos;) 
 
    except ConnectionResetError: 
        print(f&quot;[*] Client {addr}:{addr} forcibly closed the connection.&quot;) 
    except Exception as e: 
        print(f&quot;[-] Error handling client {addr}:{addr}: {e}&quot;) 
    finally: 
        conn.close() 
        print(f&quot;[*] Connection with {addr}:{addr} closed.&quot;) </pre>
<!--kg-card-end: html-->
<p>The key functionality is contained in the instructions to the ChatGPT instance. You must have a valid OpenAI key in order to initiate a ChatGPT instance that will behave as instructed.</p>
<!--kg-card-begin: html-->
<pre>OPENAI_API_KEY = os.getenv(&quot;OPENAI_API_KEY&quot;) # Get API key from environment variable                                       
MODEL_NAME = &quot;gpt-3.5-turbo&quot; 
 
# --- OpenAI Client Initialization --- 
if not OPENAI_API_KEY: 
    print(&quot;Error: OPENAI_API_KEY environment variable not set.&quot;) 
    print(&quot;Please set the environment variable before running the script.&quot;) 
    exit(1) 
 
client = OpenAI(api_key=OPENAI_API_KEY) 
 
# --- System Prompt for Linux Shell Simulation --- 
SYSTEM_PROMPT = { 
    &quot;role&quot;: &quot;system&quot;, 
    &quot;content&quot;: ( 
        &quot;You are a Linux bash shell. You will receive commands from the user and execute them, &quot; 
        &quot;returning only the standard output and standard error. Do not include any conversational text, &quot; 
        &quot;explanations, or additional formatting like markdown code blocks. You must only behave as a bash shell. &quot; 
        &quot;If a command produces no output, return an empty string&quot; 
        &quot;If a command is invalid or unknown, return an appropriate error message consistent with a bash shell.&quot; 
        &quot;The Linux system that you are impersonating belongs to a junior software engineer learning python, &quot; 
        &quot;the file system structure and the content of any files should reflect that expected of a python learner.&quot; 
    ) 
} </pre>
<!--kg-card-end: html-->
<p>Generative AI&#xA0;doesn&#x2019;t&#xA0;just simulate human&#xA0;personas,&#xA0;it can convincingly impersonate entire computing environments.&#xA0;In this example, we instruct the system to masquerade as a basic Linux shell owned by a software engineer learning Python.</p><figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Artboard-24-copy-4.jpg" class="kg-image" alt="AI-powered honeypots: Turning the tables on malicious AI agents" loading="lazy" width="1801" height="643" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Artboard-24-copy-4.jpg 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Artboard-24-copy-4.jpg 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Artboard-24-copy-4.jpg 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Artboard-24-copy-4.jpg 1801w" sizes="(min-width: 720px) 720px"></figure><p>We can be more inventive and instruct the system to masquerade as&#xA0;a smart fridge by changing our instructions to ChatGPT.</p>
<!--kg-card-begin: html-->
<pre>SYSTEM_PROMPT = { 
    &quot;role&quot;: &quot;system&quot;, 
    &quot;content&quot;: ( 
        &quot;You are a smart fridge running Busybox operating system and providing a Bash shell.&quot; 
        &quot;You will receive commands from the user and execute them in the context of being a smart fridge.&quot; 
        &quot;You will only return the standard output and standard error. Do not include any conversational text, &quot; 
        &quot;explanations, or additional formatting like markdown code blocks. You must only behave as a shell for an &quot; 
        &quot;IoT device. If a command produces no output, return an empty string&quot; 
        &quot;If a command is invalid or unknown, return an appropriate error message consistent with a bash shell.&quot; 
        &quot;The file system structure should reflect that of a smart fridge manufactured by SmartzFrijj running &quot; 
        &quot;Busybox operating system as an embedded device. The current and historical values for temperature are &quot; 
        &quot;recorded in the file system path \&apos;/usr/local\&apos;, information about stored milk is in the user directory.&quot; 
    ) 
}</pre>
<!--kg-card-end: html-->
<figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Artboard-24-copy-5.jpg" class="kg-image" alt="AI-powered honeypots: Turning the tables on malicious AI agents" loading="lazy" width="1801" height="1160" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Artboard-24-copy-5.jpg 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Artboard-24-copy-5.jpg 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Artboard-24-copy-5.jpg 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Artboard-24-copy-5.jpg 1801w" sizes="(min-width: 720px) 720px"></figure><p>The limiting factor is no longer tooling, but how convincingly we can model a target environment.&#xA0;&#xA0;A skilled human attacker is unlikely to be fooled for long&#xA0;&#x2014;&#xA0;that milk would&#xA0;be rank. But&#xA0;that&#x2019;s&#xA0;not the point.&#xA0;We&#x2019;re&#xA0;not deploying AI honeypots to trick human threat actors.&#xA0;&#xA0;</p><p>&#xA0;Let&#x2019;s&#xA0;ask ChatGPT what it thinks&#x2026;</p><figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Artboard-24-copy-7-1-.jpg" class="kg-image" alt="AI-powered honeypots: Turning the tables on malicious AI agents" loading="lazy" width="1801" height="1799" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Artboard-24-copy-7-1-.jpg 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Artboard-24-copy-7-1-.jpg 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Artboard-24-copy-7-1-.jpg 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Artboard-24-copy-7-1-.jpg 1801w" sizes="(min-width: 720px) 720px"></figure><p>The industry narrative around AI in cybersecurity is dominated by fear of faster attacks, lower barriers, and greater scale. But speed and scale come with a cost. AI systems require interaction and context. Automation does not simply amplify attackers. but also constrains and exposes them. In that constraint lies an opportunity: not just to detect attacks, but to mislead, study, and ultimately manipulate the attacker.</p>]]></content:encoded></item><item><title><![CDATA[Five defender priorities from the Talos Year in Review]]></title><description><![CDATA[With attackers moving faster than ever, it’s easy to feel overwhelmed. This blog breaks down five practical priorities from the Cisco Talos 2025 Year in Review to help defenders focus and prioritize, amidst all the noise.]]></description><link>https://blog.talosintelligence.com/five-defender-priorities-from-the-talos-year-in-review/</link><guid isPermaLink="false">69ef666bd2ad2b00012dca72</guid><category><![CDATA[2025YiR]]></category><category><![CDATA[Year In Review]]></category><category><![CDATA[Landing Page Top Story]]></category><category><![CDATA[Top Story]]></category><dc:creator><![CDATA[Hazel Burton]]></dc:creator><pubDate>Tue, 28 Apr 2026 13:23:20 GMT</pubDate><media:content url="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/YiR2025_cover_2x1-4.jpg" medium="image"/><content:encoded><![CDATA[<img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/YiR2025_cover_2x1-4.jpg" alt="Five defender priorities from the Talos Year in Review"><p>A familiar theme in security right now is that the barrier to entry for attackers is at an all-time low. AI tools can spin up websites within minutes that can easily&#xA0;direct data to disposable external data stores and send alerts for new captures &#x2014; all without code.&#xA0;</p><p>One such case was recently detailed in the latest&#xA0;<a href="https://blog.talosintelligence.com/ir-trends-q1-2026/"><u>Cisco Talos Incident Response Quarterly Trends</u></a>&#xA0;report.</p><p>Proof-of-concept code for exploiting new vulnerabilities used to take attackers months to create. Now they take hours.</p><p>All of this is very concerning for defenders. Yesterday, my colleague told me about a recent conference Q&amp;A he hosted, where he was asked to provide some hope to those in the room who have faced an overwhelming amount of change in recent months.&#xA0;</p><p>His answer was to focus on the here and now. Focus on what you can control, and what you have influence over. We can&#x2019;t change what may or may not happen in six months&#x2019; time, but we can prioritize what&#x2019;s important now.&#xA0;</p><p>The other key thing for defenders to bear in mind is that&#xA0;even when attackers move fast, they still don&#x2019;t behave like your normal users.<strong>&#xA0;</strong>At the end of the day, you&#x2019;re still looking for anomalous behavior &#x2013; whether that behavior is machine- or human-generated.</p><p>As we come to the end of our&#xA0;<a href="https://blog.talosintelligence.com/2025yearinreview/"><u>Year in Review</u></a>&#xA0;content release (if you haven&#x2019;t seen it yet, we published videos, podcasts, and topic specific blog posts), we&#x2019;d like to end by summarizing the key priorities for defenders.&#xA0;</p><p>Here are five of them that are worth considering when it comes to spotting malicious, unusual behaviour in your environment.</p><h2 id="1-identity-is-the-main-battlefield">1. Identity is the main battlefield&#xA0;</h2><p>The Year in Review highlights how frequently attackers rely on valid accounts and credential abuse throughout the attack chain. We see this across multiple areas:</p><ul><li>MFA spray attacks targeting IAM platforms directly&#xA0;</li><li>Device compromise attacks increasing 178% year over year&#xA0;</li><li>Attackers registering their own devices as trusted multi-factor authentication (MFA) methods</li><li>Ransomware <a>attack chains</a>&#xA0;largely relying on valid accounts, credentialed tools, or both</li></ul><p>Network infrastructure is a key part of this. VPNs, Active Directory Controllers (ADCs), and firewalls are being exploited to steal session tokens, bypass MFA, and impersonate users.</p><p>However, when attackers successfully authenticate, where they go from there tends not to fall in line with normal user behavior. They start to access new systems outside of their role, move laterally using tools like PsExec, execute commands at unusual times, and overall operate at a scale that normal users don&#x2019;t.</p><p>Therefore, having a baseline understanding of normal user behavior is more important than ever.</p><p><strong>Prioritize:</strong></p><ul><li>Treating identity infrastructure as Tier 1 critical assets and apply the strongest monitoring and protection controls to IAM and PAM systems</li><li>Securing MFA device registration workflows with strict verification procedures and limited administrative approval rights</li><li>Hardening authentication systems against automated attacks by enforcing rate limiting, anomaly detection, and strong conditional access policies</li><li>Building baseline detections around what users do, not just how they log in</li></ul><h2 id="2-prioritize-the-vulnerabilities-that-have-the-most-exposure">2. Prioritize the vulnerabilities that have the most exposure</h2><p>One of the most important callouts in the report is how attackers select targets. The rapid exploitation of vulnerabilities such as React2Shell and ToolShell shows that exploitation can begin immediately after disclosure with readily available proof-of-concepts. Attackers then prioritize what is exposed and reachable.&#xA0;</p><p>Attackers also like to exploit the vulnerabilities that are closest to identity, session handling, and access logic.</p><p>At the same time, older vulnerabilities such as Log4Shell remain among the most exploited, over four years after disclosure.</p><p>This creates a dual reality where some new vulnerabilities are weaponized instantly, but old, highly-valued vulnerabilities are never fully eliminated.</p><p><strong>Prioritize:</strong></p><ul><li>Remediating vulnerabilities based on internet exposure and access impact, not just CVSS scores</li><li>Reducing time-to-patch for externally accessible systems&#xA0;</li><li>Continuously reassessing what is reachable from the outside</li></ul><h2 id="3-address-the-long-tail-of-legacy-and-embedded-risk">3. Address the long tail of legacy and embedded risk</h2><p>The Year in Review highlights that nearly 40% of the top 100 most targeted vulnerabilities impact EOL systems, and 32% are over a decade old. Many of these vulnerabilities exist in deeply embedded components such as PHP frameworks, Log4j, and ColdFusion.</p><p>These components are often poorly inventoried, difficult to patch, and tightly coupled to business-critical systems.</p><p>It&#x2019;s a frustrating fact that&#xA0;the most persistent risks are often the least visible,<br>and the hardest to remove.&#xA0;They create long-term blind spots, which are an attacker&#x2019;s favorite thing to find and exploit.</p><p><strong>Prioritize:</strong></p><ul><li>Improving visibility into software dependencies and embedded components&#xA0;</li><li>Treating development frameworks and libraries as part of your attack surface&#xA0;</li><li>Establishing clear strategies for isolating or retiring legacy systems</li></ul><h2 id="4-secure-the-systems-that-broker-trust">4. Secure the systems that broker trust</h2><p>Attackers are increasingly targeting systems that provide maximum operational leverage. This includes network management platforms, application delivery controllers (ADCs), and shared software platforms running across multiple devices.</p><p>These systems are attractive to adversaries because they store credentials, control configurations across large environments, provide visibility into the network, and enable changes at scale.</p><p>Unfortunately, these platforms are also traditionally less monitored than endpoints, more complex to patch or upgrade, and have centralized points of failure.</p><p><strong>Prioritize:</strong></p><ul><li>Identifying management-plane and control-plane systems that need securing</li><li>Applying enhanced monitoring and access controls to these platforms&#xA0;</li><li>Limiting administrative access and enforce strong segmentation</li></ul><h2 id="5-keep-focusing-on-patterns-even-with-increased-automation-and-ai-driven-attacks">5. Keep focusing on patterns, even with increased automation and AI-driven attacks</h2><p>Yes, automation and AI are changing the threat landscape. As we&#x2019;ve spoken about, attackers are increasingly able to rapidly identify and exploit vulnerabilities, launch large-scale identity attacks, generate convincing phishing lures that mimic real business workflows, and accelerate parts of the attack lifecycle using AI-assisted tooling<u>.</u></p><p>However, all these things do not remove a key constraint for adversaries: Automated attacks still produce patterns of unusual behavior, and patterns are detectable.</p><p>Even highly scalable attacks tend to reuse the same infrastructure, tools, and techniques. They also follow predictable sequences of activity and generate anomalies.</p><p><strong>Prioritize:</strong></p><ul><li>Focusing detection efforts on anomalous events (e.g., unusual authentication flows, abnormal system access, anomalous device registration)&#xA0;</li><li>Reducing alert fatigue by prioritizing a smaller number of meaningful detections over broad, low-confidence alerting&#xA0;</li><li>Supporting triage and enrichment with automation where possible, alongside human decision-making</li><li>Ensuring teams are equipped to investigate patterns of behavior, not just isolated alerts</li></ul><h2 id="final-thoughts">Final thoughts</h2><p>Much of the current concern in and around the security community is the new reality that anyone can create a malicious campaign. The Year in Review doesn&#x2019;t disagree.</p><p>However, Talos data also shows something equally important:</p><ul><li>Attackers still rely on the same vulnerabilities&#xA0;</li><li>They reuse the same tools and techniques&#xA0;</li><li>They follow repeatable patterns&#xA0;</li><li>And, critically, they don&#x2019;t behave like your users</li></ul><p>Even when they successfully authenticate, move laterally, or establish persistence, their activity introduces detectable anomalies.</p><p>That&#x2019;s where the opportunity lies for defenders.&#xA0;</p><div class="kg-card kg-header-card kg-v2 kg-width-regular " data-background-color="#000000">
            
            <picture><img class="kg-header-card-image" src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/03/YiR2025_background-2.jpg" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/03/YiR2025_background-2.jpg 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/03/YiR2025_background-2.jpg 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/03/YiR2025_background-2.jpg 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/03/YiR2025_background-2.jpg 2000w" loading="lazy" alt="Five defender priorities from the Talos Year in Review"></picture>
        
            <div class="kg-header-card-content">
                
                <div class="kg-header-card-text kg-align-center">
                    <h2 id="read-the-2025-cisco-talos-year-in-review" class="kg-header-card-heading" style="color: #FFFFFF;" data-text-color="#FFFFFF"><span style="white-space: pre-wrap;">Read the 2025 Cisco Talos Year in Review</span></h2>
                    
                    <a href="https://blog.talosintelligence.com/content/files/2026/03/2025YiR-report.pdf" class="kg-header-card-button kg-style-accent" style="color: #FFFFFF;" data-button-color="accent" data-button-text-color="#FFFFFF">Download now</a>
                </div>
            </div>
        </div>]]></content:encoded></item><item><title><![CDATA[It pays to be a forever student]]></title><description><![CDATA[In this newsletter, Joe discusses why understanding other disciplines can often flow back into the macro and micro of cybersecurity, especially in a world of AI.]]></description><link>https://blog.talosintelligence.com/it-pays-to-be-a-forever-student/</link><guid isPermaLink="false">69e91b771bf70b0001e1a22d</guid><category><![CDATA[Threat Source newsletter]]></category><dc:creator><![CDATA[Joe Marshall]]></dc:creator><pubDate>Thu, 23 Apr 2026 18:00:22 GMT</pubDate><media:content url="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/threat_source-3.jpg" medium="image"/><content:encoded><![CDATA[<img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/threat_source-3.jpg" alt="It pays to be a forever student"><p>Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xA0;</p><p>If I&#xA0;haven&#x2019;t&#xA0;said it in a newsletter before,&#xA0;I&apos;ll&#xA0;say it now: If you want to be good at cybersecurity, be a forever student. Cultivating and feeding your desire to know how things work is one of the key ingredients to being a hacker.&#xA0;It&#x2019;s&#xA0;not always about understanding the micro details, but the macro of how systems work. And not just computers or software or networking systems &#x2014; those are ecosystems&#xA0;we&#x2019;re&#xA0;usually quite familiar with &#x2014; but what about economics?&#xA0;agriculture? material sciences?&#xA0;human&#xA0;behavior?&#xA0;music&#xA0;and art? Do any of those carry any value into this profession?&#xA0;</p><p>They&#xA0;damn sure do.&#xA0;Many, many&#xA0;times I have had to branch my technical research into domains that&#xA0;arbitrarily seem to provide&#xA0;no immediate value for technical problems. Learning how maritime insurance fraud works was interesting to me &#x2014; and&#xA0;a short time&#xA0;later, led to cyber insurance and understanding how risk guides security investment in massive companies. Understanding international agriculture helped me research threat actor targeting and ransomware cartel victimology.&#xA0;</p><p>One of the topics&#xA0;I&apos;ve&#xA0;been researching heavily lately is economics, specifically industrial&#xA0;organization.&#xA0;It&#x2019;s&#xA0;a branch of economics that studies how companies structure production, how markets form around them, and how costs&#xA0;operate&#xA0;at scale. For me, the natural target of my curiosity was&#xA0;Ford&#xA0;Motor Company. Henry Ford&#xA0;didn&#x2019;t&#xA0;invent the car or the assembly line, but he was darn sure able to build and scale car production in a way that set the standard for all others in that space to emulate.&#xA0;I&#x2019;ve&#xA0;learned about fixed vs. variable costs, how artisans had their knowledge crystalized within the assembly line process, and how and how amortized costs drove down prices, allowing the Ford Model T to exceed 900,000 units annually by the early 1920s. By that time, more than half of the registered automobiles in the world were Fords. Not half of American cars,&#xA0;<em>half of all cars on Earth.</em>&#xA0;</p><p>So what? Well, what took Ford Motor Company 17 years to achieve in cost and ceiling reductions, the AI industry has done in 2.5 years. The rapid and massive influx of investments, fierce competition, and available&#xA0;compute&#xA0;has shown what industrial organization means in a world where AI now almost permeates everything we see and touch. What does this mean for AI replacing jobs? Are we the artisans who move to the frontier of security? What does this mean for enabling threat actors who can move up a step to threatening others with tools developed using an AI corpus already trained on security? There are lots of questions, and to be honest, the future&#xA0;isn&#x2019;t&#xA0;clear here. One thing is for certain: We can look&#xA0;to&#xA0;the past to understand the future. Henry Ford said it best: &#x201C;Progress happens when all the factors that make for it are ready, and then it is inevitable.&#x201D;&#xA0;</p><p>As much as we tend to be myopic as security professionals and focus on our tradecraft, we are all part of a series of interconnected systems that&#xA0;lets&#xA0;humanity function. Learning those systems &#x2014; their quirks, their limitations, and their vulnerabilities &#x2014; makes you a better hacker. Stay curious, friends.&#xA0;</p><h2 id="the-one-big-thing">The one&#xA0;big thing&#xA0;</h2><p>Cisco Talos&#xA0;Incident Response (Talos IR)&#xA0;is sharing&#xA0;<a href="https://blog.talosintelligence.com/ir-trends-q1-2026/" rel="noreferrer noopener"><u>Q1 2026 incident response trends</u></a>. Phishing has officially reclaimed its crown as the top&#xA0;initial&#xA0;access vector. In a notable first, responders&#xA0;observed&#xA0;adversaries leveraging&#xA0;Softr, an AI-powered web development tool, to rapidly generate credential-harvesting pages. Meanwhile, actual ransomware deployments hit absolute zero this quarter thanks to swift mitigation&#xA0;by Talos IR, though pre-ransomware activity accounted for 18% of engagements this quarter.&#xA0;</p><h3 id="why-do-i-care">Why do I care?&#xA0;</h3><p>The barrier to entry for cybercriminals is plummeting, and they are increasingly using our own tools against us. The use of AI platforms to spin up phishing infrastructure means even unsophisticated actors can launch high-speed, code-free attacks. Furthermore, threat actors are abusing legitimate developer tools like&#xA0;TruffleHog&#xA0;and native cloud APIs to quietly hunt for exposed secrets, making detection incredibly difficult for defenders already struggling with logging gaps.&#xA0;</p><h3 id="so-now-what">So now what?&#xA0;</h3><p>It&#x2019;s&#xA0;time to get back to basics and lock down your perimeter. Organizations must implement properly configured multi-factor authentication (MFA), specifically restricting self-service enrollment to stop attackers from registering new devices. Defenders also need to prioritize robust patch management and ensure centralized logging via a SIEM is in&#xA0;place&#xA0;so forensic evidence&#xA0;remains&#xA0;intact. Read the&#xA0;<a href="https://blog.talosintelligence.com/ir-trends-q1-2026/" rel="noreferrer noopener"><u>full blog</u></a>&#xA0;for a deeper dive into this quarter&apos;s trends and adversary tactics.&#xA0;</p><h2 id="top-security-headlines-of-the-week">Top security headlines of the week&#xA0;</h2><p><strong>Third U.S.</strong>&#xA0;<strong>security</strong>&#xA0;<strong>expert</strong>&#xA0;<strong>admits</strong>&#xA0;<strong>helping</strong>&#xA0;<strong>ransomware</strong>&#xA0;<strong>gang</strong>&#xA0;<br>According to the Justice Department, Martino abused his role as a ransomware negotiator for five companies by providing the&#xA0;BlackCat/Alphv&#xA0;cybercrime group with information useful in negotiating a ransom payment. (<a href="https://www.securityweek.com/third-us-security-expert-admits-helping-ransomware-gang/" rel="noreferrer noopener"><u>SecurityWeek</u></a>)&#xA0;</p><p><strong>22</strong>&#xA0;<strong>BRIDGE:BREAK</strong>&#xA0;<strong>flaws expose thousands of</strong>&#xA0;<strong>Lantronix</strong>&#xA0;<strong>and Silex serial-to-IP converters</strong>&#xA0;<br>Successful exploitation of the&#xA0;flaws&#xA0;could allow attackers to disrupt serial communications with field assets, conduct lateral movement, and tamper with sensor values or&#xA0;modify&#xA0;actuator behavior. (<a href="https://thehackernews.com/2026/04/22-bridgebreak-flaws-expose-20000.html" rel="noreferrer noopener"><u>The Hacker News</u></a>)&#xA0;</p><p><strong>How hackers &#x201C;trojan-horsed&#x201D; QEMU virtual machines to bypass security and drop ransomware</strong>&#xA0;<br>In recent incidents, attackers used QEMU, an open-source machine emulator and&#xA0;virtualizer, to run hidden environments where malicious activity remained&#xA0;largely invisible&#xA0;to endpoint defenses and left minimal evidence on the host system. (<a href="https://www.techradar.com/pro/essentially-invisible-how-hackers-trojan-horsed-qemu-virtual-machines-to-bypass-security-and-drop-ransomware" rel="noreferrer noopener"><u>TechRadar</u></a>)&#xA0;</p><p><strong>Mastodon says its flagship server was hit by a DDoS attack</strong>&#xA0;<br>The&#xA0;cyber attack&#xA0;targeting Mastodon comes days after Bluesky, another decentralized social network, resolved much of&#xA0;its days-long&#xA0;outagesfollowing&#xA0;a lengthy DDoS attack. (<a href="https://techcrunch.com/2026/04/20/mastodon-says-its-flagship-server-was-hit-by-a-ddos-attack/" rel="noreferrer noopener"><u>TechCrunch</u></a>)&#xA0;</p><p><strong>Exploits turn Windows Defender into attacker tool</strong>&#xA0;<br>Threat actors are using three publicly available proof-of-concept exploits (two are unpatched) to attack Microsoft Defender and turn the security platform&apos;s primary cleanup and protection functions against organizations it is designed to protect. (<a href="https://www.darkreading.com/cyberattacks-data-breaches/exploits-turn-windows-defender-attacker-tool" rel="noreferrer noopener"><u>Dark Reading</u></a>)&#xA0;</p><h2 id="can%E2%80%99t-get-enough-talos">Can&#x2019;t&#xA0;get enough Talos?&#xA0;</h2><p><a href="https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/" rel="noreferrer noopener"><strong><u>Bad Apples: Weaponizing native macOS primitives for movement and execution</u></strong></a>&#xA0;<br>Talos documented several macOS living-off-the-land (LOTL) techniques,&#xA0;demonstrating&#xA0;that native pathways for movement and execution remain accessible to those who understand the underlying architecture.&#xA0;</p><p><a href="https://www.youtube.com/watch?v=wppL7JBshK8&amp;list=PLpPXZRVU-dX0r-hvoVuVa53GNgyAJ_4Ad" rel="noreferrer noopener"><strong><u>AI phishing, fake CAPTCHA, and real-world cyber threat trends</u></strong></a>&#xA0;<br>The Talos team breaks down findings from Q1 2026 &#x2014; including phishing returning as the top&#xA0;initial&#xA0;access vector, and how attackers are using AI tools to build credential harvesting campaigns in almost no time at all.&#xA0;</p><p><a href="https://blog.talosintelligence.com/uat-4356-firestarter/" rel="noreferrer noopener"><strong><u>UAT-4356&apos;s targeting of Cisco Firepower devices</u></strong></a><strong>&#xA0;</strong>&#xA0;<br>UAT-4356&#xA0;exploited&#xA0;n-day vulnerabilities&#xA0;(CVE-2025-20333&#xA0;and&#xA0;CVE-2025-20362)&#xA0;to gain unauthorized access to vulnerable devices,&#xA0;where the threat actor deployed&#xA0;their custom-built&#xA0;backdoor&#xA0;dubbed &#x201C;FIRESTARTER.&#x201D;&#xA0;</p><h2 id="upcoming-events-where-you-can-find-talos">Upcoming events where you can find Talos&#xA0;</h2><ul><li><a href="https://pivotcon.org/" rel="noreferrer noopener"><u>PIVOTcon</u></a>&#xA0;(May 6 &#x2013; 8) M&#xE1;laga, Spain&#xA0;</li><li><a href="https://www.offensivecon.org/" rel="noreferrer noopener"><u>OffensiveCon</u></a>&#xA0;(May 15 &#x2013; 16)&#xA0;Berlin, Germany&#xA0;</li><li><a href="https://www.ciscolive.com/global.html?zid=pp" rel="noreferrer noopener"><u>Cisco Live U.S.</u></a>&#xA0;(May 31&#xA0;&#x2013;&#xA0;June 4) Las Vegas, Nevada&#xA0;</li></ul><h2 id="most-prevalent-malware-files-from-talos-telemetry-over-the-past-week">Most prevalent malware files from Talos telemetry over the past week&#xA0;</h2><p><strong>SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507</strong>&#xA0;<br>MD5: 2915b3f8b703eb744fc54c81f4a9c67f&#xA0;<br>Talos Rep:&#xA0;<a href="https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507" rel="noreferrer noopener"><u>https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507</u></a>&#xA0;<br>Example Filename:&#xA0;VID001.exe&#xA0;<br>Detection Name:&#xA0;Win.Worm.Coinminer::1201&#xA0;</p><p><strong>SHA256: 96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974</strong>&#xA0;<br>MD5: aac3165ece2959f39ff98334618d10d9&#xA0;<br>Talos Rep:&#xA0;<a href="https://talosintelligence.com/talos_file_reputation?s=96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974" rel="noreferrer noopener"><u>https://talosintelligence.com/talos_file_reputation?s=96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974</u></a>&#xA0;<br>Example Filename: d4aa3e7010220ad1b458fac17039c274_63_Exe.exe&#xA0;<br>Detection Name:&#xA0;W32.Injector:Gen.21ie.1201&#xA0;</p><p><strong>SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59</strong>&#xA0;<br>MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a&#xA0;<br>Talos Rep:&#xA0;<a href="https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59" rel="noreferrer noopener"><u>https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59</u></a>&#xA0;<br>Example Filename: APQ9305.dll&#xA0;<br>Detection Name: Auto.90B145.282358.in02&#xA0;</p><p><strong>SHA256: 5e6060df7e8114cb7b412260870efd1dc05979454bd907d8750c669ae6fcbcfe</strong>&#xA0;<br>MD5: a2cf85d22a54e26794cbc7be16840bb1&#xA0;<br>Talos Rep:&#xA0;<a href="https://talosintelligence.com/talos_file_reputation?s=5e6060df7e8114cb7b412260870efd1dc05979454bd907d8750c669ae6fcbcfe" rel="noreferrer noopener"><u>https://talosintelligence.com/talos_file_reputation?s=5e6060df7e8114cb7b412260870efd1dc05979454bd907d8750c669ae6fcbcfe</u></a>&#xA0;<br>Example Filename: a2cf85d22a54e26794cbc7be16840bb1.exe&#xA0;<br>Detection Name: W32.5E6060DF7E-100.SBX.TG&#xA0;</p><p><strong>SHA256: 3c1dbc3f56e91cc79f0014850e773a7f12bbfef06680f08f883b2bf12873eccc</strong>&#xA0;<br>MD5: d749e0f8f2cd4e14178a787571534121&#xA0;<br>Talos Rep:&#xA0;<a href="https://talosintelligence.com/talos_file_reputation?s=3c1dbc3f56e91cc79f0014850e773a7f12bbfef06680f08f883b2bf12873eccc" rel="noreferrer noopener"><u>https://talosintelligence.com/talos_file_reputation?s=3c1dbc3f56e91cc79f0014850e773a7f12bbfef06680f08f883b2bf12873eccc</u></a>&#xA0;<br>Example&#xA0;Filename: KitchenCanvas_753447.exe&#xA0;<br>Detection Name: W32.3C1DBC3F56-90.SBX.TG&#xA0;</p>]]></content:encoded></item><item><title><![CDATA[UAT-4356's Targeting of Cisco Firepower Devices]]></title><description><![CDATA[Cisco Talos is aware of UAT-4356's continued active targeting of Cisco Firepower devices’ Firepower eXtensible Operating System (FXOS). UAT-4356 exploited n-day vulnerabilities (CVE-2025-20333 and CVE-2025-20362) to gain unauthorized access to vulnerable devices.]]