
Andrew Thompson
@imposecost
Head of Research and Discovery (RAD) @Google Threat Intelligence Group. Posts are attributable to meโnot my employer. U.S. military and intelligence veteran.
ID: 871496297575927809
https://www.linkedin.com/in/imposecost 04-06-2017 22:38:03
875 Tweet
38,38K Followers
1,1K Following



Nothing too exciting by APT41 ๐จ๐ณ here IMO, using Impacket, CobaltStrike, Mimikatz, Pillager, RawCopy, Neo-reGeorg Using a compromised SharePoint server for C2 is interesting I guess, especially with this new ToolShell exploit for SharePoint servers securelist.com/apt41-in-africโฆ










Huge thanks to Invadergirl - the commissioned piece just landed and itโs next-level in person. Canโt stop staring at it!






Going to be cool when Invadergirl starts doing steganography in her work. Or maybe she already has ๐ถ๏ธ

