AtlasCross is a new APT actor known for advanced phishing-based attacks with novel trojan deployment.
Analyst brief
AtlasCross is a new APT actor with advanced technical capabilities and a cautious operational approach. It primarily targets specific entities through tailored phishing attacks designed for in-domain penetration. Its key TTPs include a phishing document-based attack chain, the deployment of two novel trojan programs, and the use of rare attack tactics. Defenders should focus on enhancing detection rules for these phishing documents, which serve as the main initial access vector for lateral movement.
AtlasCross
unknown
NSFOCUS Security Labs recently discovered a new attack process based on phishing documents in their daily threat-hunting operations. Delving deeper into this finding through extensive research, they confirmed two new Trojan horse programs and many rare attack techniques and tactics. NSFOCUS Security Labs believes that this new attack process comes from a new APT attacker, who has a high technical level and cautious attack attitude. The phishing attack activity captured this time is part of the attacker’s targeted strike on specific targets and is its main means to achieve in-domain penetration. NSFOCUS Security Labs validated the high-level threat attributes of AtlasCross in terms of development technology and attack strategy through an in-depth analysis of its attack metrics. At this current stage, AtlasCross has a relatively limited scope of activity, primarily focusing on targeted attacks against specific hosts within a network domain. However, the attack processes they employ are highly robust and mature. NSFOCUS Security Labs deduce that this attacker is highly likely to deploy this attack process into larger-scale network attack operations.
What method does AtlasCross use to gain initial access to a target network?+
AtlasCross's primary initial access vector is an attack chain that begins with phishing documents. These documents are used to penetrate specific targets and achieve in-domain penetration.
What defensive measures should defenders prioritize against AtlasCross?+
Defenders should focus on enhancing detection rules for phishing documents, which serve as AtlasCross's main initial access vector for lateral movement.