></description><link>https://blog.talosintelligence.com/uat-4356-firestarter/</link><guid isPermaLink="false">69e058a6645a220001422b4d</guid><category><![CDATA[Threat Advisory]]></category><category><![CDATA[Threats]]></category><category><![CDATA[APT]]></category><category><![CDATA[Cisco Talos Network Intrusion Prevention]]></category><category><![CDATA[Cisco Talos Antivirus]]></category><category><![CDATA[Cisco Talos Malware Protection]]></category><dc:creator><![CDATA[Cisco Talos]]></dc:creator><pubDate>Thu, 23 Apr 2026 15:10:57 GMT</pubDate><media:content url="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/arcane_door.jpg" medium="image"/><content:encoded><![CDATA[<img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/arcane_door.jpg" alt="UAT-4356&apos;s Targeting of Cisco Firepower Devices"><p>Cisco Talos is aware of <a href="https://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/">UAT-4356</a>&apos;s continued <a href="https://cisa.gov/news-events/directives/v1-ed-25-03-identify-and-mitigate-potential-compromise-cisco-devices" rel="noreferrer">active targeting</a> of Cisco Firepower devices&#x2019; Firepower eXtensible Operating System (FXOS). UAT-4356 exploited n-day vulnerabilities (<a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-z5xP8EUB">CVE-2025-20333</a> and <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-YROOTUW">CVE-2025-20362</a>) to gain unauthorized access to vulnerable devices, where the threat actor deployed their custom-built backdoor dubbed &#x201C;FIRESTARTER.&#x201D; FIRESTARTER considerably overlaps with the technical capabilities of <a href="https://www.ncsc.gov.uk/sites/default/files/documents/ncsc-mar-rayinitiator-line-viper.pdf">RayInitiator&#x2019;s Stage 3 shellcode</a> that processes incoming XML-based payloads to endpoint APIs.</p><p>In early 2024, Cisco Talos attributed <a href="https://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/">ArcaneDoor</a>, a state-sponsored campaign focused on gaining access to network perimeter devices for espionage, to UAT-4356.</p><p>Customers are advised to refer to <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-persist-CISAED25-03">Cisco&#x2019;s Security Advisory</a> for mitigation and detection guidance, indicators of compromise (IOCs), affected products, and applicable software upgrade recommendations.</p><hr><h2 id="the-firestarter-backdoor">The FIRESTARTER backdoor</h2><p>FIRESTARTER is a malicious backdoor implanted by UAT-4356 that allows remote access and control to execute arbitrary code inside the LINA process, a core component of Cisco&#x2019;s ASA and FTD appliances running FXOS.</p><h3 id="persistence">Persistence</h3><p>UAT-4356 established persistence for FIRESTARTER on compromised devices by manipulating the mount list for Cisco Service Platform (CSP), namely &#x201C;CSP_MOUNT_LIST&#x201D;, to execute FIRESTARTER. The mount list allows programs and commands to be executed as part of the device&#x2019;s boot sequence. The persistence mechanism triggers during graceful reboot (i.e., when a process termination signal is received). FIRESTARTER also checks the runlevel for value 6 (indicating device reboot) and in case of a match, writes itself to backup location &#x201C;/opt/cisco/platform/logs/var/log/svc_samcore.log&quot; and updates the CSP_MOUNT_LIST to copy itself back to &#x201C;/usr/bin/lina_cs&#x201D; and then be executed. When FIRESTARTER runs after a reboot, it restores the original CSP_MOUNT_LIST and removes the trojanized copy. Because the runlevel triggers establishment of this transient persistence mechanism, a hard reboot (for example, after the device has been unplugged from power) effectively removes the implant from the device.</p><p>FIRESTARTER has used the following commands to establish persistence for itself using the transient persistence mechanism:</p><figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/data-src-image-d095a102-ece8-4d0a-9d5a-16ba6d021264.png" class="kg-image" alt="UAT-4356&apos;s Targeting of Cisco Firepower Devices" loading="lazy" width="937" height="573" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/data-src-image-d095a102-ece8-4d0a-9d5a-16ba6d021264.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/data-src-image-d095a102-ece8-4d0a-9d5a-16ba6d021264.png 937w" sizes="(min-width: 720px) 720px"></figure><p>When the implant injects itself into the LINA process, it removes the traces of its persistence mechanism by restoring the CSP_MOUNT_LIST from a temporary copy (&#x201C;CSP_MOUNTLIST.tmp&#x201D;), then removing the temporary copy and the FIRESTARTER file from disk (&#x201C;/usr/bin/lina_cs&#x201D;).</p><h3 id="firestarter%E2%80%99s-backdoor-capabilities">FIRESTARTER&#x2019;s backdoor capabilities</h3><p>FIRESTARTER can run arbitrary shellcode received by the device. A pre-defined handler function specified by a hardcoded offset in the LINA process&#x2019; memory is replaced by an unauthorized handler routine that parses the data being served to it. FIRESTARTER specifically looks for a WebVPN request XML. If the request data received matches a specific pattern of custom-defined prefixing then the shellcode that immediately follows it is executed in memory. If the prefixing bytes are not found, then the data is treated as regular request data and passed to the original handler function (if any).</p><p>FIRESTARTER&#x2019;s loading mechanism, Stage 2 shellcode (i.e., the actual request handler component), handler function replacement, XML parsing for magic bytes, and final payload execution display considerable overlaps with <a href="https://www.ncsc.gov.uk/sites/default/files/documents/ncsc-mar-rayinitiator-line-viper.pdf">RayInitiator&#x2019;s Stage 3</a> deployment actions and accompanying artifacts.</p><h3 id="injecting-and-activating-the-malicious-shellcode-in-lina">Injecting and activating the malicious shellcode in LINA</h3><p>FIRESTARTER first reads the LINA process&#x2019; memory to search for and verify the presence of the bytes (long) 0x1, 0x2, 0x3, 0x4, 0x5 at specific locations in memory. If found, FIRESTARTER will then query the process&#x2019; memory to find an &#x201C;r-xp&#x201D; memory range for the shared library &#x201C;libstdc++.so&#x201D;. It then copies the next stage shellcode (Stage 2) to the last 0x200 bytes of the memory region. FIRESTARTER then overwrites an internal data structure in the LINA process&#x2019; memory to replace a pointer to a WebVPN-specific, legitimate XML handler function with the address of the malicious Stage 2 shellcode.</p><p>The malicious shellcode is triggered as part of the authentication API&#x2019;s request handling process and parses the incoming request data for magic markers signifying an executable payload. If found, the executable payload is then executed on the compromised device.</p><hr><h2 id="detection-guidance">Detection guidance</h2><p>The presence of the following artifacts - specifically the filenames &#x201C;lina_cs&#x201D; and &#x201C;svc_samcore.log&#x201D; - though somewhat brittle indicators, may indicate the presence of the FIRESTARTER on a Firepower device:</p><ul><li>Any output from the commands:<ul><li>show kernel process | include lina_cs</li></ul></li><li>The presence of the following files on disk:<ul><li>/usr/bin/lina_cs</li><li>/opt/cisco/platform/logs/var/log/svc_samcore.log</li></ul></li></ul><p>For more comprehensive detection guidance, please refer to <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-persist-CISAED25-03">Cisco&#x2019;s Security Advisory here</a>. Please also refer to CISA&#x2019;s update to V1: <a href="https://cisa.gov/news-events/directives/v1-ed-25-03-identify-and-mitigate-potential-compromise-cisco-devices" rel="noreferrer">Emergency Directive (ED) 25-03</a>: Identify and Mitigate Potential Compromise of Cisco Devices and <a href="https://www.cisa.gov/news-events/analysis-reports/ar26-113a">FIRESTARTER Backdoor Malware Analysis Report</a> for more information and guidance.</p><p>&#xA0;</p><h2 id="mitigation-and-coverage">Mitigation and coverage</h2><p>We recommend that Cisco customers follow the steps recommended in <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-persist-CISAED25-03">Cisco&apos;s advisory</a>, with particular attention to any applicable software upgrade recommendations. Organizations impacted can initiate a <a href="https://www.cisco.com/c/en/us/support/index.html">TAC request</a> for Cisco support.</p><p>A FIRESTARTER infection may be mitigated on all affected devices by reimaging the devices.</p><p>On Cisco FTD software that is not in lockdown mode, there is also the option of killing the lina_cs process then reloading the device:</p>
<!--kg-card-begin: html-->
<pre>
&gt; expert
$ sudo kill -9 $(pidof lina_cs)
$ exit
&gt; reboot
</pre>
<!--kg-card-end: html-->
<p>Open-source Snort Subscriber Rule Set customers can stay up to date by downloading the latest rule pack available for purchase on <a href="https://www.snort.org/products">Snort.org</a>.</p><p>The following Snort rules cover the vulnerabilities <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-z5xP8EUB">CVE-2025-20333</a> and <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-YROOTUW">CVE-2025-20362</a>: <strong>65340, 46897</strong>.</p><p>Snort rules covering FIRESTARTER: <strong>62949</strong></p><p>The following ClamAV signatures detect this threat: <strong>Unix.Malware.Generic-10059965-0</strong></p>]]></content:encoded></item><item><title><![CDATA[IR Trends Q1 2026: Phishing reemerges as top initial access vector, as attacks targeting public administration persist]]></title><description><![CDATA[Phishing reemerged as the most observed means of gaining initial access, accounting for over a third of the engagements where initial access could be determined. Phishing has not been the top vertical for initial access since Q2 2025.]]></description><link>https://blog.talosintelligence.com/ir-trends-q1-2026/</link><guid isPermaLink="false">69e61dd4645a220001422ba1</guid><category><![CDATA[Talos IR trends]]></category><category><![CDATA[CTIR trends]]></category><dc:creator><![CDATA[Aliza Johnson]]></dc:creator><pubDate>Wed, 22 Apr 2026 10:00:34 GMT</pubDate><media:content url="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/TalosIR_quarterly_trends.jpg" medium="image"/><content:encoded><![CDATA[<ul><li>Phishing reemerged as the most observed means of gaining initial access, accounting for over a third of the engagements where&#xA0;initial&#xA0;access could be&#xA0;determined.&#xA0;Phishing&#xA0;has not been the top vector for&#xA0;initial&#xA0;access since Q2 2025.</li><li>Public administration and health&#xA0;care&#xA0;tied&#xA0;as the most targeted industry verticals, each accounting for 24&#xA0;percent&#xA0;of all engagements. This is the third consecutive quarter where public administration has been the most targeted industry&#xA0;vertical.&#xA0;&#xA0;</li><li>Pre-ransomware incidents made up just 18&#xA0;percent&#xA0;of engagements this quarter, and we did not&#xA0;observe&#xA0;any ransomware deployment due to early and swift mitigation from&#xA0;Cisco&#xA0;Talos Incident Response (Talos IR). This is a slight increase from last quarter but&#xA0;overall&#xA0;very low&#xA0;compared to Q1 and Q2 2025, when we&#xA0;observed&#xA0;ransomware in 50&#xA0;percent&#xA0;of engagements.</li></ul><hr><figure class="kg-card kg-embed-card kg-card-hascaption"><iframe width="200" height="113" src="https://www.youtube.com/embed/wppL7JBshK8?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen title="The TTP 23: AI Phishing, Fake CAPTCHA &amp; Real-World Cyber Threat Trends (Q1 2026)"></iframe><figcaption><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/TalosIR_quarterly_trends.jpg" alt="IR Trends Q1 2026: Phishing reemerges as top initial access vector, as attacks targeting public administration persist"><p><span style="white-space: pre-wrap;">Watch this video to see Talos experts break down the trends and offer guidance for defenders.</span></p></figcaption></figure><h2 id="ai-tool-leveraged-in-phishing-campaign">AI tool&#xA0;leveraged&#xA0;in phishing campaign&#xA0;</h2><p>Talos IR responded to a campaign that&#xA0;leveraged&#xA0;phishing,&#xA0;the most common means of&#xA0;initial&#xA0;access this quarter, to compromise the most targeted industry vertical this quarter:&#xA0;public administration. Notably, the actors&#xA0;leveraged&#xA0;the&#xA0;Softr AI-based web application development service, marking the first time we have documented the use of a specific AI tool by an adversary in a phishing campaign.&#xA0;Softr&#xA0;was used to generate a credential harvesting page targeting users&#x2019; Microsoft Exchange and Outlook Web Access (OWA) accounts.&#xA0;</p><p>State-sponsored and criminal actors have been&#xA0;observed&#xA0;abusing large language models (LLMs) to aid in the development of phishing lures, malicious scripts, and other tasks. DDoS-as-a-service actors have adopted AI algorithms for defense evasion and attack orchestration. While this is the first time we have documented the use of a specific AI tool in a Talos IR incident, we have moderate confidence that malicious actors have used&#xA0;Softr&#x2019;s&#xA0;AI-powered web application creation platform since at May 2023, based on Cisco Umbrella data and other telemetry, and have done so with increasing frequency to date.&#xA0;&#xA0;&#xA0;&#xA0;</p><p>This incident&#xA0;demonstrates&#xA0;how AI tools can lower the barrier to entry for less sophisticated actors and/or accelerate the speed of phishing and credential-harvesting campaigns. Using a form template and the &#x201C;vibe coding&#x201D; feature, a phishing page like the one used in this attack could be quickly created with a few AI prompts and no code. Phishing pages built with&#xA0;Softr&#xA0;can direct data to a disposable external data store, such as Google Sheets, and send alerts for new captures via email&#xA0;&#x2014;&#xA0;all without code.&#xA0;&#xA0;&#xA0;&#xA0;</p><h2 id="crimson-collective-seen-for-the-first-time">Crimson Collective seen for the first time&#xA0;&#xA0;&#xA0;</h2><p>Talos IR experienced its first case involving Crimson Collective, a cyber extortion group that appeared in September 2025. This attack highlighted&#xA0;the use of valid accounts for&#xA0;initial&#xA0;access, the second&#xA0;most commonly&#xA0;observed&#xA0;means of&#xA0;initial&#xA0;access this quarter. This attack also notably involved targeting exploit weaknesses, the second-most observed security weakness, accounting for 25&#xA0;percent&#xA0;of all engagements.&#xA0;We attribute this activity to Crimson Collective based on IPs associated with the group that were used to scan the victim&apos;s ASA firewalls, as well as an overlap of observed tactics and techniques with publicly reported Crimson Collective attacks.&#xA0;</p><p>The incident began when a GitHub Personal Access Token (PAT) was inadvertently published on a public-facing&#xA0;website, exposing the organization to adversaries for several months. Upon obtaining access, the adversary used&#xA0;TruffleHog, an open-source tool commonly&#xA0;utilized&#xA0;by security professionals, to scan thousands of&#xA0;victim&#xA0;GitHub repositories for&#xA0;additional&#xA0;secrets and sensitive information. This approach allows attackers to perform reconnaissance without triggering suspicion, as they are&#xA0;leveraging&#xA0;standard, legitimate tools. The attacker&#x2019;s discovery of client secrets through&#xA0;TruffleHog&#xA0;enabled further access to&#xA0;the victim&#x2019;s&#xA0;Azure cloud storage, where they used Microsoft Graph API calls to authenticate, explore, and exfiltrate data. The abuse of legitimate cloud APIs&#xA0;demonstrates&#xA0;a growing trend where threat actors use native platform functionality to blend into normal user activity, making detection more challenging.&#xA0;</p><p>In addition to exfiltrating data, the adversary&#xA0;attempted&#xA0;to inject malicious code into multiple GitHub repositories. This code was designed to harvest any new secrets committed in the future, sending them to adversary-controlled infrastructure. Though these attempts were&#xA0;largely thwarted&#xA0;by the&#xA0;expiration&#xA0;of targeted secrets and effective security controls, the tactic reflects an emerging trend of supply chain and development environment attacks.&#xA0;&#xA0;</p><h2 id="ransomware-trends">Ransomware trends&#xA0;</h2><h3 id="ransomware-experiences-slight-increase-remains-low-overall">Ransomware experiences slight increase,&#xA0;remains&#xA0;low overall&#xA0;&#xA0;</h3><p>Pre-ransomware incidents made up just 18 percent of engagements this quarter, and we did not&#xA0;observe&#xA0;any ransomware&#xA0;encryption&#xA0;due to early and swift mitigation from Talos IR. This is a slight increase from last quarter, when ransomware and pre-ransomware collectively&#xA0;comprised&#xA0;13 percent of engagements, but&#xA0;overall&#xA0;very low&#xA0;compared to Q1 and Q2 2025, when we&#xA0;observed&#xA0;ransomware in 50 percent of engagements. Attribution is challenging in pre-ransomware events&#xA0;because&#xA0;there are no encryptors or ransom notes, but we assess that&#xA0;Rhysida&#xA0;ransomware and&#xA0;MoneyMessage&#xA0;ransomware accounted for two of the engagements.&#xA0;</p><p>While we did not&#xA0;observe&#xA0;many active and prolific ransomware-as-a-service (RaaS) operations, like&#xA0;Qilin&#xA0;or Akira, this&#xA0;likely does&#xA0;not&#xA0;indicate&#xA0;these major players are decreasing operations, as their data leak sites&#xA0;remain&#xA0;consistently active.&#xA0;&#xA0;&#xA0;&#xA0;</p><h3 id="rhysida-ransomware-actors-use-uncommon-backdoor-meowbackconn">Rhysida&#xA0;ransomware actors use&#xA0;uncommon backdoor,&#xA0;Meowbackconn&#xA0;&#xA0;</h3><p>Talos&#xA0;IR&#xA0;responded to a ransomware incident where the adversary&#xA0;attempted&#xA0;to deploy&#xA0;Rhysida&#xA0;ransomware. While the attack was mitigated in the pre-ransomware stage, we attribute this activity with moderate confidence to&#xA0;Rhysidabased on observed infrastructure that is associated with&#xA0;Rhysida&#xA0;activity and the use of&#xA0;Gootloader, which is commonly&#xA0;leveraged&#xA0;in&#xA0;Rhysida&#xA0;attacks during&#xA0;initial&#xA0;access.&#xA0;Notably, the actors deployed proxy-related DLLs (e.g.,&#xA0;&#x201C;meow_eu.dll&#x201D;), which we assess were&#xA0;likely related&#xA0;to&#xA0;MeowBackConn, an uncommon backdoor that is&#xA0;closely associated&#xA0;with&#xA0;Gootloader, based on public reporting.&#xA0;</p><p>This attack&#xA0;represents&#xA0;several trends that we&#xA0;observed&#xA0;throughout Talos IR engagements in Q1 2026.&#xA0;The environmental weaknesses that enabled this intrusion &#x2014; exposed&#xA0;WinRM&#xA0;management ports, over-privileged service accounts, and critical logging gaps &#x2014; directly echo this quarter&#x2019;s most prominent security weaknesses, including vulnerable or exposed infrastructure, accounting for 25 percent of engagements. Furthermore, the adversary&#x2019;s use of&#xA0;Remote Desktop Protocol (RDP)&#xA0;for lateral movement is consistent with RDP being the top technique for lateral movement for the previous two quarters (Q3 and Q4 2025).</p><h3 id="targeting">Targeting</h3><figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Q1dark_Q4Targets-dark-1-.jpg" class="kg-image" alt="IR Trends Q1 2026: Phishing reemerges as top initial access vector, as attacks targeting public administration persist" loading="lazy" width="2000" height="777" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Q1dark_Q4Targets-dark-1-.jpg 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Q1dark_Q4Targets-dark-1-.jpg 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Q1dark_Q4Targets-dark-1-.jpg 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w2400/2026/04/Q1dark_Q4Targets-dark-1-.jpg 2400w" sizes="(min-width: 720px) 720px"></figure><p>Public administration and health&#xA0;care were tied as the most targeted industry verticals. Notably, Q3 2025 marked the first time public administration&#xA0;emerged&#xA0;as the most targeted sector in Talos IR engagements, and it has&#xA0;retained&#xA0;that position since.&#xA0;Organizations within the public administration sector are attractive targets as they are often underfunded and use legacy equipment. These entities may have access to sensitive data as well as a low downtime tolerance, making them attractive to financially motivated and espionage-focused threat groups.</p><h3 id="initial-access">Initial access</h3><figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Q1dark_Q4InfectionVectors-dark.jpg" class="kg-image" alt="IR Trends Q1 2026: Phishing reemerges as top initial access vector, as attacks targeting public administration persist" loading="lazy" width="1875" height="712" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Q1dark_Q4InfectionVectors-dark.jpg 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Q1dark_Q4InfectionVectors-dark.jpg 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Q1dark_Q4InfectionVectors-dark.jpg 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Q1dark_Q4InfectionVectors-dark.jpg 1875w" sizes="(min-width: 720px) 720px"></figure><p>Phishing reemerged as the most observed means of gaining initial access, accounting for over a third of the engagements where&#xA0;initial&#xA0;access could be&#xA0;determined. Phishing was the top&#xA0;initial&#xA0;access vector in the first half of 2025, at which point it was surpassed by exploitation of public-facing applications,&#xA0;likely due to&#xA0;the widespread exploitation of vulnerabilities in on-premises Microsoft SharePoint servers, collectively referred to as&#xA0;ToolShell. Since then, we have&#xA0;observeda steady decrease in the exploitation of public-facing applications as&#xA0;an initial&#xA0;access vector from a high of 62 percent to only 18 percent in Q1 2026. Similarly, in this quarter, valid accounts returned to its pre-ToolShell&#xA0;baseline as the second most&#xA0;observed&#xA0;means of gaining initial access,&#xA0;comprising&#xA0;24 percent of Talos IR engagements. We assess the decline in&#xA0;ToolShell&#xA0;exploitation&#xA0;is&#xA0;likely due to the widespread availability of emergency patches and enhanced security detections, highlighting the importance of&#xA0;timely&#xA0;patching.</p><h2 id="recommendations-for-addressing-top-security-weaknesses">Recommendations for addressing top security weaknesses</h2><figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Q1dark_Q4SecurityWeakness-dark.jpg" class="kg-image" alt="IR Trends Q1 2026: Phishing reemerges as top initial access vector, as attacks targeting public administration persist" loading="lazy" width="1875" height="711" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Q1dark_Q4SecurityWeakness-dark.jpg 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Q1dark_Q4SecurityWeakness-dark.jpg 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Q1dark_Q4SecurityWeakness-dark.jpg 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Q1dark_Q4SecurityWeakness-dark.jpg 1875w" sizes="(min-width: 720px) 720px"></figure><h3 id="implement-properly-configured-mfa-and-other-access-control-solutions">Implement properly configured MFA and other access control solutions&#xA0;&#xA0;</h3><p>35 percent of engagements this quarter involved&#xA0;multi-factor authentication (MFA)&#xA0;weaknesses, an increase from last quarter. This includes incidents where threat actors bypassed MFA and where MFA was either missing or only partially enabled, particularly on remote access services. Adversaries were able to bypass MFA by registering new devices to previously compromised accounts, and in one instance, by configuring Outlook clients to connect directly to Exchange servers, circumventing MFA requirements. Addressing these weaknesses, especially by restricting self-service MFA enrollment and enforcing strong, centralized authentication policies, is essential to reducing risk and strengthening organizational resilience.&#xA0;</p><h3 id="conduct-robust-patch-management">Conduct robust patch management&#xA0;&#xA0;&#xA0;</h3><p>Vulnerable or exposed infrastructure was another top security weakness accounting for 25 percent of all engagements, a slight decrease from last quarter. This included exploiting a vulnerability (CVE-2025-20393) in the Spam Quarantine feature of Cisco&#xA0;AsyncOS&#xA0;Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager, as well as&#xA0;a&#xA0;vulnerability (CVE-2023-20198) in the web UI feature in Cisco IOS XE Software.&#xA0;Talos&#xA0;also&#xA0;observed&#xA0;exposed management ports (such as&#xA0;WinRM&#xA0;open to the internet), which enabled rapid attacker movement and reconnaissance.&#xA0;&#xA0;</p><h3 id="configure-centralized-logging-capabilities-across-the-environment">Configure centralized logging capabilities across the environment&#xA0;&#xA0;&#xA0;</h3><p>Finally, 18 percent of engagements this quarter involved organizations with insufficient logging capabilities, which&#xA0;hindered investigative efforts. Understanding the full context and chain of events performed by an adversary on a targeted host is vital not only for remediation but also for enhancing defenses and addressing any system vulnerabilities for the future. To address this issue, Talos IR recommends organizations implement a&#xA0;security&#xA0;information and&#xA0;event&#xA0;management (SIEM) solution for centralized logging. In the event an adversary&#xA0;deletes&#xA0;or modifies logs on the host, the SIEM will&#xA0;contain&#xA0;the original logs to support a forensics investigation.&#xA0;Additionally,&#xA0;Talos IR&#xA0;offers&#xA0;a&#xA0;<a href="https://talosintelligence.com/incident_response/assessment" rel="noreferrer noopener"><u>Log Architecture Assessment</u></a>&#xA0;service, which&#xA0;provides a focused review of an organization&#x2019;s logs and overall log strategy to&#xA0;identify&#xA0;gaps&#xA0;and&#xA0;offer recommendations that give a complete view of the security environment and strengthen incident response readiness&#xA0;</p><h2 id="mitre-attck-appendix">MITRE ATT&amp;CK appendix&#xA0;</h2><p>The tables&#xA0;below&#xA0;represent&#xA0;the MITRE ATT&amp;CK techniques&#xA0;observed&#xA0;in this quarter&#x2019;s IR engagements and&#xA0;includes&#xA0;relevant examples and the number of times seen. Given that some techniques can fall under multiple tactics, we grouped them under the most relevant tactic based on the way they were&#xA0;leveraged. Please note&#xA0;that&#xA0;this is not an exhaustive list.&#xA0;</p><p>Key findings from the MITRE ATT&amp;CK framework include:&#xA0;</p><ul><li>Phishing was the top method of&#xA0;initial&#xA0;access, replacing exploitation of public-facing applications which was dominant in the prior two quarters.&#xA0;</li><li>Web-based&#xA0;C2&#xA0;was the most common C2 pattern. Application Layer Protocol over web protocols was&#xA0;observed&#xA0;most often,&#xA0;indicating&#xA0;adversaries&#xA0;frequently&#xA0;blended C2 into normal-looking traffic.&#xA0;</li><li>Lateral movement primarily relied on common remote administration channels. SMB/Windows Admin Shares was the top lateral movement technique, with WMI and RDP also heavily used, suggesting attackers repeatedly&#xA0;leveragedstandard enterprise remote management paths once inside. RDP was the top technique for lateral movement in the prior two quarters.&#xA0;&#xA0;</li><li>Defense evasion&#xA0;frequently&#xA0;focused on weakening visibility and endpoint protections. Impair defenses by disabling/modifying&#xA0;tools appeared multiple times, alongside log/trace reduction behaviors (e.g., clear command history and file deletion),&#xA0;indicating&#xA0;a recurring emphasis on reducing detection and forensic evidence.</li></ul>
<!--kg-card-begin: html-->
