APT41 Targeting Pharmaceutical Sector: Log4Shell to Domain Compromise
Threat Intelligence Report | Operation DragonRxPress enter or click to view image in full sizeClassi 2026-5-13 08:18:56 Author: infosecwriteups.com(查看原文) 阅读量:4 收藏

Threat Intelligence Report | Operation DragonRx

Andrey Pautov

Press enter or click to view image in full size

Classification: TLP:CLEAR — Unrestricted distribution (FIRST TLP 2.0)
Report ID: CTI-2026-APT41–001
Date: 2026–04–25
Analyst: Andrey Pautov (@1200km)
Status: Draft

Research notice: This report documents a representative APT41-style intrusion scenario constructed for adversary-emulation research and defender training. NovaTech Pharma, Operation DragonRx, the RxPhage implant, all IP addresses, credentials, and IOCs are fictional. The attack chain, techniques, and tooling are drawn from authoritative open-source APT41 reporting. This is a threat-intelligence product describing the attack as observed in the research scenario — not a confirmed APT41 intrusion. See the companion lab guide for hands-on reproduction: lab-architecture.md.

Operation DragonRx series:

CTI Report


文章来源: https://infosecwriteups.com/apt41-targeting-pharmaceutical-sector-log4shell-to-domain-compromise-9e4c1ba9dad6?source=rss----7b722bfd1b8d---4
如有侵权请联系:admin#unsafe.sh