C0017

C0017C0017

ATT&CK
14.1
References
2

Description

[C0017](https://attack.mitre.org/campaigns/C0017) was an [APT41](https://attack.mitre.org/groups/G0096) campaign conducted between May 2021 and February 2022 that successfully compromised at least six U.S. state government networks through the exploitation of vulnerable Internet facing web applications. During [C0017](https://attack.mitre.org/campaigns/C0017), [APT41](https://attack.mitre.org/groups/G0096) was quick to adapt and use publicly-disclosed as well as zero-day vulnerabilities for initial access, and in at least two cases re-compromised victims following remediation efforts. The goals of [C0017](https://attack.mitre.org/campaigns/C0017) are unknown, however [APT41](https://attack.mitre.org/groups/G0096) was observed exfiltrating Personal Identifiable Information (PII).(Citation: Mandiant APT41)

References

  1. https://attack.mitre.org/campaigns/C0017
  2. https://www.mandiant.com/resources/apt41-us-state-governments

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Campaign
C0021
Campaign
C0018
Campaign
Operation CuckooBees
Campaign
C0015
Campaign
C0011
Campaign
C0027
Sourced from MITRE ATT&CK Enterprise 14.1. Curated by Adam Lundqvist, SQUR.