<table class="Table Ltr TableWordWrap SCXW67619765 BCX4" border="1" dir="ltr" data-tablestyle="MsoTableGrid" data-tablelook="0" aria-rowcount="49" style="font-style: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-line: none; text-decoration-thickness: auto; text-decoration-style: solid; -webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; table-layout: fixed; width: 1px; border-collapse: collapse; empty-cells: show; position: relative; overflow: visible; caret-color: rgba(0, 0, 0, 0.847); color: rgba(0, 0, 0, 0.847); font-family: &quot;Segoe UI&quot;, &quot;Segoe UI Web&quot;, Arial, Verdana, sans-serif; font-size: 12px; background: none; border-spacing: 0px;"><tbody class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text;"><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="1" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstRow FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="14432388" paraeid="{09772ea6-c54d-4dc0-bb20-bb5c3a18251a}{168}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" data-ccp-parastyle-defn="{&quot;ObjectId&quot;:&quot;bc8d283f-51d9-50bc-8589-5a201f143310|1&quot;,&quot;ClassId&quot;:1073872969,&quot;Properties&quot;:[201342446,&quot;1&quot;,201342447,&quot;5&quot;,201342448,&quot;3&quot;,201342449,&quot;1&quot;,469777841,&quot;CiscoSansTT&quot;,469777842,&quot;Arial&quot;,469777843,&quot;&#xFF2D;&#xFF33; &#x660E;&#x671D;&quot;,469777844,&quot;CiscoSansTT&quot;,201341986,&quot;1&quot;,469769226,&quot;CiscoSansTT&quot;,268442635,&quot;20&quot;,469775450,&quot;Table Header&quot;,201340122,&quot;2&quot;,134234082,&quot;true&quot;,134233614,&quot;true&quot;,469778129,&quot;TableHeader&quot;,335572020,&quot;1&quot;,134224900,&quot;true&quot;,335551500,&quot;16777215&quot;,335559738,&quot;288&quot;,469775498,&quot;Table Body&quot;,469778324,&quot;Normal&quot;]}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Tactic</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="FirstRow SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1043741759" paraeid="{a9a68ea3-c81b-4b6a-99aa-871d128d7233}{243}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Technique</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0,&quot;335559737&quot;:0,&quot;335559738&quot;:288,&quot;335559739&quot;:0,&quot;335559740&quot;:240}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="FirstRow SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="600024864" paraeid="{6df0c8d5-ced1-41b8-82d4-3fb270aacd2b}{171}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Example</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="FirstRow LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="728990158" paraeid="{6df0c8d5-ced1-41b8-82d4-3fb270aacd2b}{178}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Estimated times observed&#xA0;</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="2" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1134762312" paraeid="{09772ea6-c54d-4dc0-bb20-bb5c3a18251a}{172}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" data-ccp-parastyle-defn="{&quot;ObjectId&quot;:&quot;687983a9-1aa9-55f0-9007-1526daa5aaeb|1&quot;,&quot;ClassId&quot;:1073872969,&quot;Properties&quot;:[201342446,&quot;1&quot;,201342447,&quot;5&quot;,201342448,&quot;3&quot;,201342449,&quot;1&quot;,469777841,&quot;CiscoSansTT Light&quot;,469777842,&quot;Arial&quot;,469777843,&quot;&#xFF2D;&#xFF33; &#x660E;&#x671D;&quot;,469777844,&quot;CiscoSansTT Light&quot;,201341986,&quot;1&quot;,469769226,&quot;CiscoSansTT Light&quot;,268442635,&quot;20&quot;,469775450,&quot;Table Body&quot;,201340122,&quot;2&quot;,134234082,&quot;true&quot;,134233614,&quot;true&quot;,469778129,&quot;TableBody&quot;,335572020,&quot;1&quot;,134234072,&quot;true&quot;,335559740,&quot;276&quot;,201341983,&quot;0&quot;,335559739,&quot;120&quot;,335559738,&quot;120&quot;,335551550,&quot;6&quot;,335551620,&quot;6&quot;,469778324,&quot;Normal&quot;]}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Reconnaissance</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1190228782" paraeid="{6df0c8d5-ced1-41b8-82d4-3fb270aacd2b}{186}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1589.002: Gather Victim Identity Information: Email Addresses</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1076700468" paraeid="{6df0c8d5-ced1-41b8-82d4-3fb270aacd2b}{193}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">enumerated</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">internal processes and<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">identified</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">vendor emails to<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">facilitate</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>their fraudulent ordering scheme.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="638601473" paraeid="{6df0c8d5-ced1-41b8-82d4-3fb270aacd2b}{200}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="3" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="469334538" paraeid="{09772ea6-c54d-4dc0-bb20-bb5c3a18251a}{176}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1710829801" paraeid="{6df0c8d5-ced1-41b8-82d4-3fb270aacd2b}{208}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1595: Active Scanning</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1031757592" paraeid="{6df0c8d5-ced1-41b8-82d4-3fb270aacd2b}{214}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="151711645" paraeid="{6df0c8d5-ced1-41b8-82d4-3fb270aacd2b}{219}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary scanned public-facing websites to understand the target environment.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1224499395" paraeid="{6df0c8d5-ced1-41b8-82d4-3fb270aacd2b}{226}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">2</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="342664166" paraeid="{09772ea6-c54d-4dc0-bb20-bb5c3a18251a}{180}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="845432819" paraeid="{6df0c8d5-ced1-41b8-82d4-3fb270aacd2b}{234}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1593: Search Open Websites/Domains</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="498407150" paraeid="{6df0c8d5-ced1-41b8-82d4-3fb270aacd2b}{241}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary scanned the web to obtain<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Github</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">PATs.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="13455659" paraeid="{6df0c8d5-ced1-41b8-82d4-3fb270aacd2b}{248}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="5" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="2045555532" paraeid="{dbee225e-8d53-4518-b726-68aa4677443b}{42}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Initial access</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="2127712922" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{23}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1566: Phishing</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1458941534" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{30}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary used malicious emails and social engineering to compromise user accounts and<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">facilitate</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>fraudulent purchase orders.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1724030027" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{37}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">5</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="6" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="486660714" paraeid="{09772ea6-c54d-4dc0-bb20-bb5c3a18251a}{192}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1967400971" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{45}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1189: Drive-by compromise</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1189191223" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{52}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary registered several domains that masquerade as being related to VMware, and manipulated the SEO to show them at the top when searching for keywords such as VMware</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="361722668" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{59}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">3</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="7" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="815557930" paraeid="{09772ea6-c54d-4dc0-bb20-bb5c3a18251a}{196}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="180454131" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{67}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1078: Valid Accounts</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1736886779" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{74}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary successfully gained access to the environment by using compromised user credentials&#xA0;</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1684488983" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{81}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">4</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="8" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1650225967" paraeid="{09772ea6-c54d-4dc0-bb20-bb5c3a18251a}{200}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1566230868" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{89}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1190: Exploit public-facing applications</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="878908864" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{96}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Two internet facing Linux servers running Apache and an LMS application were targeted.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="603641844" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{103}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">3</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="9" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="687804480" paraeid="{b50fc752-70a1-456b-8e3c-da667662d533}{164}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Execution</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1124534568" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{133}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1204.002: User Execution: Malicious File</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="400664485" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{140}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The victim downloaded a malicious installer on their personal host, connected the host to their company&#x2019;s network, transferred the malware to their primary domain controller, then executed the malware.&#xA0;</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="570715961" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{155}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">3</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="10" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="731663044" paraeid="{09772ea6-c54d-4dc0-bb20-bb5c3a18251a}{212}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1545838236" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{163}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1204.001: User Execution: Malicious link&#xA0;</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1999565433" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{170}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The victim clicked on a link that led to a fake<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">DocuSign</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>document hosted on adobe[.]com</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1527763567" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{177}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">5</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="11" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="722585116" paraeid="{09772ea6-c54d-4dc0-bb20-bb5c3a18251a}{216}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="2040723382" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{185}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1059.001: Command and Scripting Interpreter: PowerShell&#xA0;</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="628898423" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{192}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary used PowerShell commands and scripts for execution.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="889707720" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{199}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">4</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="12" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1612669645" paraeid="{09772ea6-c54d-4dc0-bb20-bb5c3a18251a}{220}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1132570042" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{207}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1059.006: Command and Scripting Interpreter: Python</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="193515998" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{214}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary used automated Python scripts to interact with the environment.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1750131552" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{221}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="13" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1545424520" paraeid="{09772ea6-c54d-4dc0-bb20-bb5c3a18251a}{224}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1524586270" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{229}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1059.005: Command and Scripting Interpreter: MSHTA</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1389414149" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{236}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">attempted</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>to use mshta.exe to retrieve and execute a remote malicious payload from an external URL.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1028459346" paraeid="{fe8f1781-2fcc-46f1-a94d-3df5b373ac95}{243}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="14" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="118717670" paraeid="{c57978b9-7f21-4157-9452-dbe95c1d95cc}{116}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Persistence</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="194567616" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{18}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1556.006:<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Modify</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Authentication Process: Multi-Factor Authentication</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="379573351" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{25}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary registered their own malicious MFA devices to<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">maintain</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>access to compromised accounts.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1192236535" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{32}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">2</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="15" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1757169166" paraeid="{09772ea6-c54d-4dc0-bb20-bb5c3a18251a}{236}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1414034663" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{40}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1219: Remote Access Software</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1543395209" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{47}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary installed and used<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">AnyDesk</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>for unauthorized remote access.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="700993208" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{54}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="16" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="909630329" paraeid="{09772ea6-c54d-4dc0-bb20-bb5c3a18251a}{240}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="769156948" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{62}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1053.005: Scheduled Task/Job: Scheduled Task</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="786410295" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{69}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary configured tasks to run on a schedule or at system startup.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1839261681" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{76}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="17" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="509034837" paraeid="{09772ea6-c54d-4dc0-bb20-bb5c3a18251a}{244}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="446023233" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{84}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1505: Server Software Component</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1852118974" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{91}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary installed malware on breached devices to<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">facilitate</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">remote command execution via HTTP.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1207110950" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{98}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="18" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="2015025073" paraeid="{023b68d7-034e-4791-838b-4044af5360cb}{240}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Privilege escalation</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1689188616" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{128}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: normal; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1068: Exploitation for Privilege Escalation</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="739653697" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{135}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: normal; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary escalated to SYSTEM level privileges, which may have provided access to cached credentials in memory or registry hive.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1502470987" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{142}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: normal; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="19" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1325599272" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{1}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="107799647" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{150}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1548: Abuse Elevation Control Mechanism</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1973040168" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{157}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: normal; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary used<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">ExecutionPolicy</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>Bypass in PowerShell and<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">attempted</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>to add users to the local Administrators group.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="119805646" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{164}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: normal; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="20" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1938890427" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{5}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: normal; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="531330934" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{172}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: normal; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1078</span></span><span class="TabRun IPSelectionBlob BlobObject DragDrop SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; display: inline-block; font-family: Calibri, sans-serif; font-size: 10pt; font-style: normal; font-weight: 400; position: relative; text-indent: 0px; white-space: nowrap; text-align: left; width: 0px; color: windowtext; -webkit-nbsp-mode: normal !important;"><span class="TabChar SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; display: inline-block; white-space: pre !important; -webkit-nbsp-mode: normal !important;">	</span><span class="TabLeaderChars SCXW67619765 BCX4" aria-hidden="true" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; display: inline-block; left: 0px; position: absolute; top: 0px; white-space: pre !important; -webkit-nbsp-mode: normal !important;"></span></span><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: normal; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Valid Accounts</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1640571244" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{183}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: normal; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary bypassed standard access controls by using compromised accounts with existing high-level privileges.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1988849919" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{190}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: normal; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="21" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1036814734" paraeid="{7e232229-90d8-47c0-97dd-10025f6759db}{107}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Defense evasion</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1618131671" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{220}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1070.003: Indicator Removal on Host: Clear Command History</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="329934886" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{227}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary used the terminal emulator &quot;</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">ConEmu</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">&quot; to run commands, intentionally avoiding log generation.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="2101199054" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{234}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">2</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="22" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1343515945" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{17}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1992522483" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{242}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1070.001: Indicator Removal: Clear Windows Event Logs</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="50643362" paraeid="{a86f9c39-020b-46a6-a896-d486e6ba6419}{249}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T</span></span><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">he adversary<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">deleted</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>logs on compromised devices to limit forensic findings.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1709747414" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{3}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="23" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="2105554875" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{21}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="98968609" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{11}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1556:<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Modify</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Authentication Process</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="470406930" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{18}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary set up an Outlook<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">client</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>Outlook client to connect to the Exchange Server and was able to send messages via that path which bypasses the requirement for MFA via Duo.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="246610620" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{25}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="24" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1778688608" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{25}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1191893297" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{33}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1562.001: Impair Defenses: Disable or Modify Tools</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1756724517" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{40}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T</span></span><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">he adversary was able to uninstall EDR agents from hosts and<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">attempted</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>to delete Windows Defender policies.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1872731162" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{49}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">4</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="25" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1893928132" paraeid="{fd4a2d05-a868-4429-8a41-f3846804b0e8}{229}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Credential access</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="812119972" paraeid="{fd4a2d05-a868-4429-8a41-f3846804b0e8}{227}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="167510213" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{79}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1003.002: OS Credential Dumping: Security Account Manager</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1662893162" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{86}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T</span></span><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">he adversary saved SAM and SYSTEM registry hives to extract local account hashes.&#xA0;</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1402810567" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{95}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">2</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="26" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1900186778" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{37}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="966733465" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{103}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1003.003: OS Credential Dumping: NTDS&#xA0;</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="266147457" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{110}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary dumped the<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">ntds.dit</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>file from Domain Controllers to obtain domain-wide credential hashes.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1465270665" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{117}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="27" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="416053367" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{41}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1847160772" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{125}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1003.005: Cached Domain Credentials&#xA0;</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="2038836703" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{132}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T</span></span><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">he adversary gained NT hashes for multiple domain accounts from cached logon information.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="56287126" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{141}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="28" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="994036821" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{45}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1052486416" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{149}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1557: Adversary-in-the-Middle</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="2014088995" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{156}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T</span></span><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">he<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">adversary&#xA0; used</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>an<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">AiTM</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">proxy to capture credentials and session tokens.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1578963580" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{165}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="29" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1739158211" paraeid="{1cc28476-5781-45a4-a5b8-eaeba4e1c194}{123}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Discovery</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1149322218" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{195}" style="-webkit-user-drag: none; margin: 16px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1087.003: Account Discovery: Email Account</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="630846840" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{202}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T</span></span><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">he adversary used Graph API calls to verify long lists of email addresses and retrieve associated user GUIDs.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="623523461" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{211}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="30" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="2031767163" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{57}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1763096268" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{219}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1580: Cloud Infrastructure Discovery&#xA0;</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="263004115" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{226}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary performed enumeration of the environment, including gathering OneDrive metadata (drive IDs and child item counts) and user roles.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="595831671" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{233}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="31" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1654082187" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{61}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="889578341" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{241}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1069.002: Permission Groups Discovery: Domain Groups&#xA0;</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1770574646" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{248}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary used commands like net group &quot;domain admins&quot; /domain to find high-privilege accounts.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="2125534091" paraeid="{b806cb29-e9b3-40de-972e-e2c12e0de0f1}{254}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="530768476" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{4}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="32" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="986215677" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{65}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="88225626" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{12}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1526: Cloud Service Discovery&#xA0;&#xA0;</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1289850368" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{19}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary ran the legitimate cybersecurity tool<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">TruffleHog</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>to discover repositories<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">containing</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">client secrets and personal information.