Executive Summary
This intelligence summary details the tradecraft of APT29 (SVR) as observed in the MITRE ATT&CK Evaluations. The threat actor demonstrated high sophistication by maintaining a minimal process footprint, instead performing the majority of their operations within system memory (EventID 10) and the Windows Registry to evade traditional process-based detection mechanisms. The intrusion began with a malicious screensaver dropper (.scr) and evolved into a complex execution chain leveraging multiple signed Microsoft binaries to bypass security controls.
The attack featured advanced techniques including steganography to hide encrypted payloads within image files (monkey.png) and on-the-fly compilation using the C# compiler (csc.exe). Once established, the actor performed systematic credential harvesting by requesting full access (0x1FFFFF) to LSASS and other critical processes, followed by lateral movement using PsExec and custom Python implants. This campaign emphasizes the actor's reliance on 'living off the land' and trust manipulation, such as injecting unauthorized certificates into the Windows trust store to facilitate encrypted C2 communication.
