National Security Agency. (2022, December). APT5: Citrix ADC Threat Hunting Guidance. Retrieved February 5, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1053.003 Cron |
GroupAPT5 | APT5 has made modifications to the crontab file including in `/var/cron/tabs/`. |
| T1190 Exploit Public-Facing Application |
GroupAPT5 | APT5 has exploited vulnerabilities in externally facing software and devices including Pulse Secure VPNs and Citrix Application Delivery Controllers. |
| T1190 Exploit Public-Facing Application |
CampaignSPACEHOP Activity | SPACEHOP Activity has enabled the exploitation of CVE-2022-27518 and CVE-2022-27518 for illegitimate access. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.