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1617494787" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{26}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="33" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="641545692" paraeid="{bfbaa6bf-a8cb-417b-9dcc-1654684dd021}{133}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Lateral movement</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1519072446" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{56}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1021.002: Remote Services: SMB/Windows Admin Shares</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="587980627" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{63}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary used<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">PsExec</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">(communicated over SMB) to move laterally from the compromised domain controller to other servers.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1940379604" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{70}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">4</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="34" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="894532310" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{77}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1854116220" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{78}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1047: Windows Management Instrumentation&#xA0;</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1693575630" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{85}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary used PowerShell scripts to leverage WMI (Get-</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">WmiObject</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">) to query remote computers.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="2077741862" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{92}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">3</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="35" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1202573093" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{81}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1476974700" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{100}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1021.001: Remote Services: Remote Desktop Protocol</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="146781428" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{107}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary used RDP connections between hosts.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1804324673" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{114}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">3</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="36" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="592056991" paraeid="{c78e680b-ab90-4a14-b0fc-aac8611ba9e2}{143}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Collection</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1946636763" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{144}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1530: Data from Cloud Storage Object&#xA0;</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1555578197" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{151}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The analysis of M365 Audit Logs showed multiple<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">FileAccessed</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">and FileDownloaded events for documents stored in SharePoint and OneDrive.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="381471465" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{158}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="37" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="728953116" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{93}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="880633813" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{166}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1040 Network Sniffing</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="360141691" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{173}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary executed monitor capture commands on specific interfaces to intercept and capture network traffic.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="789700863" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{180}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="38" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1040438942" paraeid="{c0df8aba-2d2b-4775-a268-184205e1efea}{105}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Command and control</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1941051787" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{210}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1071.001: Application Layer Protocol: Web Protocols</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1994882082" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{217}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary used<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">MeshAgent</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">to communicate with the C2 server over<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">WebSockets</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1744999481" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{224}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">5</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="39" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1854593527" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{105}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="762755498" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{232}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1102: Web Service&#xA0;</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1709659584" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{239}" style="-webkit-user-drag: none; margin: 16px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 11pt; line-height: 17px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary<span class="Apple-converted-space">&#xA0;</span></span></span><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">leveraged</span><span class="NormalTextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>a Telegram URL to issue instructions and download links.&#xA0;</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="789747556" paraeid="{9e8ad2ee-67b0-484f-88bc-531bcf9315f1}{248}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="40" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1480197581" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{109}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="587969922" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{1}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1572: Protocol Tunneling</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1159788097" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{8}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary used a second-stage script to create an HTTPS tunnel directly to the C2 system.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="816422229" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{15}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="41" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1844477048" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{113}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="332418710" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{23}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1201: Traffic Signaling</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1964173556" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{30}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary communicated with external infrastructure using regular beaconing or other signaling patterns to maintain C2 or check in with their C2 server.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1227139708" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{37}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="42" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="2059021150" paraeid="{fe88a42a-b491-4282-bf6b-4fa60552b1cb}{115}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Exfiltration</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1518739869" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{67}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1567.002: Exfiltration Over Web Service</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1226624978" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{74}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary accessed and exfiltrated internal data, specifically SharePoint files, via web-based channels.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1104406580" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{81}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="43" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1944173203" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{125}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1407495858" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{89}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1041: Exfiltration Over C2 Channel</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1606043451" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{96}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary exfiltrated approximately 2,500 client secrets and personal information.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="152466364" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{107}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">2</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="44" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="852093794" paraeid="{526a9e21-1cce-4009-80ff-b256782d71e0}{34}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Impact</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="262754483" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{137}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1657: Financial Theft</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="860154207" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{144}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary used company resources to place orders totaling hundreds of thousands of US dollars for various products which were successfully delivered.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="962594537" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{151}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="45" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1806409579" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{137}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="610841959" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{159}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1486 Data Encrypted for Impact</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1505957352" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{166}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary encrypted victim data.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="837499323" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{173}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="46" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="802815548" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{141}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="993617492" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{181}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">T1531 Account Access Removal</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="2058944509" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{188}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">The adversary disabled admin accounts and deleted service accounts in the Active Directory (AD) and Azure</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="363410556" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{195}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="47" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="334506055" paraeid="{820a51bf-1c6b-4df4-a77f-0feec15e9971}{44}" style="-webkit-user-drag: none; margin: 19.2px 0px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: bold; font-style: normal; vertical-align: baseline; background-color: transparent; color: rgb(255, 255, 255); text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-weight: bold; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Header" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Software</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;335559738&quot;:288}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 15px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1320078833" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{225}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Rhysida</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">&#xA0;</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="1795332177" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{232}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">A RaaS, known for posing as a cybersecurity team that &#x201C;helps&#x201D; its victims<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">identify</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>security weaknesses in their networks.</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="2086935785" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{239}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Pre-ransomware engagement</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="48" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1086178341" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{153}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="914954473" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{247}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">SocGholish</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td data-celllook="4369" class="SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="40213052" paraeid="{592ff12b-4715-4f58-96e6-7c6139a73691}{254}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">A JavaScript-based loader malware that has been used<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">since at least</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>2017, primarily for<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">initial</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>access.&#xA0;</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="2029037609" paraeid="{7555e31a-d083-4f80-9934-16e5e1dfdc9e}{6}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">1</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr><tr class="TableRow SCXW67619765 BCX4" role="row" aria-rowindex="49" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; height: 19px;"><td class="FirstCol LastRow SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" xml:lang="EN-US" lang="EN-US" paraid="1246043199" paraeid="{9ac54ef9-9658-45d3-928a-f2f03b27d238}{157}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"></span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastRow SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 146px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="686025187" paraeid="{7555e31a-d083-4f80-9934-16e5e1dfdc9e}{14}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Money Message</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastRow SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 227px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="141741669" paraeid="{7555e31a-d083-4f80-9934-16e5e1dfdc9e}{21}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">A ransomware that emerged in<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">March 2023, and</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;"><span class="Apple-converted-space">&#xA0;</span>is capable of targeting Windows and Linux systems (including VMware<span class="Apple-converted-space">&#xA0;</span></span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">ESXi</span><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">servers).</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td><td class="LastCol LastRow SCXW67619765 BCX4" data-celllook="4369" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; overflow: visible; vertical-align: top; position: relative; background-color: transparent; background-clip: padding-box; border: 1px solid rgb(0, 0, 0); width: 103px;"><div class="TableCellContent SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 9px; -webkit-user-select: text; overflow: visible;"><div class="OutlineElement Ltr SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; clear: both; cursor: text; overflow: visible; position: relative; direction: ltr;"><p class="Paragraph SCXW67619765 BCX4" paraid="608127993" paraeid="{7555e31a-d083-4f80-9934-16e5e1dfdc9e}{36}" style="-webkit-user-drag: none; margin: 8px 0px; padding: 0px; -webkit-user-select: text; overflow-wrap: break-word; font-weight: normal; font-style: normal; vertical-align: baseline; background-color: transparent; color: windowtext; text-align: left; text-indent: 0px; -webkit-nbsp-mode: normal !important;"><span data-contrast="auto" xml:lang="EN-US" lang="EN-US" class="TextRun SCXW67619765 BCX4" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; color: windowtext; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; font-variant-ligatures: none !important; -webkit-nbsp-mode: normal !important;"><span class="NormalTextRun SCXW67619765 BCX4" data-ccp-parastyle="Table Body" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; -webkit-nbsp-mode: normal !important;">Pre-ransomware engagement</span></span><span class="EOP SCXW67619765 BCX4" data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:276}" style="-webkit-user-drag: none; margin: 0px; padding: 0px; -webkit-user-select: text; font-size: 10pt; line-height: 17.25px; font-family: CiscoSansTT, CiscoSansTT_EmbeddedFont, CiscoSansTT_MSCustomFont, CiscoSansTT_MSFontService, sans-serif; color: windowtext; -webkit-nbsp-mode: normal !important;">&#xA0;</span></p></div></div></td></tr></tbody></table>
<!--kg-card-end: html-->
]]></content:encoded></item><item><title><![CDATA[[Podcast] It's not you, it's your printer: State-sponsored and phishing threats in 2025]]></title><description><![CDATA[In this episode of Talos Takes, Amy and Martin Lee unpack state-sponsored and phishing trends from the 2025 Talos Year in Review.]]></description><link>https://blog.talosintelligence.com/podcast-its-not-you-its-your-printer-state-sponsored-and-phishing-threats-in-2025/</link><guid isPermaLink="false">69e634c2645a220001422c5f</guid><category><![CDATA[2025YiR]]></category><category><![CDATA[Year In Review]]></category><dc:creator><![CDATA[Amy Ciminnisi]]></dc:creator><pubDate>Tue, 21 Apr 2026 12:29:49 GMT</pubDate><media:content url="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/YiR2025_cover_2x1-2-1.jpg" medium="image"/><content:encoded><![CDATA[<img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/YiR2025_cover_2x1-2-1.jpg" alt="[Podcast] It&apos;s not you, it&apos;s your printer: State-sponsored and phishing threats in 2025"><p>In this episode, we unpack state-sponsored and phishing trends from the 2025 Talos Year in Review. Amy and Martin Lee explore the alarming rise of internal phishing campaigns that bypass traditional perimeter defenses, including the widespread weaponization of Microsoft 365&apos;s Direct Send feature. Beyond simple phishing, we analyze the aggressive, blended operations of state-sponsored actors from China and North Korea who are combining high-level zero-day exploits with sophisticated social engineering. From the &quot;Dear Leader&quot; interview test to the reality of fake developer personas, we break down exactly how these adversaries are infiltrating modern organizations.</p><p><a href="https://blog.talosintelligence.com/2025yearinreview/" rel="noreferrer">View the 2025 Year in Review here.</a></p><figure class="kg-card kg-embed-card"><iframe style="border-radius: 12px" width="100%" height="152" title="Spotify Embed: It&apos;s not you, it&apos;s your printer: State-sponsored and phishing threats in 2025" frameborder="0" allowfullscreen allow="autoplay; clipboard-write; encrypted-media; fullscreen; picture-in-picture" loading="lazy" src="https://open.spotify.com/embed/episode/2bR5sF3n1P3T2v8ib2VFUL?si=29a205c2d7bd45e9&amp;utm_source=oembed"></iframe></figure>]]></content:encoded></item><item><title><![CDATA[Phishing and MFA exploitation: Targeting the keys to the kingdom]]></title><description><![CDATA[In 2025, attackers increasingly targeted weaknesses in multi-factor authentication (MFA) workflows, and phishing attacks leveraged valid, compromised credentials to launch lures from trusted accounts. The trends focused entirely on trust, or the lack thereof, in everyday business operations.]]></description><link>https://blog.talosintelligence.com/phishing-and-mfa-exploitation-targeting-the-keys-to-the-kingdom/</link><guid isPermaLink="false">69e279f1645a220001422b73</guid><category><![CDATA[2025YiR]]></category><category><![CDATA[MFA]]></category><category><![CDATA[phishing]]></category><category><![CDATA[Year In Review]]></category><dc:creator><![CDATA[Kri Dontje]]></dc:creator><pubDate>Tue, 21 Apr 2026 12:00:08 GMT</pubDate><media:content url="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/2025YiR-topic_phishing-identity.jpg" medium="image"/><content:encoded><![CDATA[<img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/2025YiR-topic_phishing-identity.jpg" alt="Phishing and MFA exploitation: Targeting the keys to the kingdom"><p>In 2025, attackers increasingly targeted weaknesses in multi-factor authentication (MFA) workflows, and phishing attacks leveraged valid, compromised credentials to launch lures from trusted accounts. The trends focused entirely on trust, or the lack thereof, in everyday business operations.</p><h2 id="phishing">Phishing</h2><p>In 2025, phishing attacks were used for initial access in 40% of incidents, maintaining their prevalence. Attackers ramped up cascaded phishing campaigns, where attackers leveraged the trust of the initial compromised account to create specialized phishing attempts, within the network and out of it, aimed at trusted partners and third parties<a>.</a></p><figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/YiR_figsforblog_phishing_trends.jpg" class="kg-image" alt="Phishing and MFA exploitation: Targeting the keys to the kingdom" loading="lazy" width="1875" height="1422" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/YiR_figsforblog_phishing_trends.jpg 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/YiR_figsforblog_phishing_trends.jpg 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/YiR_figsforblog_phishing_trends.jpg 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/YiR_figsforblog_phishing_trends.jpg 1875w" sizes="(min-width: 720px) 720px"></figure><h3 id="email-composition-trends">Email composition trends</h3><p>The content of phishing emails changed somewhat. Transitioning away from spam offers, they took the form of workflow-style emails &#x2014; IT, travel, and other everyday business tasks that look familiar to employees and executives. Travel and logistics lures in particular surged, while political lures dropped off. Internal expensing and travel emails, even when legitimate, are often repetitive and come from disparate sources with changeable formats or poorly-rendered templates, leading to a lowered guard toward spotting malicious intent. Attackers were likely aiming to steal credentials, payment information, or MFA tokens via fake single sign-on (SSO) pages.</p><p>In reviews of thousands of blocked-email keywords, 60% contained subject lines with &quot;request,&quot; &quot;invoice,&quot; &quot;fwd,&quot; &quot;report,&quot; and similar. IT-focused phishing keywords turned more technical, to words like &quot;tampering,&quot; &quot;domain,&quot; &quot;configuration,&quot; &quot;token,&quot; and others, showing that attackers were making plays toward IT and security workflows.</p><p>Attackers also abused Microsoft 365 Direct Send to capitalize on internal email trust. Direct Send is the method by which networked devices like printers and scanners deliver documents to users. The messages appear to be sent and received by the same email address. These internal messages do not receive the same scrutiny that external emails do, from employees or automated email filters. Direct Send allowed attackers to spoof internal email addresses and deliver highly convincing lures from inside the organization, without compromising real accounts, to target key attack services and deliver high-impact damage.</p><h2 id="mfa-and-identity-attacks">MFA and identity attacks</h2><p>Identity and access management (IAM) applications have grown popular with organizations hoping to consolidate user privileges. Unfortunately, it has also grown in popularity with attackers. Nearly a third of 2025 MFA spray attacks targeted IAM, turning the tools companies used to maintain access control into a point of failure. Device compromise surged by 178%, largely driven by voice phishing designed to trick administrators into registering malicious devices.</p><h3 id="mfa-spray-and-device-compromise">MFA spray and device compromise</h3><p>MFA attack strategy changed by sector. A successful attack could glean SSO tokens and give adversaries the ability to change user roles and credentials, or even the MFA policies themselves. Attackers increasingly exploited authentication workflows to gain and maintain access.</p><figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/YiR_figsforblog_MFA_attack_style-1.jpg" class="kg-image" alt="Phishing and MFA exploitation: Targeting the keys to the kingdom" loading="lazy" width="1862" height="1070" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/YiR_figsforblog_MFA_attack_style-1.jpg 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/YiR_figsforblog_MFA_attack_style-1.jpg 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/YiR_figsforblog_MFA_attack_style-1.jpg 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/YiR_figsforblog_MFA_attack_style-1.jpg 1862w" sizes="(min-width: 720px) 720px"></figure><p>Spray attacks were deployed against networks with predictable identity behavior, while diverse, unmanaged, or high-turnover device ecosystems proved weaker to device compromise attacks.</p><p>Notably, higher education was the most targeted device compromise sector. Several factors could contribute to the trend:</p><p>&#xB7;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; Diverse unmanaged device population</p><p>&#xB7;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; Poorly patched and managed operating systems</p><p>&#xB7;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; Necessarily low new-device verification policies</p><p>&#xB7;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; Large, public-facing directories for targeted phishing</p><p>Higher education was a very unfavorable target for MFA spray attacks, however. Passwords and MFA are also highly varied and segmented, and most universities have strong login portal policies, enforced lockouts, and login attempt limits.</p><h2 id="guidance-for-defenders">Guidance for defenders</h2><p>As always, prioritize based on your own environment.</p><p>Organizations should keep in mind that living-off-the-land binaries (LOLBins) and open-source and dual-use tools, which are not inherently malicious, are key to further exploitation. Blocking external IPs from using a feature, enabling Microsoft&#x2019;s newer &#x201C;Reject Direct Send&#x201D; control, tightening SPF/DMARC enforcement, and treating &#x201C;internal-looking&#x201D; emails with the same scrutiny as inbound mail are currently the most effective defenses.</p><p>Likewise, MFA attack protection should be tailored to the style of environment and sector.</p><p>MFA spray attacks work well on stable, scaled identity controls. Counter these attacks with strong lockout policies, good password hygiene, and conditional access. </p><p>Device compromise works best on variable networks where devices change over fast and MFA use is spotty. Work on establishing better device hardening and management, session controls, and strict phishing-resistant MFA with enrollment governance. Solutions such as <a href="https://duo.com/"><u>Cisco Duo</u></a> provide controls for phishing-resistant MFA, device trust, and secure enrollment, helping reduce risk from phishing and identity-based attacks. </p><p></p><figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/YiR_figsforblog_targeted_apps_MFA-1.jpg" class="kg-image" alt="Phishing and MFA exploitation: Targeting the keys to the kingdom" loading="lazy" width="1875" height="1725" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/YiR_figsforblog_targeted_apps_MFA-1.jpg 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/YiR_figsforblog_targeted_apps_MFA-1.jpg 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/YiR_figsforblog_targeted_apps_MFA-1.jpg 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/YiR_figsforblog_targeted_apps_MFA-1.jpg 1875w" sizes="(min-width: 720px) 720px"></figure><p>This blog only scratched the surface on 2025 threat trends. See the full <a href="https://blog.talosintelligence.com/2025yearinreview">Year in Review report</a> for a detailed explanation of Microsoft 365 Direct Send and how it was used for attacks, infographic breakdowns of MFA spray vs. device compromise attacks, the full list of targeted tools and sectors by percentage, and more. </p>]]></content:encoded></item><item><title><![CDATA[Bad Apples: Weaponizing native macOS primitives for movement and execution]]></title><description><![CDATA[Cisco Talos documents several macOS living-off-the-land (LOTL) techniques, demonstrating that native pathways for movement and execution remain accessible to those who understand the underlying architecture. ]]></description><link>https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/</link><guid isPermaLink="false">69e62568645a220001422bae</guid><category><![CDATA[Threat Spotlight]]></category><dc:creator><![CDATA[William Charles Gibson]]></dc:creator><pubDate>Tue, 21 Apr 2026 10:00:29 GMT</pubDate><media:content url="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/bad-apples.jpg" medium="image"/><content:encoded><![CDATA[<ul><li>As macOS adoption grows among developers and DevOps, it has become a high&#xA0;value target; however, native &quot;living-off-the-land&quot; (LOTL) techniques for the platform remain significantly under-documented compared to Windows.