Operation Cloud Hopper

Although long, a highly recommended read:

https://www.pwc.co.uk/issues/cyber-security-data-privacy/insights/operation-cloud-hopper.html

https://www.pwc.co.uk/cyber-security/pdf/cloud-hopper-report-final-updated.pdf

One thing I want to call out is Table 3, where PWC clearly demonstrated an interesting composite indicator of a TTP that appears to be specific to this operation. Specifically, the use of @india.com registrants and ITITCH nameservers. If you have the ability to pivot on this TTP, then you're likely to find a significant number of other similar domains.

Happy hunting, y'alls!

Comments

Popular posts from this blog

Yara and Rich Headers are full of win

"It's Not All Black And White" or "Why You Should Switch From Blacklisting To Whitelisting"

"WannaCry Is North Korea!" or "Rich Headers Win Again!"