
Andrew Thompson
@imposecost
Head of Research and Discovery (RAD) @Google Threat Intelligence Group. Posts are attributable to meβnot my employer. U.S. military and intelligence veteran.
ID: 871496297575927809
https://www.linkedin.com/in/imposecost 04-06-2017 22:38:03
875 Tweet
38,38K Followers
1,1K Following



Nothing too exciting by APT41 π¨π³ here IMO, using Impacket, CobaltStrike, Mimikatz, Pillager, RawCopy, Neo-reGeorg Using a compromised SharePoint server for C2 is interesting I guess, especially with this new ToolShell exploit for SharePoint servers securelist.com/apt41-in-africβ¦










Huge thanks to Invadergirl - the commissioned piece just landed and itβs next-level in person. Canβt stop staring at it!






Going to be cool when Invadergirl starts doing steganography in her work. Or maybe she already has πΆοΈ