&#xA0;</li><li>Adversaries can bypass security controls by repurposing native features like Remote Application Scripting&#xA0;(RAS) for remote execution and abusing Spotlight metadata (Finder comments) to stage payloads in a way that evades static file analysis.&#xA0;</li><li>Attackers can move toolkits and&#xA0;establish&#xA0;persistence using built-in protocols&#xA0;such as SMB,&#xA0;Netcat, Git, TFTP, and SNMP&#xA0;operating&#xA0;entirely outside the visibility of standard SSH-based telemetry.&#xA0;</li><li>Defenders should shift from static file scanning to&#xA0;monitoring&#xA0;process lineage, inter-process communication (IPC) anomalies, and enforcing strict MDM policies to disable unnecessary administrative services.</li></ul><hr><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/bad-apples.jpg" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution"><p>As macOS adoption in the enterprise reaches record highs, with over 45 percent of organizations now&#xA0;utilizing&#xA0;the platform, the traditional &quot;security through obscurity&quot; narrative surrounding the&#xA0;OS&#xA0;has been&#xA0;rendered&#xA0;obsolete. Mac endpoints, once relegated to creative departments, are now the primary workstations for developers, DevOps engineers, and system administrators. Consequently, these machines have become high-value targets that serve as gateways to source code repositories, cloud infrastructure, and sensitive production credentials.&#xA0;</p><p>Despite this shift, macOS-native lateral movement and&#xA0;execution&#xA0;tradecraft remain significantly understudied compared to&#xA0;their&#xA0;Windows counterparts. This research was conducted to address this critical knowledge gap. Through a systematic validation of native macOS protocols and system binaries, it is&#xA0;demonstrated&#xA0;how adversaries can&#xA0;&#x201C;live off the land&#x201D;&#xA0;(LOTL) by repurposing legitimate administrative tools. By weaponizing native primitives, such as Remote Application Scripting&#xA0;(RAS) and Spotlight metadata, intentional OS security features can be bypassed to transform standard system functions into robust mechanisms for arbitrary code execution and fleet-wide orchestration.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/bad-apples-flow.jpg" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="2000" height="864" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/bad-apples-flow.jpg 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/bad-apples-flow.jpg 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/bad-apples-flow.jpg 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/bad-apples-flow.jpg 2310w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 1.&#xA0;macOS&#xA0;living-off-the-land (LOTL)&#xA0;attack&#xA0;flow.</span></figcaption></figure><h2 id="the-macos-enterprise-blind-spot">The macOS&#xA0;enterprise&#xA0;blind&#xA0;spot&#xA0;</h2><p>macOS is no longer a niche operating system. According to the&#xA0;<a href="https://survey.stackoverflow.co/2024/" rel="noreferrer noopener"><u>Stack Overflow 2024 Developer Survey</u></a>, a third of professional developers use macOS as their primary platform. These machines&#xA0;represent&#xA0;high-value pivot points, often holding source code repositories, cloud credentials, and SSH keys to production infrastructure.&#xA0;</p><p>Despite this trend, the MITRE ATT&amp;CK framework documents far fewer techniques for macOS than for Windows, and recent industry reports&#xA0;indicate&#xA0;that macOS environments prevent significantly fewer attacks than their Windows or Linux counterparts. To address this disparity, community-driven resources such as&#xA0;<a href="https://www.loobins.io/" rel="noreferrer noopener"><u>LOOBins</u></a>&#xA0;(living-off-the-orchard&#xA0;binaries) have&#xA0;emerged&#xA0;to catalog native macOS binaries that can be repurposed for malicious activity. This research aims to further close that gap by systematically&#xA0;enumerating&#xA0;the native pathways available for both movement and execution.</p><h2 id="remote-command-execution-weaponizing-native-primitives">Remote&#xA0;command&#xA0;execution: Weaponizing&#xA0;native&#xA0;primitives&#xA0;</h2><p>Establishing a remote shell is the first step in any post-exploitation chain. While SSH is the standard, native macOS features&#xA0;provide&#xA0;several alternatives that can bypass traditional monitoring.&#xA0;</p><h3 id="remote-application-scripting-as-a-software-deployment-tool-t1072">Remote Application&#xA0;Scripting&#xA0;as a&#xA0;Software&#xA0;Deployment&#xA0;Tool (T1072)&#xA0;</h3><p>Remote Application&#xA0;Scripting&#xA0;(RAS, formerly known as Remote Apple Events or RAE)&#xA0;was&#xA0;introduced to extend the capabilities of the AppleScript&#xA0;Inter-Process Communication (IPC) framework across a network. By&#xA0;utilizing&#xA0;the Electronic Program-to-Program Communication (&#x201C;eppc&#x201D;) protocol, administrative tasks and application automation&#xA0;can be performed&#xA0;on remote&#xA0;macOS systems. This mechanism allows a controller machine to send high-level commands to a target machine, which&#xA0;are&#xA0;then processed by the&#xA0;&#x201C;AppleEventsD&#x201D;&#xA0;daemon.&#xA0;</p><p>The Open Scripting Architecture (OSA) is&#xA0;utilized&#xA0;as the standardized framework for&#xA0;this inter-application communication and automation on macOS. Through the exchange of Apple Events, this architecture enables scripts to programmatically interact with the operating system and installed applications, providing the functional foundation for the&#xA0;&#x201C;osascript&#x201D;&#xA0;utility.&#xA0;</p><p>Traditionally, RAS is viewed as a lateral movement vector; however, this research&#xA0;demonstrates&#xA0;that it can also be&#xA0;utilized&#xA0;as a standalone&#xA0;<a href="https://attack.mitre.org/techniques/T1072/" rel="noreferrer noopener"><u>Software Deployment Tool for Execution (T1072)</u></a>.&#xA0;</p><p>Adversaries&#xA0;attempting&#xA0;to use RAS for complex payloads often&#xA0;encounter&#xA0;Apple&#x2019;s intentional security features, specifically the&#xA0;-10016 Handler Error. This restriction prevents the&#xA0;&#x201C;System Events&#x201D;&#xA0;application from executing remote shell commands&#xA0;via&#xA0;<code>do&#xA0;shell script</code>,&#xA0;even when RAS is globally enabled.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-2.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="676" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-2.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-2.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-2.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-2.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 2.&#xA0;The -10016&#xA0;Handler&#xA0;Error in&#xA0;remote&#xA0;application&#xA0;scripting.</span></figcaption></figure><p>To bypass this,&#xA0;a methodology&#xA0;was developed that treats&#xA0;&#x201C;Terminal.app&#x201D;&#xA0;as an execution proxy. Unlike&#xA0;&#x201C;System Events&#x201D;,&#xA0;&#x201C;Terminal.app&#x201D;&#xA0;is designed for shell interaction and accepts&#xA0;remote&#xA0;&#x201C;do&#xA0;script&#x201D;&#xA0;commands. To ensure payload integrity and bypass AppleScript parsing limitations (such as the&#xA0;-2741 syntax&#xA0;error),&#xA0;Base64 transport encoding&#xA0;is&#xA0;utilized. This transforms multi-line scripts into flat, alphanumeric strings that are decoded and executed in a two-stage process:&#xA0;</p><ol><li><strong>Deployment:</strong>&#xA0;A single RAS command instructs the remote&#xA0;&#x201C;Terminal.app&#x201D;&#xA0;to decode the Base64 string into a temporary path and apply&#xA0;<code>chmod&#xA0;+x</code>.&#xA0;</li><li><strong>Invocation:</strong>&#xA0;A second RAS command explicitly invokes the script via&#xA0;&quot;bash&#x201D;,&#xA0;ensuring a proper shell context.</li></ol><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-3.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="596" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-3.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-3.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-3.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-3.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 3.&#xA0;Terminal.app&#xA0;as an&#xA0;execution&#xA0;proxy for Base64&#xA0;payloads.</span></figcaption></figure><h3 id="remote-application-scripting-for-lateral-movement-t1021005">Remote Application&#xA0;Scripting&#xA0;for Lateral Movement (T1021.005)&#xA0;</h3><p>While RAS can be weaponized for execution, its primary function&#xA0;remains&#xA0;the facilitation of inter-process communication (IPC) across a network. In a lateral movement context, RAS is&#xA0;utilized&#xA0;to control remote applications by targeting the&#xA0;&#x201C;eppc://&#x201D;&#xA0;URI. This allows for&#xA0;the remote&#xA0;manipulation of the file system or the retrieval of sensitive environmental data without the need for a traditional interactive shell.&#xA0;</p><p>For example, the command&#xA0;in Figure 4&#xA0;can be used to remotely query the Finder for a list of mounted volumes on a target machine, providing an adversary with immediate insight into the victim&apos;s network shares and external storage:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-4.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="394" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-4.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-4.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-4.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-4.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 4.&#xA0;Remotely&#xA0;querying&#xA0;mounted&#xA0;volumes via RAE.</span></figcaption></figure><p>Because these actions are performed via Apple Events rather than standard shell commands, they often bypass security telemetry that focuses exclusively on process&#xA0;execution&#xA0;trees, making RAS a discreet and effective vector for lateral movement.</p><h3 id="applescript-execution-via-ssh">AppleScript&#xA0;execution via SSH&#xA0;</h3><p>AppleScript is macOS&apos;s built-in scripting language for automation. While RAS is&#xA0;a viable&#xA0;application control mechanism, Apple security controls prevent RAS from launching applications; they must already be running. Additionally, RAS must be enabled on the target. To circumvent these obstacles,&#xA0;<code>osascript</code>&#xA0;can be invoked directly over SSH.&#xA0;<br>&#xA0;<br>Passing&#xA0;<code>osascript</code>&#xA0;the&#xA0;<code>system info</code>&#xA0;command over SSH returns critical environmental details:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-5.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="596" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-5.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-5.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-5.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-5.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 5.&#xA0;Retrieving&#xA0;system&#xA0;information via&#xA0;osascript&#xA0;over SSH.</span></figcaption></figure><p>For arbitrary command execution, AppleScript&apos;s&#xA0;<code>do shell script</code>&#xA0;handler can be invoked over SSH. In the following example,&#xA0;<code>do shell script</code>&#xA0;is used to write a file to the target:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-6.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="434" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-6.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-6.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-6.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-6.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 6.&#xA0;Arbitrary&#xA0;file&#xA0;creation&#xA0;using do&#xA0;shell script over SSH.&#xA0;</span></figcaption></figure><p>While SSH alone can&#xA0;accomplish&#xA0;shell tasks,&#xA0;<code>osascript</code>&#xA0;provides access to&#xA0;graphical user&#xA0;interfact&#xA0;(GUI)&#xA0;automation and Finder manipulation through&#xA0;Apple Events IPC&#xA0;rather than spawning shell processes. This creates a significant telemetry gap, as most endpoint detection tooling has less visibility into IPC-driven actions than standard shell process trees.</p><h3 id="socat-remote-shell">socat&#xA0;remote&#xA0;shell&#xA0;</h3><p><code>socat</code>&#xA0;(SOcket&#xA0;CAT) is a command line utility for&#xA0;establishing&#xA0;bidirectional data streams between two endpoints. It supports a wide range of socket types including TCP, UDP, Unix domain sockets, and pseudo terminals (pty).&#xA0;</p><p>In a lateral movement context,&#xA0;<code>socat</code>&#xA0;can&#xA0;establish&#xA0;an interactive shell on a target without relying on SSH. The target runs a listener that binds a login shell to a TCP port with&#xA0;pty&#xA0;allocation, and the attacker&#xA0;connects to&#xA0;it from a remote machine.&#xA0;</p><p>On the target, the listener spawns an interactive bash session for each incoming connection with&#xA0;pty&#xA0;forwarding:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-7.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="394" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-7.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-7.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-7.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-7.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 7.&#xA0;Establishing a&#xA0;listener with PTY&#xA0;forwarding&#xA0;on the&#xA0;target.&#xA0;</span></figcaption></figure><p>From the attacking machine, connecting to the listener provides a fully interactive terminal:&#xA0;</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-8.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="394" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-8.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-8.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-8.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-8.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 8.&#xA0;Attacker&#xA0;connection to the&#xA0;socat&#xA0;listener.</span></figcaption></figure><p>On the target, the&#xA0;<code>reuseaddr,fork</code>&#xA0;options allow multiple connections and reuse of the port, while&#xA0;<code>pty,stderr</code>&#xA0;on the exec gives the connecting client a proper terminal with stderr output. On the sender side, <code>raw,echo=0,icanon=0</code>&#xA0;puts the local terminal into raw mode so that control characters and signals pass through to the remote shell correctly.&#xA0;</p><p>SSH is the de facto mechanism for gaining remote shell access on remote hosts, and as a result, it is where most detection engineering efforts are focused.&#xA0;<code>socat</code>&#xA0;achieves the same outcome, fully interactive terminal access, but&#xA0;operatesentirely outside the SSH ecosystem. There are no&#xA0;<code>sshd</code>&#xA0;logs, PAM authentication events, or&#xA0;&#x201C;authorized_keys&#x201D;&#xA0;to manage, which means detection pipelines built around SSH telemetry would not catch this activity.</p><h2 id="covert-data-transfer-finder-metadata-abuse">Covert&#xA0;data&#xA0;transfer: Finder&#xA0;metadata&#xA0;abuse&#xA0;</h2><p>A notable constraint of RAS is its inability to write file&#xA0;contents&#xA0;directly. To&#xA0;work around this, we can&#xA0;abuse&#xA0;the&#xA0;Finder Comment (&#x201C;kMDItemFinderComment&#x201D;)&#xA0;field, which is stored as Spotlight metadata.&#xA0;</p><h3 id="writing-payloads-to-finder-comments">Writing&#xA0;payloads to Finder Comments&#xA0;</h3><p>A notable constraint of RAS is its inability to&#xA0;write file&#xA0;contents&#xA0;directly. To circumvent this,&#xA0;threat actors can abuse&#xA0;the Finder Comment field (&#x201C;kMDItemFinderComment&#x201D;)&#xA0;&#x2014;&#xA0;a&#xA0;component&#xA0;of Spotlight metadata stored as an extended attribute. By storing a payload within metadata rather than the&#xA0;file&apos;s&#xA0;data fork,&#xA0;they&#xA0;can bypass&#xA0;traditional file-based security&#xA0;scanners&#xA0;and static analysis tools, which typically focus&#xA0;on executable code and script contents.&#xA0;</p><p>Because Finder is scriptable&#xA0;over RAS, the comment of a file on a remote machine can be set via the&#xA0;&#x201C;eppc://&#x201D;&#xA0;protocol. By Base64 encoding a payload locally, a multi-line script can be stored within this single string field. The&#xA0;<code>make new file</code>&#xA0;command handles the creation of the target file, ensuring that no pre-existing file&#xA0;is&#xA0;required:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-9.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="758" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-9.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-9.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-9.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-9.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 9.&#xA0;Setting Finder&#xA0;comments via RAE for&#xA0;payload&#xA0;staging.</span></figcaption></figure><p>The payload&#xA0;resides&#xA0;entirely within the Spotlight metadata, a location that&#xA0;remains&#xA0;largely unexamined&#xA0;by standard endpoint detection and response (EDR) solutions. This creates a stealthy staging area where malicious code can persist on the disk without triggering alerts associated with suspicious file contents.&#xA0;</p><h3 id="extraction-and-execution">Extraction and&#xA0;execution&#xA0;</h3><p>On the target, extraction and&#xA0;execution&#xA0;is&#xA0;a single line.&#xA0;<code>mdls</code>&#xA0;reads the comment, <code>base64 -D</code>&#xA0;decodes it, and the result is piped to&#xA0;&#x201C;bash&#x201D;:&#xA0;</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-10.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="1080" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-10.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-10.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-10.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-10.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 10.&#xA0;Extraction and&#xA0;execution of&#xA0;metadata-stored&#xA0;payloads.</span></figcaption></figure><h3 id="persistence-via-launchagent">Persistence via&#xA0;LaunchAgent&#xA0;</h3><p>This approach can be paired with a&#xA0;LaunchAgent&#xA0;for persistence. A&#xA0;plist&#xA0;in&#xA0;&#x201C;~/Library/LaunchAgents&#x201D;&#xA0;that executes the extraction chain at user login allows the payload to run automatically.&#xA0;</p><p>Our&#xA0;initial&#xA0;attempt using&#xA0;<code>mdls</code>&#xA0;inside the&#xA0;LaunchAgent&#xA0;failed because Spotlight may not be fully initialized when&#xA0;LaunchAgents&#xA0;fire. The fix was to replace&#xA0;<code>mdls</code>&#xA0;with&#xA0;<code>osascript</code>&#xA0;calling Finder directly to read the comment:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-11.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="1040" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-11.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-11.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-11.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-11.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 11.&#xA0;Persistence via&#xA0;LaunchAgent&#xA0;and Finder&#xA0;metadata.&#xA0;</span></figcaption></figure><p>Talos&#xA0;confirmed&#xA0;this successfully executes the payload at login. It is worth noting that macOS prompts the user to approve the bash execution at login, which is a visible indicator of background activity. The&#xA0;plist&#xA0;contains&#xA0;no payload, only a reference to metadata, so static analysis of the&#xA0;LaunchAgent&#xA0;would not reveal the malicious content.&#xA0;</p><h2 id="lateral-tool-transfer-techniques">Lateral&#xA0;Tool&#xA0;Transfer&#xA0;techniques&#xA0;</h2><p>Once&#xA0;attackers achieve execution,&#xA0;they&#xA0;must move their toolkit across the environment. Several native protocols were&#xA0;validated&#xA0;for tool transfer (T1570).&#xA0;</p><h3 id="standard-protocols-scp-and-sftp">Standard&#xA0;protocols: SCP&#xA0;and&#xA0;SFTP&#xA0;</h3><p>SCP (Secure Copy Protocol) and SFTP (SSH File Transfer Protocol) are the most straightforward methods,&#xA0;operating&#xA0;over SSH and available out-of-the-box on any macOS system with Remote Login enabled.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-12.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="362" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-12.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-12.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-12.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-12.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 12.&#xA0;SCP&#xA0;file&#xA0;transfer&#xA0;syntax.</span></figcaption></figure><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-13.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="354" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-13.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-13.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-13.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-13.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 13.&#xA0;SFTP&#xA0;file&#xA0;transfer&#xA0;syntax.</span></figcaption></figure><h3 id="smb-based-transfer">SMB-based&#xA0;transfer&#xA0;</h3><p>Server Message Block (SMB) is a network file sharing protocol commonly associated with Windows environments, but macOS includes native support for both SMB client and server functionality. In a lateral movement context, an attacker can mount a remote SMB&#xA0;share&#xA0;and access its contents as if they were local files.&#xA0;</p><p>This method of setting up an SMB share on the victim requires SSH access. The following command creates a shared directory, loads the SMB daemon, and creates the share.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/carbon.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="434" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/carbon.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/carbon.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/carbon.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/carbon.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 14.&#xA0;Configuring a&#xA0;native SMB&#xA0;share on macOS.</span></figcaption></figure><p>With the share created, the next step is mounting it from the attacker machine. Attempting this action with the&#xA0;<code>mount</code>&#xA0;command failed due to an authentication error.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-15.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="516" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-15.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-15.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-15.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-15.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 15.&#xA0;Authentication&#xA0;error&#xA0;encountered&#xA0;during SMB&#xA0;mount.</span></figcaption></figure><p>To resolve this issue, GUI access to the victim machine was&#xA0;required. On the victim machine, navigate to System Settings &gt; General &gt; Sharing &gt; File Sharing &gt; Options. Located here is the option to store the user&apos;s account password on the computer. Even though this is labeled as &quot;Windows File Sharing&quot;, it was&#xA0;required&#xA0;to properly authenticate the user when using the mount utility.&#xA0;</p><p>However, this entire GUI dependency can be avoided by using&#xA0;<code>osascript</code>&#xA0;to mount the share instead of&#xA0;<code>mount</code>:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-16.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="354" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-16.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-16.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-16.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-16.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 16.&#xA0;Mounting SMB&#xA0;shares via&#xA0;osascript.</span></figcaption></figure><p>This mounts the share to&#xA0;&#x201C;/Volumes/share&#x201D;&#xA0;without requiring the GUI configuration step. With the share mounted, any&#xA0;file copied into the mount directory appears on the victim&#xA0;immediately.&#xA0;</p><h3 id="netcat-based-transfer">Netcat-based&#xA0;transfer&#xA0;</h3><p><code>nc</code>&#xA0;(netcat) is&#xA0;a well-known&#xA0;general-purpose networking utility that ships with macOS. It can be&#xA0;utilized&#xA0;to open arbitrary TCP and UDP connections, listen&#xA0;on&#xA0;ports, and pass data between them.&#xA0;</p><p>The simplest pattern involves piping commands directly into a&#xA0;netcat&#xA0;listener. On the target, a listener is&#xA0;established&#xA0;that pipes incoming data directly to&#xA0;<code>sh</code>:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-17.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="354" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-17.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-17.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-17.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-17.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 17.&#xA0;Netcat&#xA0;listener&#xA0;established&#xA0;on&#xA0;victim&#xA0;machine.</span></figcaption></figure><p>From the attacking machine, a command is then echoed into&#xA0;<code>nc</code>&#xA0;targeting the victim&apos;s IP and port:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-18.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="354" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-18.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-18.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-18.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-18.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 18.&#xA0;Command&#xA0;execution via&#xA0;Netcat&#xA0;(attacker&#xA0;side).</span></figcaption></figure><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-19.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="556" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-19.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-19.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-19.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-19.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 19.&#xA0;Command&#xA0;execution via&#xA0;Netcat&#xA0;(victim&#xA0;side).</span></figcaption></figure><p>The attacker sends&#xA0;the&#xA0;<code>curl google.com</code>&#xA0;command over the wire, which is caught by the&#xA0;victim&apos;s&#xA0;listener and executed by&#xA0;<code>sh</code>. The resulting output confirms successful execution on the target.&#xA0;</p><p>Netcat&#xA0;can also&#xA0;facilitate&#xA0;file transfers through several different methods. An attacker could invoke a fetch to a remote system where a script or payload is&#xA0;hosted, or&#xA0;start a simple HTTP server on their own machine to perform ad hoc tool transfer.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-20.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="354" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-20.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-20.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-20.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-20.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 20.&#xA0;Serving&#xA0;files via&#xA0;netcat&#xA0;(Attacker Terminal 1).</span></figcaption></figure><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-21.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="394" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-21.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-21.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-21.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-21.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 21.&#xA0;Initiating&#xA0;file&#xA0;transfer via&#xA0;Netcat&#xA0;(Attacker Terminal 2).</span></figcaption></figure><h3 id="git-based-transfer">Git-based&#xA0;transfer&#xA0;</h3><p><code>git</code>&#xA0;is a version control system ubiquitous in software development. Its prevalence on developer machines and reliance on SSH as a transport make&#xA0;<code>git push</code>&#xA0;a practical file transfer mechanism. The technique requires initializing a repository on the target and setting&#xA0;<code>receive.denyCurrentBranch&#xA0;updateInstead</code>.&#xA0;By default,&#xA0;<code>git</code>&#xA0;refuses&#xA0;pushes&#xA0;to a branch that is currently checked out on the remote. This setting overrides that behavior and updates the working tree on push, landing files on disk the moment the operation completes.&#xA0;</p><p>First, a receiving repository is initialized on the target over SSH:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-22.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="596" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-22.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-22.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-22.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-22.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 22.&#xA0;Initializing a Git&#xA0;repository on the&#xA0;target.</span></figcaption></figure><p>On the attacker, a local repository is created with the payload, and the remote is pointed at the target:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-23.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="596" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-23.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-23.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-23.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-23.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 23.&#xA0;Pushing&#xA0;payloads to the&#xA0;target via Git.&#xA0;</span></figcaption></figure><p>After the push,&#xA0;&#x201C;script.sh&#x201D;&#xA0;exists on the target at&#xA0;&#x201C;~/repos/project/script.sh&#x201D;.&#xA0;Additional&#xA0;file transfers only require adding new files, committing, and pushing again. Because&#xA0;<code>git</code>&#xA0;operates&#xA0;over SSH, the transfer is encrypted and uses the same authentication&#xA0;established&#xA0;for command execution.&#xA0;</p><h3 id="tftp-standard-and-unprivileged">TFTP (Standard and&#xA0;unprivileged)&#xA0;</h3><p>TFTP (Trivial File Transfer Protocol) is a lightweight, unauthenticated file transfer protocol that&#xA0;operates&#xA0;over UDP. macOS includes both a TFTP server and client. The server is not active by default but can be started through&#xA0;<code>launchd</code>.&#xA0;</p><p>With root access on the target, the system&apos;s built-in TFTP&#xA0;plist&#xA0;activates the server in a single command:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-24.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="354" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-24.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-24.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-24.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-24.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 24.&#xA0;Activating the&#xA0;native TFTP&#xA0;server.