Operation This is Not a Test

Multiple countries in the first quarter of 2020 where targeted by the APT41 threat group with a focus on vulnerabilities in Citrix NetScaler/ADC, Cisco routers, and Zoho ManageEngine Desktop Central. The attacks spanned across more than 20 sectors including utilities, gas, oil, petrochemical, finance, education, government, and healthcare. The campaign used various techniques including PowerShell, BITS jobs, process injection, scripting, and encoding for persistence, defense evasion, and communication with command and control servers.
