Report

APT41's Attack Chain: Exe-LolBins Leads to Powershell Backdoor with Telegram C2

The Forrester Wave™: Managed Detection and Response, Q2 2023

APT41's Attack Chain: Exe-LolBins Leads to Powershell Backdoor with Telegram C2

APT41 is a Chinese cyber espionage group that has been active since at least 2012. They are known for their advanced tactics, techniques, and procedures (TTPs), which include the use of custom-built malware and tools. One of the tools that APT41 has been known to use is a PowerShell backdoor. PowerShell is a scripting language that is built into Microsoft Windows, and it can be used to automate administrative tasks and manage system configurations. APT41's PowerShell backdoor takes advantage of this functionality to bypass traditional security measures and gain access to target systems.



ThreatMon Free Trial

Download Download Here


Start Your Free Trial Now!

The 30-day free trial of ThreatMon allows users to explore the product's security benefits. During this trial period, you can test Threat Intelligence data, detect threats to your organization and recommend security measures.

Start Free Trial