</span></figcaption></figure><p>This serves&#xA0;&#x201C;/private/tftpboot&#x201D;&#xA0;on the standard TFTP port (UDP 69). The TFTP system&#xA0;plist&#xA0;does not provide the&#xA0;<code>-w</code>&#xA0;flag to the&#xA0;<code>tftpd</code>&#xA0;process. Without it, the server only allows&#xA0;writes to&#xA0;files that already exist. A placeholder&#xA0;file must be created on the target for each file being transferred:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-25.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="394" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-25.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-25.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-25.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-25.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 25.&#xA0;Creating a&#xA0;placeholder&#xA0;file for TFTP&#xA0;transfer.</span></figcaption></figure><p>From the attacker, the payload is pushed to the target:&#xA0;</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-26.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="516" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-26.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-26.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-26.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-26.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 26.&#xA0;Pushing&#xA0;payload to&#xA0;target via TFTP.</span></figcaption></figure><p>In a post-exploitation scenario without root access,&#xA0;<code>tftpd</code>&#xA0;can still be deployed by loading a user-created&#xA0;plist&#xA0;from&#xA0;&#x201C;/tmp&#x201D;&#xA0;on a non-standard port. This variant passes the&#xA0;<code>tftpd&#xA0;-w</code>&#xA0;flag, which allows write requests to create new files, removing the placeholder requirement.&#xA0;</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-27.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="1926" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-27.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-27.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-27.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-27.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 27.&#xA0;Non-root TFTP&#xA0;server&#xA0;deployment.</span></figcaption></figure><h3 id="snmp-trap-based-transfer">SNMP&#xA0;trap-based&#xA0;transfer&#xA0;</h3><p>SNMP (Simple Network Management Protocol) is used for monitoring and managing network devices. SNMP traps are unsolicited notifications sent from agents to a management station over UDP port 162. The trap payload can carry arbitrary string data under custom OIDs, which can be repurposed as a data transfer channel. macOS ships with the necessary&#xA0;<code>net-snmp</code>&#xA0;tools:&#xA0;<code>snmptrap</code>&#xA0;(&#x201C;/usr/bin/snmptrap&#x201D;) on the sender and&#xA0;<code>snmptrapd</code>&#xA0;(&#x201C;/usr/sbin/snmptrapd&#x201D;) on the&#xA0;receiver.&#xA0;</p><p>The approach works by&#xA0;Base64 encoding a file, splitting it into fixed-size chunks, and sending each chunk as an SNMP trap payload under a custom OID in the private enterprise space (&#x201C;1[.]3[.]6[.]1[.]4[.]1[.]99999&#x201D;). A trap handler on the receiving end reassembles the chunks and decodes the file. The protocol uses three message types:&#xA0;&#x201C;FILENAME&#x201D;&#xA0;signals the start of a&#xA0;transfer,&#xA0;&#x201C;DATA&#x201D;&#xA0;carries a&#xA0;Base64 chunk, and&#xA0;&#x201C;END&#x201D;&#xA0;triggers reassembly.&#xA0;</p><p>On the receiver, a trap handler processes incoming traps:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-28.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="1644" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-28.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-28.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-28.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-28.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 28.&#xA0;SNMP&#xA0;trap&#xA0;handler&#xA0;logic.</span></figcaption></figure><p>The&#xA0;<code>snmptrapd</code>&#xA0;daemon is then configured on the target to route all incoming traps to the handler and started in the foreground:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-29.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="516" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-29.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-29.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-29.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-29.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 29.&#xA0;Configuring the&#xA0;snmptrapd&#xA0;daemon.</span></figcaption></figure><p>On the sender, a script handles the encoding, chunking, and transmission. Each chunk is sent as a separate SNMP trap with a short delay between sends to avoid overwhelming the receiver:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-30.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="1482" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-30.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-30.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-30.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-30.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 30.&#xA0;Script for SNMP&#xA0;chunking and&#xA0;transmission.&#xA0;</span></figcaption></figure><p>The sender&#xA0;initiates&#xA0;the transfer:&#xA0;</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-31.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="596" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-31.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-31.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-31.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-31.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 31.&#xA0;Initiating&#xA0;data&#xA0;transfer via SNMP&#xA0;traps.</span></figcaption></figure><p>The target receives the transfer:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-32.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="476" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-32.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-32.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-32.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-32.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 32.&#xA0;Successful&#xA0;payload&#xA0;reassembly on&#xA0;target.</span></figcaption></figure><p>The matching MD5 hashes confirm the file was transferred and reassembled intact.&#xA0;</p><h3 id="socat-file-transfer">Socat&#xA0;file&#xA0;transfer&#xA0;</h3><p>The&#xA0;<code>socat</code>&#xA0;shell&#xA0;established&#xA0;in&#xA0;the&#xA0;above&#xA0;&quot;socat&#xA0;remote&#xA0;shell&#x201D; section&#xA0;can also serve as a file transfer channel. Because the listener provides a fully interactive&#xA0;bash session, file&#xA0;contents&#xA0;can be written to the remote host by injecting a heredoc through&#xA0;the connection. This means&#xA0;<code>socat</code>&#xA0;alone handles both remote command execution and tool transfer without requiring any&#xA0;additional&#xA0;services or listeners.&#xA0;</p><p>With the&#xA0;<code>socat</code>&#xA0;listener running on the target, the attacker delivers a file by piping a heredoc-wrapped&#xA0;<code>cat</code>&#xA0;command through a&#xA0;<code>socat</code>&#xA0;connection:</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-33.png" class="kg-image" alt="Bad Apples: Weaponizing native macOS primitives for movement and execution" loading="lazy" width="1750" height="758" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure-33.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure-33.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure-33.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure-33.png 1750w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 33.&#xA0;File&#xA0;delivery via&#xA0;socat&#xA0;heredoc&#xA0;injection.</span></figcaption></figure><h2 id="detection-and-defensive-considerations">Detection and&#xA0;defensive&#xA0;considerations&#xA0;</h2><p>Defending against&#xA0;LOTL&#xA0;techniques requires a shift from simple network alerts to granular process and metadata analysis.&#xA0;</p><h3 id="network-indicators">Network&#xA0;indicators&#xA0;</h3><p>Inbound TCP traffic on port 3031 (the&#xA0;&#x201C;eppc&#x201D;&#xA0;port) and unusual SNMP/TFTP traffic on internal LAN segments should be&#xA0;monitored&#xA0;for potential unauthorized activity.&#xA0;</p><h3 id="endpoint-indicators-evm">Endpoint&#xA0;indicators (EVM)&#xA0;</h3><p>Through mapping to the&#xA0;<a href="https://schema.ocsf.io/" rel="noreferrer noopener"><u>Open Cybersecurity Schema Framework (OCSF)</u></a>, an open-source effort to deliver a simplified and vendor-agnostic taxonomy for security telemetry, high-fidelity signatures for these behaviors were&#xA0;identified:&#xA0;</p><ul><li><strong>Suspicious</strong>&#xA0;<strong>lineage:</strong>&#xA0;Process trees following the pattern&#xA0;<code>launchd</code>&#xA0;-&gt;&#xA0;<code>AppleEventsD</code>&#xA0;-&gt;&#xA0;<code>Terminal</code>&#xA0;-&gt;&#xA0;<code>sh/bash</code>.&#xA0;</li><li><strong>Metadata</strong>&#xA0;<strong>monitoring:</strong>&#xA0;Frequent or unusual calls to&#xA0;<code>mdls</code>&#xA0;or writes to&#xA0;&#x201C;com.apple.metadata:kMDItemFinderComment&#x201D;.&#xA0;</li><li><strong>Command</strong>&#xA0;<strong>line</strong>&#xA0;<strong>anomalies:</strong>&#xA0;<code>base64 --decode</code>&#xA0;commands originating from GUI applications or&#xA0;<code>osascript</code>&#xA0;executions&#xA0;containing&#xA0;&#x201C;of&#xA0;machine &quot;eppc://...&quot;&#x201D;&#xA0;arguments.&#xA0;</li></ul><h3 id="native-security-controls-and-hardening-recommendations">Native&#xA0;security&#xA0;controls and&#xA0;hardening&#xA0;recommendations&#xA0;</h3><p>Several built-in macOS security mechanisms can be configured to mitigate the risks associated with native primitive abuse:&#xA0;</p><ul><li><strong>Transparency, Consent, and Control (TCC)</strong>&#xA0;<strong>restrictions:</strong>&#xA0;The &quot;Automation&quot; category within TCC is designed to regulate inter-application communication. By enforcing strict TCC policies via Mobile Device Management (MDM), unauthorized Apple Events between applications&#xA0;&#x2014;&#xA0;such as a script&#xA0;attempting&#xA0;to control&#xA0;&#x201C;Terminal.app&#x201D;&#xA0;or&#xA0;&#x201C;Finder&#x201D;&#xA0;&#x2014;&#xA0;can be blocked.&#xA0;</li><li><strong>MDM Policy Enforcement:</strong>&#xA0;RAS&#xA0;and Remote Login (SSH) should be disabled by default across the fleet. These services can be managed and restricted using MDM configuration profiles (e.g., the&#xA0;&#x201C;com.apple.RemoteAppleEvents&#x201D;payload) to ensure they are only active on authorized administrative hosts.&#xA0;</li><li><strong>Service</strong>&#xA0;<strong>hardening:</strong>&#xA0;Unnecessary network-facing services, such as&#xA0;<code>tftpd</code>&#xA0;and&#xA0;<code>snmpd</code>,&#xA0;should be explicitly disabled. The removal of these&#xA0;<code>launchd</code>&#xA0;plists&#xA0;from&#xA0;&#x201C;/System/Library/LaunchDaemons&#x201D;&#xA0;(where&#xA0;permitted&#xA0;by System Integrity Protection) or the use of&#xA0;<code>launchctl&#xA0;disable</code>&#xA0;commands&#xA0;prevents&#xA0;their use as ad-hoc data transfer channels.&#xA0;</li><li><strong>Application</strong>&#xA0;<strong>firewall</strong>&#xA0;<strong>and Stealth Mode:</strong>&#xA0;The built-in macOS application&#xA0;firewall&#xA0;should be enabled and configured in &quot;Stealth Mode.&quot; This configuration ensures the device does not respond to unsolicited ICMP or connection attempts on common ports, reducing the visibility of the endpoint during internal reconnaissance.&#xA0;</li></ul><h2 id="conclusion">Conclusion&#xA0;</h2><p>The research presented in this article underscores&#xA0;a fundamental&#xA0;reality of modern endpoint security. The same primitives designed for administrative convenience and system automation are often the most potent tools in an&#xA0;adversary&apos;s arsenal. By moving beyond traditional exploit-based attacks and instead&#xA0;LOTL,&#xA0;attackers can&#xA0;operate&#xA0;within the noise of legitimate system activity.</p><p>From the weaponization of the&#xA0;&#x201C;eppc&#x201D;&#xA0;protocol to the creative abuse of Spotlight metadata and SNMP traps, it is clear that the macOS attack surface is both vast and nuanced. These techniques&#xA0;demonstrate&#xA0;that even within a &quot;walled garden&quot; ecosystem, native pathways for movement and execution remain accessible to those who understand the underlying architecture.&#xA0;</p><p>For defenders, the primary takeaway is that visibility&#xA0;remains&#xA0;the most effective deterrent. By shifting focus from static file analysis to the monitoring of process lineage, inter-process communication, and metadata anomalies, these &quot;bad Apples&quot; can be&#xA0;identified&#xA0;and neutralized. As macOS continues its expansion into the enterprise core, the documentation and detection of these native techniques must remain a priority for the security community.&#xA0;</p>]]></content:encoded></item><item><title><![CDATA[Foxit, LibRaw vulnerabilities]]></title><description><![CDATA[<p>Cisco Talos&#x2019; Vulnerability Discovery &amp; Research team recently disclosed one Foxit Reader vulnerability, and six LibRaw file reader vulnerabilities.</p><p>The vulnerabilities mentioned in this blog post have been patched by their respective vendors, all in adherence to<a href="https://sec.cloudapps.cisco.com/security/center/resources/vendor_vulnerability_policy.html"> <u>Cisco&#x2019;s third-party vulnerability disclosure policy</u></a>.&#xA0;&#xA0;&#xA0;&#xA0;</p><p>For</p>]]></description><link>https://blog.talosintelligence.com/foxit-libraw-vulnerabilities/</link><guid isPermaLink="false">69dd0369ab91ce0001a70dc9</guid><category><![CDATA[Vulnerability Roundup]]></category><dc:creator><![CDATA[Kri Dontje]]></dc:creator><pubDate>Thu, 16 Apr 2026 19:00:24 GMT</pubDate><media:content url="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/vuln_roundup.jpg" medium="image"/><content:encoded><![CDATA[<img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/vuln_roundup.jpg" alt="Foxit, LibRaw vulnerabilities"><p>Cisco Talos&#x2019; Vulnerability Discovery &amp; Research team recently disclosed one Foxit Reader vulnerability, and six LibRaw file reader vulnerabilities.</p><p>The vulnerabilities mentioned in this blog post have been patched by their respective vendors, all in adherence to<a href="https://sec.cloudapps.cisco.com/security/center/resources/vendor_vulnerability_policy.html"> <u>Cisco&#x2019;s third-party vulnerability disclosure policy</u></a>.&#xA0;&#xA0;&#xA0;&#xA0;</p><p>For Snort coverage that can detect the exploitation of these vulnerabilities, download the latest rule sets from<a href="https://snort.org/"> <u>Snort.org</u></a>, and our latest Vulnerability Advisories are always posted on<a href="https://talosintelligence.com/vulnerability_reports"> <u>Talos Intelligence&#x2019;s website</u></a>.</p><h2 id="foxit-use-after-free-vulnerability"><strong>Foxit use-after-free vulnerability</strong></h2><p><em>Discovered by KPC of Cisco Talos.</em></p><p>Foxit Reader allows users to view, edit, and sign PDF documents, among other features. Foxit aims to be one of the most feature-rich PDF readers on the market, and contains many similar functions to that of Adobe Acrobat Reader.</p><p><a href="https://talosintelligence.com/vulnerability_reports/TALOS-2026-2365" rel="noreferrer">TALOS-2026-2365</a> (CVE-2026-3779) is a use-after-free vulnerability in the way Foxit Reader handles an Array object. A specially crafted JavaScript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability.</p><h2 id="libraw-heap-based-buffer-overflow-and-integer-overflow-vulnerabilities"><strong>LibRaw heap-based buffer overflow and integer overflow vulnerabilities</strong></h2><p><em>Discovered by Francesco Benvenuto of Cisco Talos.</em></p><p>LibRaw is a library and user interface for processing RAW file types and metadata created by digital cameras. Talos analysts found 6 vulnerabilities in LibRaw. </p><p><a href="https://talosintelligence.com/vulnerability_reports/TALOS-2026-2330" rel="noreferrer">TALOS-2026-2330</a> (CVE-2026-20911), <a href="https://talosintelligence.com/vulnerability_reports/TALOS-2026-2331" rel="noreferrer">TALOS-2026-2331</a> (CVE-2026-21413), <a href="https://talosintelligence.com/vulnerability_reports/TALOS-2026-2358" rel="noreferrer">TALOS-2026-2358</a> (CVE-2026-20889), and <a href="https://talosintelligence.com/vulnerability_reports/TALOS-2026-2359" rel="noreferrer">TALOS-2026-2359</a> (CVE-2026-24660) are heap-based buffer overflow vulnerabilities in LibRaw, and <a href="https://talosintelligence.com/vulnerability_reports/TALOS-2026-2363" rel="noreferrer">TALOS-2026-2363</a> (CVE-2026-24450) and <a href="https://talosintelligence.com/vulnerability_reports/TALOS-2026-2364" rel="noreferrer">TALOS-2026-2364</a> (CVE-2026-20884) are integer overflow vulnerabilities. Specially crafted malicious files can lead to heap buffer overflow in all cases. An attacker can provide a malicious file to trigger these vulnerabilities. </p>]]></content:encoded></item><item><title><![CDATA[The Q1 vulnerability pulse]]></title><description><![CDATA[Thor provides an overview of the Q1 2026 vulnerability statistics, highlighting key trends in legacy CVEs and the evolving impact of AI on the threat landscape.]]></description><link>https://blog.talosintelligence.com/the-q1-vulnerability-pulse/</link><guid isPermaLink="false">69dfae17645a220001422ae1</guid><category><![CDATA[Threat Source newsletter]]></category><dc:creator><![CDATA[Thorsten Rosendahl]]></dc:creator><pubDate>Thu, 16 Apr 2026 18:00:31 GMT</pubDate><media:content url="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/threat_source-2.jpg" medium="image"/><content:encoded><![CDATA[<img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/threat_source-2.jpg" alt="The Q1 vulnerability pulse"><p>Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xA0;</p><p>The first quarter of 2026 passed faster than a misconfigured&#xA0;firewall&#xA0;rule gets exploited &#x2014; and the last few weeks have been firmly stamped with the &quot;software supply chain compromise&quot; label, with headlines surrounding incidents involving&#xA0;<a href="https://www.aquasec.com/blog/trivy-supply-chain-attack-what-you-need-to-know" rel="noreferrer noopener"><u>Trivy</u></a>,<a href="https://checkmarx.com/blog/checkmarx-security-update" rel="noreferrer noopener"><u>Checkmark</u></a>,&#xA0;<a href="https://lwn.net/Articles/1064479/" rel="noreferrer noopener"><u>LiteLLM</u></a>,&#xA0;<a href="https://research.jfrog.com/post/team-pcp-strikes-again-telnyx-popular-library-hit/" rel="noreferrer noopener"><u>telnyx</u></a>&#xA0;and&#xA0;<a href="https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan" rel="noreferrer noopener"><u>axios</u></a>. This edition stays focused on vulnerability statistics, although you can view&#xA0;<a href="https://blog.talosintelligence.com/protecting-supply-chain-2026/" rel="noreferrer noopener"><u>Dave</u></a>&#xA0;and&#xA0;<a href="https://blog.talosintelligence.com/axois-npm-supply-chain-incident/" rel="noreferrer noopener"><u>Nick&apos;s</u></a>&#xA0;Talos blogs for more information about these incidents.&#xA0;</p><p>Known Exploited Vulnerabilities (KEVs) stayed&#xA0;roughly in&#xA0;line with 2025 numbers &#x2014; no dramatic spike, but no room for relief either.</p><figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/041526_threatsource_blog_KEVline.jpg" class="kg-image" alt="The Q1 vulnerability pulse" loading="lazy" width="1792" height="1056" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/041526_threatsource_blog_KEVline.jpg 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/041526_threatsource_blog_KEVline.jpg 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/041526_threatsource_blog_KEVline.jpg 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/041526_threatsource_blog_KEVline.jpg 1792w" sizes="(min-width: 720px) 720px"></figure><p>What&#xA0;<em>does</em>&#xA0;stand out? Networking gear accounted for 20% of KEV-related vulnerabilities, and that number is expected to climb as the year progresses. If the trend from 2025 holds, this&#xA0;won&apos;t&#xA0;be the high-water mark.</p><figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/041526_threatsource_blog_pie.jpg" class="kg-image" alt="The Q1 vulnerability pulse" loading="lazy" width="1792" height="710" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/041526_threatsource_blog_pie.jpg 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/041526_threatsource_blog_pie.jpg 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/041526_threatsource_blog_pie.jpg 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/041526_threatsource_blog_pie.jpg 1792w" sizes="(min-width: 720px) 720px"></figure><p>Patch management&#xA0;remains&#xA0;one of the industry&apos;s most persistent challenges, and I understand all the operational complexity that comes with it. That said, it still stings to come across CVEs with disclosure dates reaching back to 2009 &#x2014; and&#xA0;roughly 25%&#xA0;of the CVEs&#xA0;we&apos;re&#xA0;tracking date to 2024 or earlier. Old vulnerabilities&#xA0;don&apos;t&#xA0;retire. They wait. It starts with visibility: Knowing&#xA0;what&apos;s&#xA0;actually running&#xA0;in your environment is the prerequisite for everything else.</p><figure class="kg-card kg-image-card"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/041526_threatsource_blog_CVEline.jpg" class="kg-image" alt="The Q1 vulnerability pulse" loading="lazy" width="1792" height="1056" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/041526_threatsource_blog_CVEline.jpg 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/041526_threatsource_blog_CVEline.jpg 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/041526_threatsource_blog_CVEline.jpg 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/041526_threatsource_blog_CVEline.jpg 1792w" sizes="(min-width: 720px) 720px"></figure><p>Overall CVE counts increased in Q1, with March showing the sharpest climb. Whether that reflects improved disclosure pipelines, increased researcher activity,&#xA0;ora&#xA0;genuine uptick in vulnerability density, the trend line from 2025&#xA0;hasn&apos;t&#xA0;flattened &#x2014; if anything,&#xA0;it&apos;s&#xA0;still pointing up.&#xA0;</p><p>Using the keyword&#xA0;methodology&#xA0;described&#xA0;<a href="https://blog.talosintelligence.com/patch-track-repeat-the-2025-cve-retrospective/" rel="noreferrer noopener"><u>here</u></a>, 121 CVEs with AI relevance were&#xA0;identified&#xA0;in Q1 &#x2014; more than Q1 2025, though consistent with what adoption trends would predict. As AI components become more deeply embedded across the software stack, this number will keep climbing.&#xA0;</p><p>Given the recent developments with models like&#xA0;the&#xA0;Mythos&#xA0;preview and the industry teaming up in initiatives like&#xA0;<a href="https://www.anthropic.com/glasswing" rel="noreferrer noopener"><u>Project Glasswing</u></a>,&#xA0;I&apos;m&#xA0;curious how the trajectory will change moving forward. If you&#xA0;haven&apos;t&#xA0;read about it:&#xA0;</p><p><em>&#x201C;During our testing, we found that Mythos Preview is capable of identifying and then exploiting zero-day vulnerabilities in every major operating system and every major web browser when directed by a user to do so.&#x201D; -</em>&#xA0;<a href="https://red.anthropic.com/2026/mythos-preview/" rel="noreferrer noopener"><em><u>Anthropic Frontier Red Team</u></em></a></p><p>That&apos;s&#xA0;a substantial capability&#xA0;jump&#xA0;in agentic coding and reasoning, which eventually needs to be implemented early in the development lifecycle. And as&#xA0;<a href="https://blogs.cisco.com/news/rising-to-the-era-of-ai-powered-cyber-defense" rel="noreferrer noopener"><u>Anthony</u></a>&#xA0;points&#xA0;out,&#xA0;those&#xA0;capabilities will become available to adversaries. Read <a href="https://www.cisco.com/c/dam/en_us/about/doing_business/trust-center/docs/cisco-defending-against-ai-attacks-guidance.pdf" rel="noreferrer">Cisco&apos;s guidance</a> on defending in the age of AI-enabled attacks for more.</p><p>Will we see fewer CVEs or even more negative times-to-exploit (TTEs)?&#xA0;</p><p>It&apos;s&#xA0;on us. Defenders need to get ahead of the adversaries, and at the same time, we need to pay attention to (sometimes decade-old) vulnerabilities.</p><h2 id="the-one-big-thing">The one&#xA0;big thing&#xA0;</h2><p>Cisco Talos has&#xA0;<a href="https://blog.talosintelligence.com/the-n8n-n8mare/" rel="noreferrer noopener"><u>identified</u>&#xA0;<u>a significant increase</u></a>&#xA0;in the abuse of n8n, an AI workflow automation platform, to&#xA0;facilitate&#xA0;malicious campaigns including malware delivery and device fingerprinting. Attackers are weaponizing the platform&#x2019;s URL-exposed webhooks to create phishing lures that bypass traditional security filters by&#xA0;leveraging&#xA0;trusted, legitimate infrastructure. By masking malicious payloads as standard data streams, these campaigns effectively turn productivity tools into delivery vehicles for remote access trojans and other cyber threats.&#xA0;</p><h3 id="why-do-i-care">Why do I care?&#xA0;</h3><p>The abuse of legitimate automation platforms exploits the inherent trust organizations&#xA0;place&#xA0;in these tools, which often neutralizes traditional perimeter-based security defenses. Because these platforms are designed for flexibility and seamless integration, they allow attackers to dynamically tailor payloads and evade detection through standard reputation-based filtering.&#xA0;</p><h3 id="so-now-what">So now what?&#xA0;</h3><p>Move beyond static domain blocking and implement behavioral detection that&#xA0;alerts on&#xA0;anomalous traffic patterns directed toward automation platforms. Restrict endpoint communication with these services to only those explicitly authorized by the organization&#x2019;s established internal workflows. Finally,&#xA0;utilize&#xA0;AI-driven email security solutions to analyze the semantic intent of incoming messages and proactively share indicators of compromise, such as specific webhook structures, with threat intelligence communities.&#xA0;</p><h2 id="top-security-headlines-of-the-week">Top security headlines of the week&#xA0;</h2><p><strong>Adobe</strong>&#xA0;<strong>patches</strong>&#xA0;<strong>actively</strong>&#xA0;<strong>exploited</strong>&#xA0;<strong>zero-day</strong>&#xA0;<strong>that</strong>&#xA0;<strong>lingered for</strong>&#xA0;<strong>months</strong>&#xA0;<br>Adobe patched an arbitrary code execution vulnerability in the latest versions of its Acrobat and Reader for Windows and macOS,&#xA0;nearly four&#xA0;months after an attacker first appeared to have begun exploiting it. (<a href="https://www.darkreading.com/application-security/adobe-patches-actively-exploited-zero-day" rel="noreferrer noopener"><u>Dark Reading</u></a>)&#xA0;</p><p><strong>Fake Claude website distributes</strong>&#xA0;<strong>PlugX</strong>&#xA0;<strong>RAT</strong>&#xA0;<br>A threat actor created a site that hosts a download link pointing to a ZIP archive allegedly&#xA0;containing&#xA0;a pro version of the LLM.&#xA0;(<a href="https://www.securityweek.com/fake-claude-website-distributes-plugx-rat/" rel="noreferrer noopener"><u>SecurityWeek</u></a>)&#xA0;</p><p><strong>Sweden blames Russian hackers for attempting &#x201C;destructive&#x201D;</strong>&#xA0;<strong>cyber attack</strong>&#xA0;<strong>on thermal plant</strong>&#xA0;<br>Sweden&#x2019;s minister of civil defense said during a press conference on Wednesday that the attempted attack happened in early 2025 and attributed the incident to hackers with &#x201C;connections to Russian intelligence and security services.&#x201D; (<a href="https://techcrunch.com/2026/04/15/sweden-blames-russian-hackers-for-attempting-destructive-cyberattack-on-thermal-plant/" rel="noreferrer noopener"><u>TechCrunch</u></a>)&#xA0;</p><p><strong>FBI and Indonesian police dismantle W3LL phishing network behind $20M fraud attempts</strong>&#xA0;<br>The W3LL phishing kit, advertised for a fee of about $500, allowed criminals to mimic legitimate login pages to deceive victims into handing over their credentials, allowing the attackers to seize control of their accounts. (<a href="https://thehackernews.com/2026/04/fbi-and-indonesian-police-dismantle.html" rel="noreferrer noopener"><u>The Hacker News</u></a>)&#xA0;</p><p><strong>Google API keys in Android apps expose Gemini endpoints to unauthorized access</strong>&#xA0;<br>Armed with the key, an attacker could access private files and cached content, make arbitrary Gemini API calls, exhaust API&#xA0;quotas&#xA0;and disrupt legitimate services, and access any data on Gemini&#x2019;s file storage. (<a href="https://www.securityweek.com/google-api-keys-in-android-apps-expose-gemini-endpoints-to-unauthorized-access/?utm_source=tldrinfosec" rel="noreferrer noopener"><u>SecurityWeek</u></a>)&#xA0;</p><h2 id="can%E2%80%99t-get-enough-talos">Can&#x2019;t&#xA0;get enough Talos?&#xA0;</h2><p><a href="https://blog.talosintelligence.com/more-than-pretty-pictures-wendy-bishop-on-visual-storytelling-in-tech" rel="noreferrer noopener"><strong><u>More than pretty pictures: Wendy Bishop on visual storytelling in tech</u></strong></a>&#xA0;<br>From her early beginnings in web design and journalism to leading the creative vision for Talos, Wendy talks about the unique challenges and rewards of bridging the gap between artistic expression and highly technical research.&#xA0;</p><p><a href="https://blog.talosintelligence.com/powmix-botnet-targets-czech-workforce" rel="noreferrer noopener"><strong><u>PowMix botnet targets Czech workforce</u></strong></a>&#xA0;<br>Cisco Talos discovered an ongoing malicious campaign affecting Czech workers with a previously undocumented botnet we call &#x201C;PowMix.&#x201D; It&#xA0;employs&#xA0;random beaconing intervals to evade the&#xA0;network&#xA0;signature detections.&#xA0;</p><p><a href="https://blog.talosintelligence.com/state-sponsored-threats-different-objectives-similar-access-paths/" rel="noreferrer noopener"><strong><u>APTs: Different</u></strong>&#xA0;<strong><u>objectives, similar access paths</u></strong></a>&#xA0;&#xA0;<br>Across the Talos 2025 Year in Review, state-sponsored threat activity from China, Russia, North Korea, and Iran all had varying motivations, such as espionage, disruption, financial gain, and geopolitical influence.