Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
APT28 accesses poorly maintained Cisco routers and deploys malware on unpatched devices using CVE-2017-6742. APT28 exploited the vulnerability CVE-2017-6742 (Cisco Bug ID: CSCve54313). This vulnerability was first announced by Cisco on 29 June 2017, and patched software was made available.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
For some of the targeted devices, APT28 actors used an SNMP exploit to deploy malware, as detailed in the NCSC’s Jaguar Tooth malware analysis report.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware reportedly deployed by APT28 in espionage and reconnaissance operations.
Malware deployed by APT28 on compromised Cisco routers to establish a backdoor for follow-on attacks.
Custom, non-persistent Cisco IOS router malware that is injected into router memory, collects device information, exfiltrates it over TFTP, and enables unauthenticated backdoor access including access to existing local accounts without password verification via Telnet or physical session.
Malware deployed by APT28 on vulnerable Cisco routers through exploitation of CVE-2017-6742. It executes CLI commands to collect device and network information, including ARP-table information identifying other devices, exfiltrates information over TFTP, and enables unauthenticated access through a backdoor.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.