Operation Cloud Hopper
Although long, a highly recommended read:
https://www.pwc.co.uk/issues/cyber-security-data-privacy/insights/operation-cloud-hopper.html
https://www.pwc.co.uk/cyber-security/pdf/cloud-hopper-report-final-updated.pdf
One thing I want to call out is Table 3, where PWC clearly demonstrated an interesting composite indicator of a TTP that appears to be specific to this operation. Specifically, the use of @india.com registrants and ITITCH nameservers. If you have the ability to pivot on this TTP, then you're likely to find a significant number of other similar domains.
Happy hunting, y'alls!
https://www.pwc.co.uk/issues/cyber-security-data-privacy/insights/operation-cloud-hopper.html
https://www.pwc.co.uk/cyber-security/pdf/cloud-hopper-report-final-updated.pdf
One thing I want to call out is Table 3, where PWC clearly demonstrated an interesting composite indicator of a TTP that appears to be specific to this operation. Specifically, the use of @india.com registrants and ITITCH nameservers. If you have the ability to pivot on this TTP, then you're likely to find a significant number of other similar domains.
Happy hunting, y'alls!
Comments
Post a Comment