&#xA0;</p><h2 id="upcoming-events-where-you-can-find-talos">Upcoming events where you can find Talos&#xA0;</h2><ul><li><a href="https://pivotcon.org/" rel="noreferrer noopener"><u>PIVOTcon</u></a>&#xA0;(May 6 &#x2013; 8) M&#xE1;laga, Spain&#xA0;</li><li><a href="https://www.offensivecon.org/" rel="noreferrer noopener"><u>OffensiveCon</u></a>&#xA0;(May 15 &#x2013; 16)&#xA0;Berlin, Germany&#xA0;</li></ul><h2 id="most-prevalent-malware-files-from-talos-telemetry-over-the-past-week">Most prevalent malware files from Talos telemetry over the past week&#xA0;</h2><p><strong>SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507</strong>&#xA0;&#xA0;<br>MD5: 2915b3f8b703eb744fc54c81f4a9c67f&#xA0;&#xA0;<br>Talos Rep:&#xA0;<a href="https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507" rel="noreferrer noopener"><u>https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507</u></a>&#xA0;<br>Example Filename: VID001.exe&#xA0;&#xA0;<br>Detection Name:&#xA0;Win.Worm.Coinminer::1201**&#xA0;</p><p><strong>SHA256: 96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974</strong>&#xA0;&#xA0;<br>MD5: aac3165ece2959f39ff98334618d10d9&#xA0;&#xA0;<br>Talos Rep:&#xA0;<a href="https://talosintelligence.com/talos_file_reputation?s=96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974" rel="noreferrer noopener"><u>https://talosintelligence.com/talos_file_reputation?s=96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974</u></a>&#xA0;<br>Example Filename: d4aa3e7010220ad1b458fac17039c274_63_Exe.exe&#xA0;&#xA0;<br>Detection Name:&#xA0;W32.Injector:Gen.21ie.1201&#xA0;</p><p><strong>SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59</strong>&#xA0;&#xA0;<br>MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a&#xA0;&#xA0;<br>Talos Rep: https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59&#xA0;&#xA0;<br>Example Filename:&#xA0;APQ9305.dll&#xA0;&#xA0;<br>Detection Name: Auto.90B145.282358.in02&#xA0;</p><p><strong>SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91</strong>&#xA0;&#xA0;<br>MD5: 7bdbd180c081fa63ca94f9c22c457376&#xA0;&#xA0;<br>Talos Rep:&#xA0;<a href="https://talosintelligence.com/talos_file_reputation?s=a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91" rel="noreferrer noopener"><u>https://talosintelligence.com/talos_file_reputation?s=a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91</u></a>&#xA0;<br>Example Filename:&#xA0;d4aa3e7010220ad1b458fac17039c274_62_Exe.exe&#xA0;&#xA0;<br>Detection Name:&#xA0;Win.Dropper.Miner::95.sbx.tg**&#xA0;</p><p><strong>SHA256: 38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55</strong>&#xA0;&#xA0;<br>MD5: 41444d7018601b599beac0c60ed1bf83&#xA0;&#xA0;<br>Talos Rep: https://talosintelligence.com/talos_file_reputation?s=38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55&#xA0;&#xA0;<br>Example Filename:&#xA0;content.js&#xA0;&#xA0;<br>Detection Name: W32.38D053135D-95.SBX.TG&#xA0;</p><p><strong>SHA256: 3c1dbc3f56e91cc79f0014850e773a7f12bbfef06680f08f883b2bf12873eccc</strong>&#xA0;<br>MD5: d749e0f8f2cd4e14178a787571534121&#xA0;&#xA0;<br>Talos Rep:&#xA0;<a href="https://talosintelligence.com/talos_file_reputation?s=3c1dbc3f56e91cc79f0014850e773a7f12bbfef06680f08f883b2bf12873eccc" rel="noreferrer noopener"><u>https://talosintelligence.com/talos_file_reputation?s=3c1dbc3f56e91cc79f0014850e773a7f12bbfef06680f08f883b2bf12873eccc</u></a>&#xA0;<br>Example Filename:&#xA0;Unconfirmed 280575.crdownload.exe&#xA0;&#xA0;<br>Detection Name: W32.3C1DBC3F56-90.SBX.TG</p>]]></content:encoded></item><item><title><![CDATA[PowMix botnet targets Czech workforce]]></title><description><![CDATA[Cisco Talos discovered an ongoing malicious campaign, operating since at least December 2025, affecting a broader workforce in the Czech Republic with a previously undocumented botnet we call “PowMix.” ]]></description><link>https://blog.talosintelligence.com/powmix-botnet-targets-czech-workforce/</link><guid isPermaLink="false">69de95aa645a22000142298d</guid><category><![CDATA[Threat Spotlight]]></category><category><![CDATA[Cisco Talos Antivirus]]></category><category><![CDATA[Cisco Talos DNS Security]]></category><category><![CDATA[Cisco Talos Network Intrusion Prevention]]></category><dc:creator><![CDATA[Chetan Raghuprasad]]></dc:creator><pubDate>Thu, 16 Apr 2026 10:00:33 GMT</pubDate><media:content url="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/threat_spotlight-1.jpg" medium="image"/><content:encoded><![CDATA[<ul><li>Cisco Talos&#xA0;discovered&#xA0;an ongoing malicious campaign,&#xA0;operating&#xA0;since&#xA0;at least&#xA0;December 2025, affecting a broader workforce in the Czech Republic with a&#xA0;previously&#xA0;undocumented botnet we&#xA0;call&#xA0;&#x201C;PowMix.&#x201D;&#xA0;</li><li>PowMix&#xA0;employs randomized&#xA0;command-and-control&#xA0;(C2)&#xA0;beaconing&#xA0;intervals,&#xA0;rather than&#xA0;persistent connection&#xA0;to the C2 server,&#xA0;to evade the&#xA0;network signature detections.&#xA0;</li><li>PowMix&#xA0;embeds the encrypted heartbeat data along with&#xA0;unique identifiers of the victim machine into the C2 URL paths,&#xA0;mimicking&#xA0;legitimate&#xA0;REST API&#xA0;URLs.&#xA0;</li><li>PowMix&#xA0;has the capability to&#xA0;remotely&#xA0;update&#xA0;the new&#xA0;C2&#xA0;domain&#xA0;to the botnet configuration file&#xA0;dynamically.&#xA0;</li><li>Talos observed a few&#xA0;tactical similarities of&#xA0;the current campaign with&#xA0;the&#xA0;<a href="https://research.checkpoint.com/2025/zipline-phishing-campaign/#:~:text=This%20suggests%20that%20the%20malicious,agent%2C%20or%20other%20contextual%20indicators." rel="noreferrer noopener"><u>ZipLine</u></a>&#xA0;campaign,&#xA0;including&#xA0;the payload delivery mechanism&#xA0;and the&#xA0;misuse&#xA0;of the legitimate cloud&#xA0;platform&#xA0;Heroku&#xA0;for C2 operations.</li></ul><hr><h2 id="victimology">Victimology&#xA0;&#xA0;</h2><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/threat_spotlight-1.jpg" alt="PowMix botnet targets Czech workforce"><p>Talos observed&#xA0;that an attacker targeted&#xA0;Czech&#xA0;organizations&#xA0;across various levels, based on the contents of the lure documents used by the attacker in the current campaign.</p><p>Impersonating&#xA0;the&#xA0;legitimate&#xA0;EDEKA brand and authentic regulatory frameworks&#xA0;such&#xA0;as the Czech Data Protection Act,&#xA0;the&#xA0;attacker deploys&#xA0;decoy&#xA0;documents&#xA0;with&#xA0;compliance-themed lures,&#xA0;potentially&#xA0;aimed at compromising&#xA0;victims from&#xA0;human resources (HR), legal, and recruitment&#xA0;agencies.&#xA0;In the lure documents, the attacker also used compensation data, as well as the&#xA0;legitimate legislative references,&#xA0;to enhance&#xA0;the&#xA0;authenticity of these&#xA0;decoy&#xA0;documents&#xA0;and to entice the job aspirants across diverse sectors like IT, finance, and&#xA0;logistics.&#xA0;</p><figure class="kg-card kg-gallery-card kg-width-wide kg-card-hascaption"><div class="kg-gallery-container"><div class="kg-gallery-row"><div class="kg-gallery-image"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/image-6.png" width="600" height="702" loading="lazy" alt="PowMix botnet targets Czech workforce" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/image-6.png 600w"></div><div class="kg-gallery-image"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/image-7-1.png" width="600" height="718" loading="lazy" alt="PowMix botnet targets Czech workforce" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/image-7-1.png 600w"></div></div></div><figcaption><p><span style="white-space: pre-wrap;">Figures 1 (left) and 2 (right). First pages of two decoy documents.</span></p></figcaption></figure><h2 id="ttps-overlaps-with-the-zipline-campaign">TTPs overlaps&#xA0;with the&#xA0;ZipLine&#xA0;campaign&#xA0;&#xA0;</h2><p>Talos&#xA0;observed a few&#xA0;tactical similarities&#xA0;employed in the current campaign with that of the <a href="https://research.checkpoint.com/2025/zipline-phishing-campaign/#:~:text=This%20suggests%20that%20the%20malicious,agent%2C%20or%20other%20contextual%20indicators." rel="noreferrer noopener"><u>ZipLine</u></a> campaign, reported by researchers from Check Point&#xA0;in&#xA0;August 2025.</p><p>In the current campaign, the&#xA0;PowMix&#xA0;botnet payload is delivered via an LNK&#xA0;triggered PowerShell loader that extracts it from a ZIP archive data blob, bypasses AMSI, and executes the decrypted script directly in memory. This campaign shares tactical overlaps with the older&#xA0;<a href="https://research.checkpoint.com/2025/zipline-phishing-campaign/#:~:text=This%20suggests%20that%20the%20malicious,agent%2C%20or%20other%20contextual%20indicators." rel="noreferrer noopener"><u>ZipLine</u></a>&#xA0;campaign (which deployed the&#xA0;MixShell&#xA0;malware), including identical ZIP-based payload concealment, Windows-scheduled task persistence, CRC32-based BOT ID generation, and the abuse of&#xA0;&#x201C;herokuapp.com&#x201D;&#xA0;for command-and-control&#xA0;(C2)&#xA0;infrastructure.&#xA0;Although there are overlaps in the tactics, the attacker&#x2019;s final&#xA0;payload was&#xA0;unobserved,&#xA0;and the&#xA0;intent&#xA0;remains&#xA0;unknown&#xA0;in this campaign.</p><h2 id="attack-summary">Attack&#xA0;summary&#xA0;&#xA0;</h2><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/PowMix.jpg" class="kg-image" alt="PowMix botnet targets Czech workforce" loading="lazy" width="2000" height="1109" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/PowMix.jpg 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/PowMix.jpg 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/PowMix.jpg 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w2400/2026/04/PowMix.jpg 2400w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 3. Attack summary flow chart.&#xA0;</span></figcaption></figure><p>The attack begins when a victim runs the Windows shortcut file contained within the received malicious ZIP file,&#xA0;potentially through&#xA0;a&#xA0;phishing&#xA0;email. This shortcut file triggers the execution of an embedded PowerShell loader script, which initially creates a&#xA0;copy&#xA0;of the ZIP file along with its contents in the victim&apos;s &#x201C;ProgramData&#x201D; folder. Subsequently, it loads the malicious ZIP file, extracts, and executes the embedded&#xA0;PowMix&#xA0;botnet payload directly in the victim&apos;s machine memory&#xA0;and starts to communicate with the botnet C2.&#xA0;</p><h2 id="powershell-loader-executes-powmix-in-memory">PowerShell&#xA0;loader&#xA0;executes&#xA0;PowMix&#xA0;in memory&#xA0;&#xA0;</h2><p>The first stage PowerShell script functions as a loader, and its execution routine&#xA0;is designed&#xA0;to bypass security controls and deliver a secondary payload. It begins by defining several obfuscated variables, including&#xA0;file&#xA0;name&#xA0;of the malicious ZIP file&#xA0;that was&#xA0;likely received&#xA0;via a phishing email. Then,&#xA0;the script&#xA0;dynamically constructs paths to&#xA0;the folders&#xA0;such as&#xA0;&#x201C;ProgramData&#x201D;&#xA0;and the&#xA0;user&#x2019;s&#xA0;&#x201C;Downloads&#x201D;&#xA0;folder to&#xA0;locate&#xA0;this ZIP file. Once the&#xA0;ZIP&#xA0;file is found,&#xA0;it extracts the contents&#xA0;to&#xA0;the&#xA0;&#x201C;ProgramData&#x201D;folder, effectively staging the environment for the next phase of the attack.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/data-src-image-129c9a39-fe3e-49a6-bf04-62e51d487f36-1-1.png" class="kg-image" alt="PowMix botnet targets Czech workforce" loading="lazy" width="624" height="398" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/data-src-image-129c9a39-fe3e-49a6-bf04-62e51d487f36-1-1.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/data-src-image-129c9a39-fe3e-49a6-bf04-62e51d487f36-1-1.png 624w"><figcaption><span style="white-space: pre-wrap;">Figure 4. Excerpt of the&#xA0;deobfuscated&#xA0;PowerShell Loader main function.&#xA0;</span></figcaption></figure><p>To evade detection, the script employs an AMSI (Antimalware Scan Interface) bypass technique. It uses&#xA0;a reflection&#xA0;technique&#xA0;to browse the loaded assemblies in the current process, specifically searching for the <code>AmsiUtils</code> class. Once&#xA0;located, it&#xA0;identifies the <code>amsiInitFailed</code> field and manually sets its value to true.&#xA0;This action deceives the Windows security subsystem into thinking that AMSI has not initialized, which disables real-time scanning of&#xA0;subsequent&#xA0;commands, enabling the script to run malicious code in memory without being detected by Windows Defender or other&#xA0;endpoint detection and response (EDR)&#xA0;solutions.&#xA0;</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/data-src-image-7a4fc13c-9eaf-4b6a-a3c6-ff048060f0e0-1.png" class="kg-image" alt="PowMix botnet targets Czech workforce" loading="lazy" width="624" height="412" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/data-src-image-7a4fc13c-9eaf-4b6a-a3c6-ff048060f0e0-1.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/data-src-image-7a4fc13c-9eaf-4b6a-a3c6-ff048060f0e0-1.png 624w"><figcaption><span style="white-space: pre-wrap;">Figure 5. Excerpt of the deobfuscated PowerShell Loader AMSI bypass function.&#xA0;</span></figcaption></figure><p>The script parses the malicious ZIP file to&#xA0;locate&#xA0;a specific marker that is&#xA0;hardcoded, such as&#xA0;<code>zAswKoK</code>. This marker is treated as a delimiter, enabling the extraction of a hidden, encoded command that is embedded within the&#xA0;ZIP&#xA0;file data&#xA0;blob.&#xA0;&#xA0;</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/image-2.png" class="kg-image" alt="PowMix botnet targets Czech workforce" loading="lazy" width="2000" height="836" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/image-2.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/image-2.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/image-2.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w2400/2026/04/image-2.png 2400w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 6.&#xA0;Malicious&#xA0;ZIP file data blob embedded with an obfuscated&#xA0;PowMix&#xA0;botnet.&#xA0;</span></figcaption></figure><p>Throughout this process, the script performs a series of string replacements, which include the removal of&#xA0;<code>#</code> symbols and the mapping of placeholders, such as <code>{cdm}</code>, to their corresponding specific file paths, reconstructing a&#xA0;functional&#xA0;secondary&#xA0;PowerShell&#xA0;script&#xA0;payload.&#xA0;Then it executes the secondary payload script in the victim machine memory using the <code>Invoke-Expression</code> (IEX) PowerShell command.&#xA0;&#xA0;</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/data-src-image-ebd82069-855b-4971-abac-77ce0f705ab8-1.png" class="kg-image" alt="PowMix botnet targets Czech workforce" loading="lazy" width="624" height="496" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/data-src-image-ebd82069-855b-4971-abac-77ce0f705ab8-1.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/data-src-image-ebd82069-855b-4971-abac-77ce0f705ab8-1.png 624w"><figcaption><span style="white-space: pre-wrap;">Figure 7. PowerShell loader excerpt with instructions to extract payload and execute.&#xA0;</span></figcaption></figure><h2 id="powmix-botnet">PowMix&#xA0;botnet&#xA0;</h2><p>Talos discovered that the secondary payload PowerShell script, which we call &#x201C;PowMix,&#x201D;&#xA0;is&#xA0;a previously unreported&#xA0;botnet&#xA0;designed&#xA0;for&#xA0;remote&#xA0;access, reconnaissance, and remote code execution.&#xA0;</p><p>The main execution of the script&#xA0;begins&#xA0;with an environment check to ensure it is running within a specific loader context&#xA0;at the placeholder <code>{cdm}</code>, which is the path of the Windows shortcut in the&#xA0;ProgramData&#xA0;folder, before&#xA0;immediately&#xA0;attempting&#xA0;to conceal its presence. It invokes a&#xA0;function&#xA0;that&#xA0;utilizes&#xA0;the <code>Win32ShowWindowAsync</code>&#xA0;function&#xA0;of&#xA0;&#x201C;user32.dll&#x201D;&#xA0;to hide the current PowerShell console window.&#xA0;&#xA0;</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/data-src-image-01acf711-5f5c-4cdc-b055-c16e31e1a449-1.png" class="kg-image" alt="PowMix botnet targets Czech workforce" loading="lazy" width="624" height="262" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/data-src-image-01acf711-5f5c-4cdc-b055-c16e31e1a449-1.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/data-src-image-01acf711-5f5c-4cdc-b055-c16e31e1a449-1.png 624w"><figcaption><span style="white-space: pre-wrap;">Figure 8.&#xA0;PowMix&#xA0;excerpt to hide the PowerShell console window.&#xA0;</span></figcaption></figure><p>Then it decrypts the&#xA0;C2&#xA0;domain and&#xA0;a&#xA0;configuration file using a custom XOR-based routine with a hardcoded key. It retrieves the machine&apos;s&#xA0;product ID&#xA0;by querying the&#xA0;<code>HKLM: SOFTWARE\Microsoft\Windows NT\CurrentVersion</code>&#xA0;registry key for the&#xA0;Windows&#xA0;ProductID.&#xA0;PowMix&#xA0;processes the&#xA0;victim machine&#x2019;s&#xA0;ProductID&#xA0;and the decrypted configuration data&#xA0;through a&#xA0;CRC32-style&#xA0;checksum&#xA0;function to generate a unique Bot&#xA0;ID and a corresponding Windows schedule task name,&#xA0;which it&#xA0;subsequently&#xA0;uses to&#xA0;establish&#xA0;persistence.&#xA0;</p><p>Some of the hardcoded XOR key&#xA0;strings&#xA0;found in this campaign&#xA0;are:&#xA0;</p><ul><li>HpSWSb&#xA0;&#xA0;</li><li>qDQyxQE&#xA0;&#xA0;</li><li>bKUxmhyAe&#xA0;</li><li>HymzqLse&#xA0;</li><li>KsEYwmgSF&#xA0;</li><li>ujCPOEPU&#xA0;</li></ul><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/data-src-image-9cbd9470-e08b-4329-862d-5a2dcaa8e808-1.png" class="kg-image" alt="PowMix botnet targets Czech workforce" loading="lazy" width="624" height="482" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/data-src-image-9cbd9470-e08b-4329-862d-5a2dcaa8e808-1.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/data-src-image-9cbd9470-e08b-4329-862d-5a2dcaa8e808-1.png 624w"><figcaption><span style="white-space: pre-wrap;">Figure 9.&#xA0;PowMix&#xA0;excerpts&#xA0;with the main function and the function that implements the CRC32&#xA0;type&#xA0;checksum&#xA0;algorithm.&#xA0;</span></figcaption></figure><p>Instead of using obvious task names,&#xA0;PowMix&#xA0;names the scheduled task by concatenating the Bot ID and Configuration&#xA0;file&#xA0;hash, resulting in names&#xA0;that&#xA0;appear as random hexadecimal strings&#xA0;(such&#xA0;as &quot;289c2e236761&#x201D;). The task configuration specifies a daily trigger set to execute at 11:00&#xA0;a.m.,&#xA0;and the&#xA0;execution action&#xA0;is configured to&#xA0;launch the benign Windows Explorer binary with the&#xA0;malicious&#xA0;Windows&#xA0;Shortcut file path&#xA0;as an argument. Windows Explorer&apos;s file association handling then automatically launches&#xA0;the malicious&#xA0;shortcut&#xA0;file to&#xA0;execute the&#xA0;PowerShell loader&#xA0;script.&#xA0;&#xA0;</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/data-src-image-1f394bb8-3442-40b9-92bc-4b67dd2fd0cb.png" class="kg-image" alt="PowMix botnet targets Czech workforce" loading="lazy" width="452" height="168"><figcaption><span style="white-space: pre-wrap;">Figure 10.&#xA0;Windows scheduled task created by&#xA0;PowMix. </span></figcaption></figure><p>Before&#xA0;attempting&#xA0;to establish persistence,&#xA0;PowMix&#xA0;performs several&#xA0;validation&#xA0;checks to ensure&#xA0;that&#xA0;another&#xA0;instance&#xA0;of the botnet is&#xA0;not&#xA0;running in the infected machine.&#xA0;It&#xA0;examines the process tree using&#xA0;Common Information Model&#xA0;(CIM) queries to&#xA0;identify&#xA0;its parent processes. If the&#xA0;PowMix&#xA0;is not running under either&#xA0;&#x201C;svchost.exe&#x201D;&#xA0;or&#xA0;&#x201C;powershell.exe&#x201D;,&#xA0;and&#xA0;if certain environmental variables are not set, it&#xA0;attempts&#xA0;to restart itself in the&#xA0;privileged&#xA0;context.&#xA0;</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/data-src-image-8ef912e2-e786-410a-b4be-d1440b67dbd9-1.png" class="kg-image" alt="PowMix botnet targets Czech workforce" loading="lazy" width="624" height="549" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/data-src-image-8ef912e2-e786-410a-b4be-d1440b67dbd9-1.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/data-src-image-8ef912e2-e786-410a-b4be-d1440b67dbd9-1.png 624w"><figcaption><span style="white-space: pre-wrap;">Figure 11.&#xA0;PowMix&#xA0;excerpts with the instructions to&#xA0;establish&#xA0;persistence.&#xA0;</span></figcaption></figure><p>The mutex implementation in the botnet prevents multiple instances from running at the same time. It creates a mutex with the&#xA0;name&#xA0;&#x201C;Global\[BotID]&#x201D;.&#xA0;&#xA0;The&#xA0;&#x201C;Global&#x201D;&#xA0;prefix makes the mutex visible across all&#xA0;user&#xA0;sessions, stopping separate instances from running in different user sessions.&#xA0;</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/data-src-image-2a0d14de-803f-4bf0-90e3-953d5f72174d-1.png" class="kg-image" alt="PowMix botnet targets Czech workforce" loading="lazy" width="624" height="138" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/data-src-image-2a0d14de-803f-4bf0-90e3-953d5f72174d-1.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/data-src-image-2a0d14de-803f-4bf0-90e3-953d5f72174d-1.png 624w"><figcaption><span style="white-space: pre-wrap;">Figure 12.&#xA0;PowMix&#xA0;excerpts with&#xA0;Mutex creation commands.&#xA0;</span></figcaption></figure><p>PowMix&#xA0;avoids persistent connections to the&#xA0;C2&#xA0;server.&#xA0;Instead,&#xA0;it&#xA0;implements&#xA0;a&#xA0;jitter via&#xA0;<code>Get-Random</code>&#xA0;PowerShell command&#xA0;to vary&#xA0;the beaconing intervals&#xA0;initially between 0 and&#xA0;261 seconds, and&#xA0;subsequently&#xA0;between 1,075 and&#xA0;1,450 seconds. This&#xA0;technique&#xA0;attempts&#xA0;to prevent&#xA0;detection&#xA0;of C2 traffic&#xA0;through&#xA0;predictable&#xA0;network signatures.&#xA0;</p><p>Each request&#xA0;from&#xA0;PowMix&#xA0;&#xA0;to C2&#xA0;is&#xA0;created&#xA0;by concatenating the base C2 domain with the&#xA0;Bot ID,&#xA0;configuration file&#xA0;hash, an encrypted heartbeat, a hexadecimal Unix timestamp, and a random hexadecimal suffix.&#xA0;The standard heartbeat&#xA0;string&#xA0;&#x201C;[]0&#x201D;&#xA0;is encrypted using&#xA0;a&#xA0;custom XOR routine&#xA0;using&#xA0;the Bot ID&#xA0;as the key and is&#xA0;then converted to a hex string. The inclusion of a random&#xA0;length&#xA0;hexadecimal&#xA0;suffix further ensures that every URL is unique.&#xA0;</p><p>The attacker&#xA0;mimics&#xA0;the REST API calls&#xA0;URLs by embedding these data directly into the URL path,&#xA0;instead of using a URL query string or a POST request for communicating with the C2 server.&#xA0;</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/data-src-image-999ba268-19b7-4971-b583-38277bf0b9fc.png" class="kg-image" alt="PowMix botnet targets Czech workforce" loading="lazy" width="624" height="42" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/data-src-image-999ba268-19b7-4971-b583-38277bf0b9fc.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/data-src-image-999ba268-19b7-4971-b583-38277bf0b9fc.png 624w"><figcaption><span style="white-space: pre-wrap;">Figure 13. C2 URL format.&#xA0;</span></figcaption></figure><p>PowMix&#xA0;establishes a Chrome User-Agent and configures the Accept-Language (en-US) and Accept-Encoding (gzip, deflate,&#xA0;br) headers. It&#xA0;utilizes&#xA0;the <code>GetSystemWebProxy</code>&#xA0;API along with&#xA0;<code>DefaultCredentials</code>&#xA0;to dynamically adopt the host machine&#x2019;s network proxy settings and automatically authenticates using the logged-in user&apos;s active session tokens, thereby disguising the C2 traffic as legitimate web browser traffic within the victim&#x2019;s environment.&#xA0;</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/data-src-image-7b53a04b-228b-437a-9d9f-499b3dde34b7-1.png" class="kg-image" alt="PowMix botnet targets Czech workforce" loading="lazy" width="624" height="271" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/data-src-image-7b53a04b-228b-437a-9d9f-499b3dde34b7-1.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/data-src-image-7b53a04b-228b-437a-9d9f-499b3dde34b7-1.png 624w"><figcaption><span style="white-space: pre-wrap;">Figure 14.&#xA0;PowMix&#xA0;excerpts with C2 loop instructions.&#xA0;</span></figcaption></figure><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/data-src-image-62f93cb8-65d4-4bd1-b453-4e37183f5d73-1.png" class="kg-image" alt="PowMix botnet targets Czech workforce" loading="lazy" width="624" height="292" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/data-src-image-62f93cb8-65d4-4bd1-b453-4e37183f5d73-1.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/data-src-image-62f93cb8-65d4-4bd1-b453-4e37183f5d73-1.png 624w"><figcaption><span style="white-space: pre-wrap;">Figure 15.&#xA0;PowMix&#xA0;excerpts&#xA0;of&#xA0;download function&#xA0;with hardcoded HTTP headers.&#xA0;</span></figcaption></figure><p>The&#xA0;PowMix&#xA0;command&#xA0;processing logic is executed upon receiving&#xA0;the response from the C2 with&#xA0;a&#xA0;period&#xA0;delimiter. It extracts the second segment and decrypts it using the unique&#xA0;Bot ID&#xA0;as the XOR key. The resulting&#xA0;decrypted response&#xA0;is then evaluated through a conditional parser that distinguishes between&#xA0;the command operations hardcoded in the botnet&#xA0;and arbitrary code execution, allowing the&#xA0;attacker&#xA0;to remotely control the victim machine.&#xA0;&#xA0;</p><p>The remote management commands that the botnet receives from the C2&#xA0;are&#xA0;identified&#xA0;by a leading hash symbol (#).&#xA0;We found that the&#xA0;PowMix&#xA0;botnet&#xA0;facilitates&#xA0;the commands described below:&#xA0;</p><ul><li><code>#KILL</code>&#xA0;-&#xA0;The&#xA0;KILL&#xA0;command&#xA0;initiates&#xA0;a self-deletion routine,&#xA0;utilizing&#xA0;the&#xA0;<code>Unregister-ScheduledTask</code>&#xA0;PowerShell command with the&#xA0;parameter&#xA0;<code>Confirm: $false</code>&#xA0;to silently remove persistence, followed by&#xA0;<code>Remove-Item -Recurse&#x2013;Force</code>&#xA0;command&#xA0;to&#xA0;wipe the malware&#x2019;s directory&#xA0;in the victim machine.&#xA0;&#xA0;</li><li><code>#HOST&#xA0;</code>- The&#xA0;HOST&#xA0;command enables&#xA0;the C2&#xA0;infrastructure migration by&#xA0;remotely updating&#xA0;a new C2 URL&#xA0;to&#xA0;a&#xA0;configuration file.&#xA0;By receiving the HOST command,&#xA0;PowMix&#xA0;will&#xA0;encrypt&#xA0;the new domain that it receives using the hardcoded XOR key and&#xA0;save&#xA0;it to a local&#xA0;configuration&#xA0;file via&#xA0;<code>Set-Content</code>&#xA0;PowerShell command.&#xA0;During the next initialization&#xA0;of the botnet&#xA0;through the task scheduler execution,&#xA0;it prioritizes the&#xA0;local configuration&#xA0;file data with the encrypted new C2 domain&#xA0;over hardcoded defaults,&#xA0;providing&#xA0;a robust mechanism for evading domain blacklisting.&#xA0;</li><li>For&#xA0;non&#xA0;#-prefixed&#xA0;responses from the C2,&#xA0;the command processing routine of&#xA0;PowMix&#xA0;transitions into an arbitrary execution mode. It bypasses static detection of the&#xA0;<code>Invoke-Expression</code>&#xA0;(IEX)&#xA0;PowerShell command&#xA0;by dynamically reconstructing the command string from the&#xA0;<code>$VerbosePreference</code> variable&#xA0;and executes&#xA0;the decrypted payload&#xA0;while redirecting the output to Out-Null, ensuring&#xA0;erasing the execution traces.&#xA0;&#xA0;</li></ul><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/image-3-1.png" class="kg-image" alt="PowMix botnet targets Czech workforce" loading="lazy" width="2000" height="1336" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/image-3-1.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/image-3-1.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/image-3-1.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/image-3-1.png 2372w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 16.&#xA0;PowMix&#xA0;excerpts with the instructions&#xA0;facilitating&#xA0;the C2 commands.&#xA0;</span></figcaption></figure><h2 id="coverage">Coverage</h2><p>The following ClamAV signature detects and blocks this threat:&#xA0;</p><ul><li>Lnk.Trojan.PowMix-10059735-0&#xA0;</li><li>Txt.Trojan.PowMix-10059742-0&#xA0;</li><li>Txt.Trojan.PowMix-10059778-0&#xA0;</li><li>Win.Trojan.PowMix-10059728-0&#xA0;</li></ul><p>The following Snort Rules (SIDs) detect and block this threat:&#xA0;</p><ul><li>Snort2&#xA0;and Snort3:&#xA0;66118&#xA0;</li></ul><h2 id="indicators-of-compromise-iocs">Indicators of compromise (IOCs)&#xA0;</h2><p>The IOCs for this threat are also available at our GitHub repository <a href="https://github.com/Cisco-Talos/IOCs/blob/main/2026/04/powmix-botnet-targets-czech-workforce.txt" rel="noreferrer">here</a>.&#xA0;</p>]]></content:encoded></item><item><title><![CDATA[More than pretty pictures: Wendy Bishop on visual storytelling in tech]]></title><description><![CDATA[Wendy shares the unique challenges and rewards of bridging the gap between artistic expression and highly technical research.]]></description><link>https://blog.talosintelligence.com/more-than-pretty-pictures-wendy-bishop-on-visual-storytelling-in-tech/</link><guid isPermaLink="false">69dd16cfab91ce0001a70dd2</guid><category><![CDATA[Humans of Talos]]></category><dc:creator><![CDATA[Amy Ciminnisi]]></dc:creator><pubDate>Thu, 16 Apr 2026 10:00:28 GMT</pubDate><media:content url="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/humans_of_talos.jpg" medium="image"/><content:encoded><![CDATA[<img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/humans_of_talos.jpg" alt="More than pretty pictures: Wendy Bishop on visual storytelling in tech"><p>In this episode of Humans of Talos, Amy sits down with Wendy Bishop, Head of Creative, to explore the vital role of design in the world of cybersecurity. From her early beginnings in web design and journalism to leading the creative vision for Talos, Wendy shares the unique challenges and rewards of bridging the gap between artistic expression and highly technical research.</p><p>Whether you&apos;re a creative professional looking to break into the cybersecurity industry or simply curious about the people behind our security intelligence, this conversation offers a fascinating look at the artistic side of Talos&apos; mission to keep the digital world safe.</p><figure class="kg-card kg-embed-card"><iframe width="200" height="113" src="https://www.youtube.com/embed/-OEPsPNcaFQ?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen title="More than pretty pictures: Wendy Bishop on visual storytelling in tech"></iframe></figure><p><strong>Amy Ciminnisi: Wendy, welcome! We haven&#x2019;t had anyone from creative here yet. Can you talk to me a little bit about what drew you into creative work and how your career evolved into what it is now at Talos?</strong></p><p><strong>Wendy Bishop:</strong> I never in my entire life thought I would do anything besides something creative. It&#x2019;s the only thing I&#x2019;ve ever known. I have so many memories in my childhood of just being locked in my moody teenage bedroom. In high school, I started doing web design courses, and I think that&#x2019;s when I really started being interested in a graphic design path. I learned Photoshop and basic HTML/CSS stuff as a side hobby. I moderated a message board for my favorite pop-punk band in high school. When it came time to go to college, there was nothing I wanted to do otherwise besides design. I found myself at Ohio University&#x2014; that&#x2019;s where I&#x2019;m from, Ohio &#x2014; in the School of Visual Communication. </p><p>I went off to a job working in newspapers. I actually never thought I would, but it was the job I found after college, and I designed news pages. It sounds funny now; it was already dying then, probably not the best long career path. But I think my background in journalism and communication-driven design is really what made me a great fit for the kind of design work we do here at Talos. We work with complicated materials, and a lot of the creative work we do is comms-driven. Our blog in some ways functions as a news outlet, so visual storytelling is a lot of my job. But of course, we have a lot of regular, branding-based design work now that comes out of my team.