Part III. Hands-on Adversary Emulation
Part III offers a deep dive into the operations of three distinct APT groups—FIN6, APT3, and APT29. Each group represents a unique facet of cyber threats, ranging from financially motivated cybercrime to state-sponsored espionage. Our journey begins with examining FIN6, a group primarily known for its economically motivated cybercrimes. The emulation plan for FIN6 is a critical tool for organizations in the digital retail space, and it provides insights into reproducing and mitigating the TTPs of such adept cybercriminals.
Next, we delve into APT3, a China-based cyber espionage group. Known for its alignment with state objectives, APT3’s operations have been marked by its use of advanced TTPs, including zero-day exploits and custom malware. Chapter 15 introduces an emulation plan tailored for entities in sensitive sectors, equipping them to better predict and defend against the maneuvers of state-supported cyber operatives like APT3.
Concluding this part, we focus on APT29, a Russian state-sponsored group known for its sophisticated cyberespionage strategies, targeting vital sectors such as government, healthcare, and energy. APT29’s innovation in maneuvers, like HTML smuggling and using car listings as phishing bait, highlights its operational prowess. Chapter 16 outlines an emulation plan to mirror APT29’s methodologies. Taking this action is crucial for emulating and defending against high-level espionage activities.
These chapters provide ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access