216.73.217.22

SOC files: an APT41 attack on government IT services in Africa

· Published 20/08/2025 10:50 · Modified 20/08/2025 12:47

Export JSON

Essential information

Published
20/08/2025 10:50
Modified
20/08/2025 12:47
Tags
2025-07-21 2025-08-20 africa checkout cobalt strike credential harvesting data exfiltration dll sideloading government lateral movement mimikatz pillager sharepoint targeted attack web shell
Related entities
1 intrusion sets (apt), 4 malware, 3 others

Description

Kaspersky's MDR team detected a by APT41 against IT services in . The attackers used Impacket tools, , and custom agents for and data collection. They leveraged techniques and publicly available tools like and RawCopy. The group established persistence through scheduled tasks and services, and exfiltrated data via a compromised server. The attack showcased APT41's ability to adapt their tools to the target infrastructure and leverage internal services for command and control. The incident highlights the importance of comprehensive monitoring and proper privilege management in defending against sophisticated threats.

External references