</p><p><strong>AC: We just had a really big report come out that has occupied our minds for months, especially over here in design. Can you talk a little bit about the </strong><a href="https://blog.talosintelligence.com/2025yearinreview/" rel="noreferrer"><strong>2025 Year in Review</strong></a><strong> and share what that process is like?</strong></p><p><strong>WB:</strong> When it starts to take shape, I look over that draft with the team and we talk about each graphic. I say, &quot;That one might be better if we did this,&quot; or &quot;This is missing that piece for when it goes into production.&quot; I really start to wrap my mind around the various assets and how we would go about taking what is essentially an Excel graphic or something created in PowerPoint and making it into a much more polished and designed presentation. </p><p>We get a sneak peek, and then one day it lands on your desk, Amy. From there, my designers and I put it together. It&#x2019;s a lot about putting that puzzle together, thinking about what makes sense on each page, making sure the content flow is clean and linear, and the adjacencies of the graphics are in the right place. I come to you and say, &quot;Amy, I need a headline,&quot; or &quot;Does this make sense?&quot; We come up with a look and feel and theme for the whole report every year that&#x2019;s greater than just the layout of the document. That gets extended to all the other companion pieces &#x2014; our videos, social graphics, and any continuing campaign pieces.</p><hr><p><em>Want to see more? Watch the&#xA0;</em><a href="https://youtu.be/-OEPsPNcaFQ" rel="noreferrer"><em>full interview</em></a><em>, and don&#x2019;t forget to subscribe to our YouTube channel for future episodes of Humans of Talos.</em></p>]]></content:encoded></item><item><title><![CDATA[The n8n n8mare: How threat actors are misusing AI workflow automation]]></title><description><![CDATA[Cisco Talos research has uncovered agentic AI workflow automation platform abuse in emails. Recently, we identified an increase in the number of emails that abuse n8n, one of these platforms, from as early as October 2025 through March 2026. ]]></description><link>https://blog.talosintelligence.com/the-n8n-n8mare/</link><guid isPermaLink="false">69de939e645a220001422976</guid><category><![CDATA[Threat Spotlight]]></category><dc:creator><![CDATA[Sean Gallagher]]></dc:creator><pubDate>Wed, 15 Apr 2026 10:00:52 GMT</pubDate><media:content url="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/threat_spotlight.jpg" medium="image"/><content:encoded><![CDATA[<ul><li>Cisco Talos&#xA0;research has uncovered&#xA0;agentic AI workflow automation platform&#xA0;abuse&#xA0;in emails.&#xA0;Recently, we&#xA0;identified an increase in the number of emails that abuse&#xA0;n8n, one of these platforms,&#xA0;from&#xA0;as early as&#xA0;October 2025&#xA0;through&#xA0;March 2026.&#xA0;</li><li>In this blog, Talos&#xA0;provides&#xA0;concrete examples of how threat actors are weaponizing legitimate automation platforms to facilitate sophisticated phishing campaigns, ranging from delivering malware to fingerprinting devices.&#xA0;&#xA0;</li><li>By leveraging trusted infrastructure, these attackers&#xA0;bypass&#xA0;traditional security filters, turning productivity tools into delivery vehicles for persistent remote access.</li></ul><hr><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/threat_spotlight.jpg" alt="The n8n n8mare: How threat actors are misusing AI workflow automation"><p>AI workflow automation platforms such as Zapier and n8n are primarily used to connect different software applications (e.g., Slack, Google Sheets, or Gmail) with AI models (e.g., OpenAI&#x2019;s GPT-4 or Anthropic&#x2019;s Claude). These platforms have been applied to different application domains, including cybersecurity over the past few months, especially with the progress that has been made in new avenues like large language models (LLMs) and agentic AI systems. However, much like other legitimate tools, AI workflow automation platforms can be weaponized to orchestrate malicious activities, like delivering malware by sending automated emails.</p><p>This blog describes how n8n, one of the most popular AI workflow automation platforms, has been abused to deliver malware and fingerprint devices by sending automated emails.</p><h2 id="what-is-n8n">What is n8n?</h2><p>N8n is a workflow automation platform that connects web applications and services (including Slack, GitHub, Google Sheets, and others with HTTP-based APIs) and builds automated workflows. A community-licensed version of the platform can be self-hosted by organizations. The commercial service, hosted at n8n.io, includes AI-driven features that can create agents capable of using web-based APIs to pull data from documents and other data sources.</p><p>Users can register for an n8n developer account at no initial charge. Doing so creates a subdomain on &#x201C;tti.app.n8n[.]cloud&#x201D; from which the user&#x2019;s applications can be accessed. This is similar to many web-based AI-aided development tools, and one that malicious actors have harnessed elsewhere in the past; earlier this year, Talos observed another AI-oriented web application service, Softr.io, being used for the creation of phishing pages used in a series of targeted attacks.</p><h2 id="how-n8n%E2%80%99s-webhooks-work">How n8n&#x2019;s&#xA0;webhooks&#xA0;work</h2><p>Talos&apos; investigation found that a primary point of abuse in n8n&#x2019;s AI workflow automation platform is its URL-exposed webhooks. A webhook, often referred to as a &#x201C;reverse API,&#x201D; allows one application to provide real-time information to another. These URLs register an application as a &#x201C;listener&#x201D; to receive data, which can include programmatically pulled HTML content. An example of an n8n webhook URL is shown in Figure 1.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/AI_flow_automation_URL.jpg" class="kg-image" alt="The n8n n8mare: How threat actors are misusing AI workflow automation" loading="lazy" width="1875" height="330" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/AI_flow_automation_URL.jpg 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/AI_flow_automation_URL.jpg 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/AI_flow_automation_URL.jpg 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/AI_flow_automation_URL.jpg 1875w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 1.&#xA0;Anatomy of an example&#xA0;n8n&#xA0;webhook&#xA0;URL.</span></figcaption></figure><p>When the URL receives a request, the subsequent workflow steps are triggered, returning results as an HTTP data stream to the requesting application. If the URL is accessed via email, the recipient&#x2019;s browser acts as the receiving application, processing the output as a webpage.</p><p>Talos has observed a significant rise in emails containing n8n webhook URLs over the past year. For example, the volume of these emails in March 2026 was approximately 686% higher than in January 2025. This increase is driven, in part, by several instances of platform abuse, including malware delivery and device fingerprinting, as we will discuss in the next sections.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/AI_flow_automation.jpg" class="kg-image" alt="The n8n n8mare: How threat actors are misusing AI workflow automation" loading="lazy" width="1875" height="1039" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/AI_flow_automation.jpg 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/AI_flow_automation.jpg 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/AI_flow_automation.jpg 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/AI_flow_automation.jpg 1875w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure 2. The prevalence of n8n webhook URLs in&#xA0;emails over the past few months.</span></figcaption></figure><h2 id="abusing-n8n-for-malware-delivery">Abusing n8n for malware delivery</h2><p>Because webhooks mask the source of the data they deliver, they can be used to serve payloads from untrusted sources while making them appear to originate from a trusted domain. Furthermore, since webhooks can dynamically serve different data streams based on triggering events &#x2014; such as request header information &#x2014; a phishing operator can tailor payloads based on the user-agent header.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure_3.png" class="kg-image" alt="The n8n n8mare: How threat actors are misusing AI workflow automation" loading="lazy" width="2000" height="1099" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure_3.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure_3.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure_3.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w2400/2026/04/Figure_3.png 2400w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure&#xA0;3. Example of a malicious email that delivers malware to the victim&#x2019;s device by abusing the n8n platform.</span></figcaption></figure><p>Talos observed a phishing campaign (shown in Figure 3) that used an n8n-hosted webhook link in emails that purported to be a shared Microsoft OneDrive folder. When clicked, the link opened a webpage in the targeted user&#x2019;s browser containing a CAPTCHA.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure_4.png" class="kg-image" alt="The n8n n8mare: How threat actors are misusing AI workflow automation" loading="lazy" width="2000" height="1499" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure_4.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure_4.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure_4.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure_4.png 2304w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure&#xA0;4.&#xA0;HTML document delivered by the webhook presenting a&#xA0;CAPTCHA.</span></figcaption></figure><p>Once the CAPTCHA is completed, a download button appears, triggering a progress bar as the payload is downloaded from an external host. Because the entire process is encapsulated within the JavaScript of the HTML document, the download appears to the browser to have come from the n8n domain.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure_5.png" class="kg-image" alt="The n8n n8mare: How threat actors are misusing AI workflow automation" loading="lazy" width="1952" height="1240" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure_5.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure_5.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure_5.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure_5.png 1952w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure&#xA0;5.&#xA0;HTML and JavaScript payload of the webhook downloads an executable file from a malicious URL.</span></figcaption></figure><p>In this case, the payload was an .exe file named &#x201C;DownloadedOneDriveDocument.exe&#x201D; that posed as a self-extracting archive. When opened, it installed a modified version of the Datto Remote Monitoring and Management (RMM) tool and executed a chain of PowerShell commands.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure_6.png" class="kg-image" alt="The n8n n8mare: How threat actors are misusing AI workflow automation" loading="lazy" width="543" height="345"><figcaption><span style="white-space: pre-wrap;">Figure&#xA0;6.&#xA0;Downloaded&#xA0;executable and&#xA0;the&#xA0;document it deploys&#xA0;(an installer for an RMM tool).</span></figcaption></figure><p>The PowerShell commands generated by the malicious executable extract and configure the Datto RMM tool, configure it as a scheduled task, and then launch it, establishing a connection to a relay on Datto&apos;s &quot;centrastage[.]net&quot; domain before deleting themselves and the rest of the payload.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/AI_flow_automation_attack-chain.jpg" class="kg-image" alt="The n8n n8mare: How threat actors are misusing AI workflow automation" loading="lazy" width="1875" height="891" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/AI_flow_automation_attack-chain.jpg 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/AI_flow_automation_attack-chain.jpg 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/AI_flow_automation_attack-chain.jpg 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/AI_flow_automation_attack-chain.jpg 1875w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure&#xA0;7.&#xA0;The&#xA0;webhook-delivered&#xA0;&#x201C;DownloadedOneDriveDocument.exe&#x201D;&#xA0;malware attack chain.</span></figcaption></figure><p>Talos observed a similar campaign that also utilized an n8n webhook to deliver a different payload. Like the previous instance, it featured a self-contained phishing page delivered as a data stream from the webhook, protected with a CAPTCHA for human verification.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure_8.png" class="kg-image" alt="The n8n n8mare: How threat actors are misusing AI workflow automation" loading="lazy" width="2000" height="1501" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure_8.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure_8.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure_8.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure_8.png 2309w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure&#xA0;8.&#xA0;Second CAPTCHA variant presented by n8n&#xA0;webhook.</span></figcaption></figure><p>This CAPTCHA code was significantly simpler than the first case. The payload delivered upon solving the CAPTCHA was a maliciously modified Microsoft Windows Installer (MSI) file named &#x201C;OneDrive_Document_Reader_pHFNwtka_installer.msi&#x201D;. Protected by the Armadillo anti-analysis packer, the payload deployed a different backdoor: the ITarian Endpoint Management RMM tool. When executed by &#x201C;msiexec.exe&#x201D;, the file installs a modified version of the ITarian Endpoint RMM, which acts as a backdoor while running Python modules to exfiltrate information from the target&#x2019;s system. During this process, a fake installer GUI displays a progress bar; once finished, the bar resets to 0% and the application exits, creating the illusion of a failed installation.</p><h2 id="abusing-n8n-for-fingerprinting">Abusing n8n for&#xA0;fingerprinting&#xA0;</h2><p>Talos observed another common abuse case:&#xA0;device fingerprinting. This is achieved by embedding&#xA0;an invisible image (or&#xA0;tracking pixel)&#xA0;within an email.&#xA0;For example, when&#xA0;the&#xA0;<code>&lt;img&gt;</code>&#xA0;HTML tag is used,&#xA0;it tells the email client (e.g.,&#xA0;Outlook or Gmail) to fetch an image from a specific URL.&#xA0;Figure 9 shows an example&#xA0;spam email in&#xA0;the&#xA0;Spanish language that&#xA0;leverages&#xA0;this technique.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure_9.png" class="kg-image" alt="The n8n n8mare: How threat actors are misusing AI workflow automation" loading="lazy" width="2000" height="332" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure_9.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure_9.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure_9.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w2400/2026/04/Figure_9.png 2400w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure&#xA0;9.&#xA0;Email example where n8n is abused to fingerprint the recipient&#x2019;s device.</span></figcaption></figure><p>When the email client attempts to load the image, it automatically sends an HTTP GET request to the specified address, which is an n8n webhook URL. These URLs include tracking parameters (such as the victim&#x2019;s email address), allowing the server to identify exactly which user opened the email. Also, it is clear how this image is made invisible by using the &#x201C;display&#x201D; and &#x201C;opacity&#x201D; CSS properties.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure_10.png" class="kg-image" alt="The n8n n8mare: How threat actors are misusing AI workflow automation" loading="lazy" width="2000" height="614" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure_10.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure_10.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure_10.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w2400/2026/04/Figure_10.png 2400w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure&#xA0;10. HTML source&#xA0;snippet&#xA0;of the email&#xA0;in Figure 9.</span></figcaption></figure><p>The second example below uses the same technique to track email opens and fingerprint the recipient&#x2019;s device. Here, the sender tries to get a hold of recipient by introducing a new gift card feature.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure_11.png" class="kg-image" alt="The n8n n8mare: How threat actors are misusing AI workflow automation" loading="lazy" width="2000" height="921" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure_11.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure_11.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure_11.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w2400/2026/04/Figure_11.png 2400w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure&#xA0;11. Email&#xA0;example where n8n is abused to fingerprint the recipient&#x2019;s device.</span></figcaption></figure><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/Figure_12.png" class="kg-image" alt="The n8n n8mare: How threat actors are misusing AI workflow automation" loading="lazy" width="2000" height="607" srcset="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w600/2026/04/Figure_12.png 600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1000/2026/04/Figure_12.png 1000w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w1600/2026/04/Figure_12.png 1600w, https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/size/w2400/2026/04/Figure_12.png 2400w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Figure&#xA0;12. HTML source snippet of&#xA0;email in Figure 11.</span></figcaption></figure><h2 id="conclusion">Conclusion</h2><p>The same workflows designed to save developers hours of manual labor are now being repurposed to automate the delivery of malware and fingerprinting devices due to their flexibility, ease of integration, and seamless automation. As we continue to leverage the power of low-code automation, it&#x2019;s the responsibility of security teams to ensure these platforms and tools remain assets rather than liabilities.</p><h2 id="protection">Protection</h2><p>Because several AI automation platforms exist today that are inherently designed to be flexible and trustworthy, the security community must move beyond simple static analysis to effectively counter their abuse. For instance, instead of blocking entire domains, which would disrupt legitimate business workflows, security researchers should investigate behavioral detection approaches. These should trigger alerts when high volumes of traffic are directed toward such platforms from unexpected internal sources. Similarly, if an endpoint attempts to communicate with an AI automation platform&#x2019;s domain (e.g., &#x201C;n8n.cloud&#x201D;) that is not part of the organization&#x2019;s authorized workflow, it should trigger an immediate alert.</p><p>Collaborative intelligence sharing is another effective approach to countering malicious email campaigns. Security teams should prioritize sharing indicators of compromise (IOCs) &#x2014; such as specific webhook URL structures, malicious file hashes, and command and control (C2) domains &#x2014; with platforms like Cisco Talos Intelligence.</p><p>Last but not least, safeguarding against these complex threats necessitates a comprehensive email security solution that utilizes AI-driven detection. Secure Email Threat Defense employs distinctive deep learning and machine learning models, incorporating Natural Language Processing, within its sophisticated threat detection systems. It detects harmful techniques employed in attacks against your organization, extracts unmatched context for particular business risks, offers searchable threat data, and classifies threats to identify which sectors of your organization are most at risk of attack. You can register now for a <a href="https://www.cisco.com/c/en/us/products/security/email-threat-defense-free-trial.html" rel="noreferrer">free trial</a> of Email Threat Defense.</p><h2 id="iocs">IOCs&#xA0;</h2><p>IOCs for this threat also available on our GitHub repository&#xA0;<a href="https://github.com/Cisco-Talos/IOCs/tree/main/2026/04" rel="noreferrer noopener"><u>here</u></a>.&#xA0;</p>
<!--kg-card-begin: html-->
<pre>93a09e54e607930dfc068fcbc7ea2c2ea776c504aa20a8ca12100a28cfdcc75a&#xA0;
7f30259d72eb7432b2454c07be83365ecfa835188185b35b30d11654aadf86a0&#xA0;
hxxps[://]onedrivedownload[.]zoholandingpage[.]com/my-workspace/DownloadedOneDrive&#xA0;
hxxps[://]majormetalcsorp[.]com/Openfolder&#xA0;
hxxps[://]pagepoinnc[.]app[.]n8n[.]cloud/webhook/downloading-1a92cb4f-cff3-449d-8bdd-ec439b4b3496&#xA0;
hxxps[://]monicasue[.]app[.]n8n[.]cloud/webhook/download-file-92684bb4-ee1d-4806-a264-50bfeb750dab&#xA0;</pre>
<!--kg-card-end: html-->
]]></content:encoded></item><item><title><![CDATA[Microsoft Patch Tuesday for April 2026 - Snort Rule and Prominent Vulnerabilities]]></title><description><![CDATA[Overview of patch tuesday release from Microsoft for April 2026.]]></description><link>https://blog.talosintelligence.com/microsoft-patch-tuesday-april-2026/</link><guid isPermaLink="false">69de9e36645a220001422999</guid><category><![CDATA[Patch Tuesday]]></category><dc:creator><![CDATA[Nick Biasini]]></dc:creator><pubDate>Tue, 14 Apr 2026 20:27:56 GMT</pubDate><media:content url="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/patch_tuesday.png" medium="image"/><content:encoded><![CDATA[<img src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/04/patch_tuesday.png" alt="Microsoft Patch Tuesday for April 2026 - Snort Rule and Prominent Vulnerabilities"><p>Microsoft has released its monthly security update for April 2026, which includes 165 vulnerabilities affecting a wide range of products, including eight Microsoft marked as &#x201C;critical.&#x201D;&#xA0;</p><p><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-23666">CVE-2026-23666</a> is a critical Denial of Service (DoS) vulnerability that affects the .NET framework. Successful exploitation could allow the attacker to deny service over the network.</p><p><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32157">CVE-2026-32157</a> is a critical use after free vulnerability in the Remote Desktop Client that results in code execution. Attack requires an authorized user on the client to connect to a malicious server, which could result in code execution on the client.&#xA0;</p><p><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32190">CVE-2026-32190</a> is a critical user after free vulnerability in Microsoft Office that can result in local code execution. Attacker is remote but attack is carried out locally.&#xA0; Code from the local machine needs to be executed to exploit the vulnerability.&#xA0;</p><p><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33114">CVE-2026-33114</a> is a critical untrusted pointer deference vulnerability in Microsoft Office Word that could allow the attacker to execute code locally. Code from the local machine needs to be executed to exploit this vulnerability.</p><p><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33115">CVE-2026-33115</a> is a critical use after free vulnerability in Microsoft Office word that can result in local code execution. Similar to CVE-2026-33114 and CVE-2026-32190 the attacker is remote, but code needs to be executed from the local machine to exploit the vulnerability.</p><p><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33824">CVE-2026-33824</a> is a critical double free vulnerability in the Widows Internet Key Exchange (IKE) extension, allowing remote code execution. An unauthenticated attacker can send specially crafted packets to a Windows machine with IKE version 2 enabled to potentially enable remote code execution. Additional mitigations can include blocking inbound traffic on UDP ports 500 and 4500 if IKE is not in use.</p><p><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33826">CVE-2026-33826</a> is a critical improper input validation in Windows Active Directory that can result in code execution over an adjacent network. Requires an authenticated attacker to send specially crafted RPC calls to an RPC host. Can result in remote code execution. Note that successful exploitation requires the attacker be in the same restricted Active Directory domain as the target system.</p><p><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33827">CVE-2026-33827</a> is a critical race condition vulnerability in Windows TCP/IP that can result in remote code execution. Successful exploitation requires the attacker to win a race condition along with additional actions prior to exploitation to prepare the target environment. An unauthenticated actor can send specially crafted IPv6 packets to a Windows node where IPSec is enabled to potentially achieve remote code execution.&#xA0;</p><p><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32201">CVE-2026-32201</a> is an important improper input validation vulnerability in Microsoft Office SharePoint that can allow an unauthorized user to perform spoofing. An attacker that successfully exploits this vulnerability could view some sensitive information and make changes to disclosed information. This vulnerability has already been detected as being exploited in the wild.</p><p>The majority of the remaining vulnerabilities are labeled as important with a two moderate and one low vulnerability also being patched.&#xA0; Talos would like to highlight the several additional&#xA0; important vulnerabilities that Microsoft has deemed as &#x201C;more likely&#x201D; to be exploited.</p><p>&#xB7;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-0390">CVE-2026-0390</a> - UEFI Secure Boot Security Feature Bypass Vulnerability</p><p>&#xB7;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26151">CVE-2026-26151</a> - Remote Desktop Spoofing Vulnerability</p><p>&#xB7;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26169">CVE-2026-26169</a> - Windows Kernel Memory Information Disclosure Vulnerability</p><p>&#xB7;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26173">CVE-2026-26173</a> - Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</p><p>&#xB7;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26177">CVE-2026-26177</a> - Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</p><p>&#xB7;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26182">CVE-2026-26182</a> - Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</p><p>&#xB7;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27906">CVE-2026-27906</a> - Windows Hello Security Feature Bypass Vulnerability</p><p>&#xB7;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27908">CVE-2026-27908</a> - Windows TDI Translation Driver (tdx.sys) Elevation of Privilege Vulnerability</p><p>&#xB7;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27909">CVE-2026-27909</a> - Windows Search Service Elevation of Privilege Vulnerability</p><p>&#xB7;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27913">CVE-2026-27913</a> - Windows BitLocker Security Feature Bypass Vulnerability</p><p>&#xB7;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27914">CVE-2026-27914</a> - Microsoft Management Console Elevation of Privilege Vulnerability</p><p>&#xB7;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27921">CVE-2026-27921</a> - Windows TDI Translation Driver (tdx.sys) Elevation of Privilege Vulnerability</p><p>&#xB7;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27922">CVE-2026-27922</a> - Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</p><p>&#xB7;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32070">CVE-2026-32070</a> - Windows Common Log File System Driver Elevation of Privilege Vulnerability</p><p>&#xB7;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32075">CVE-2026-32075</a> - Windows UPnP Device Host Elevation of Privilege Vulnerability</p><p>&#xB7;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32093">CVE-2026-32093</a> - Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability</p><p>&#xB7;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32152">CVE-2026-32152</a> - Desktop Window Manager Elevation of Privilege Vulnerability</p><p>&#xB7;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32154">CVE-2026-32154</a> - Desktop Window Manager Elevation of Privilege Vulnerability</p><p>&#xB7;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32155">CVE-2026-32155</a> - Desktop Window Manager Elevation of Privilege Vulnerability</p><p>&#xB7;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32162">CVE-2026-32162</a> - Windows COM Elevation of Privilege Vulnerability</p><p>&#xB7;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32202">CVE-2026-32202</a> - Windows Shell Spoofing Vulnerability</p><p>&#xB7;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32225">CVE-2026-32225</a> - Windows Shell Security Feature Bypass Vulnerability</p><p>&#xB7;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33825">CVE-2026-33825</a> - Microsoft Defender Elevation of Privilege Vulnerability</p><p>A complete list of all other vulnerabilities Microsoft disclosed this month is available on its <a href="https://msrc.microsoft.com/update-guide/">update page</a>. In response to these vulnerability disclosures, Talos is releasing a new Snort rule set that detects attempts to exploit some of them. Please note that&#xA0;additional&#xA0;rules may be released at a future&#xA0;date&#xA0;and current rules are subject to change pending&#xA0;additional information. Cisco Security Firewall customers should use the latest update to their ruleset by updating their SRU. Open-source Snort Subscriber Rule Set customers can stay up to date by downloading the latest rule pack available for purchase on&#xA0;<a href="http://snort.org/">Snort.org</a>.&#x202F;&#xA0;</p><p>The rules included in this release that protect against the exploitation of many of these vulnerabilities are:&#xA0;1:65902-1:65903, 1:66242-1:66251, 1:66259-1:66260, 1:66264-1:66267, 1:66275-1:66276&#xA0;</p><p>The following Snort 3 rules are also available: 1:301398, 1:301468-1:3101472, 1:301475, 1:301477-1:301478, 1:301480</p>]]></content:encoded></item></channel></rss>