[
  {
    "id": "case-sandworm-notpetya",
    "slug": "sandworm-notpetya-olympic-destroyer",
    "title": "U.S. v. Andrienko et al. (Sandworm / GRU Unit 74455)",
    "summary": "Six Russian Main Intelligence Directorate (GRU) military officers charged with deploying the NotPetya wiper, Olympic Destroyer malware, KillDisk attacks against Ukrainian power grids, and cyberattacks targeting French elections.",
    "case_number": "2:20-cr-00316",
    "court": "U.S. District Court for the Western District of Pennsylvania",
    "district": "W.D. Pa.",
    "country": "United States",
    "opened_at": "2020-10-15",
    "status": "fugitive",
    "victim_sector": "Energy, Healthcare, Government, Transportation",
    "victim_country": "Ukraine, United States, France, South Korea",
    "loss_amount_usd": 10000000000,
    "loss_amount_note": "Estimated global worldwide economic damage exceeding $10 billion, including $1 billion across Heritage Valley Health System, FedEx TNT Express, and Merck.",
    "first_seen_at": "2015-12-23T15:00:00Z",
    "last_updated_at": "2026-09-20T12:00:00Z",
    "actor_slug": "sandworm-team",
    "defendant_slugs": [
      "yuriy-andrienko",
      "sergey-detistov",
      "pavel-frolov",
      "anatoliy-kovalev",
      "artem-ochichenko",
      "petr-pliskin"
    ],
    "cves": [
      "CVE-2017-0144"
    ],
    "techniques": [
      {
        "technique_id": "T1485",
        "evidence_excerpt": "The conspirators deployed the NotPetya malware, designed to irreversibly encrypt and destroy victim computer records worldwide while masquerading as ransomware.",
        "evidence_locator": "Indictment \u00b6 44, Page 22",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Andrienko et al.",
        "source_url": "https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware",
        "technique_name": "Data Destruction",
        "tactic": "Impact"
      },
      {
        "technique_id": "T1190",
        "evidence_excerpt": "Conspirators compromised the software update mechanism of M.E.Doc, an accounting software used extensively in Ukraine, to distribute the malicious NotPetya binary.",
        "evidence_locator": "Indictment \u00b6 38, Page 19",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Andrienko et al.",
        "source_url": "https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware",
        "technique_name": "Exploit Public-Facing Application",
        "tactic": "Initial Access"
      },
      {
        "technique_id": "T1021.002",
        "evidence_excerpt": "NotPetya leveraged EternalBlue (MS17-010) over SMB and PsExec to rapidly propagate across internal network subnets without user intervention.",
        "evidence_locator": "Indictment \u00b6 47, Page 24",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA17-181A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa17-181a",
        "technique_name": "SMB / Windows Admin Shares",
        "tactic": "Lateral Movement"
      },
      {
        "technique_id": "T1003",
        "evidence_excerpt": "The malware harvested passwords from computer memory using a bundled Mimikatz variant to impersonate network administrators.",
        "evidence_locator": "Indictment \u00b6 46, Page 23",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Andrienko et al.",
        "source_url": "https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware",
        "technique_name": "OS Credential Dumping",
        "tactic": "Credential Access"
      },
      {
        "technique_id": "T1566.001",
        "evidence_excerpt": "Spearphishing emails containing weaponized Microsoft Word documents executing malicious macros were sent to Ukrainian electrical substation operators.",
        "evidence_locator": "Indictment \u00b6 15, Page 7",
        "mapping_status": "proposed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Andrienko et al.",
        "source_url": "https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware",
        "technique_name": "Spearphishing Attachment",
        "tactic": "Initial Access"
      },
      {
        "technique_id": "T1055.012",
        "evidence_excerpt": "Olympic Destroyer hollowed out the legitimate svchost.exe process to inject malicious wiper threads while mimicking regular operating system background activity.",
        "evidence_locator": "Indictment \u00b6 52, Page 27",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Andrienko et al.",
        "source_url": "https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware",
        "technique_name": "Process Hollowing",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1036.005",
        "evidence_excerpt": "NotPetya named its primary payload dllhost.dat inside C:\\Windows\\ to blend in with legitimate host process binaries.",
        "evidence_locator": "Indictment \u00b6 45, Page 23",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Andrienko et al.",
        "source_url": "https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware",
        "technique_name": "Match Legitimate Name or Location",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1543.003",
        "evidence_excerpt": "The BlackEnergy malware created a persistent Windows service named 'Winexec' with automatic startup type.",
        "evidence_locator": "CISA Advisory ICS-ALERT-14-281-01B",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA ICS Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories",
        "technique_name": "Windows Service",
        "tactic": "Persistence"
      },
      {
        "technique_id": "T1499",
        "evidence_excerpt": "Olympic Destroyer terminated domain controller authentication services to cause immediate host crash loops.",
        "evidence_locator": "Indictment \u00b6 54, Page 28",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment",
        "source_url": "https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware",
        "technique_name": "Endpoint Denial of Service",
        "tactic": "Impact"
      },
      {
        "technique_id": "T1124",
        "evidence_excerpt": "NotPetya scheduled a forced system reboot via shutdown.exe /r /t 60 synchronized to local system clock timestamps.",
        "evidence_locator": "CISA Advisory AA17-181A",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA17-181A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa17-181a",
        "technique_name": "System Time Discovery",
        "tactic": "Discovery"
      }
    ],
    "events": [
      {
        "event_type": "indictment",
        "event_date": "2020-10-15",
        "description": "Grand jury returns indictment charging six GRU officers with seven counts of computer conspiracy, wire fraud, and intentional damage."
      },
      {
        "event_type": "sanction",
        "event_date": "2021-04-15",
        "description": "U.S. Department of the Treasury sanctions GRU Unit 74455 and associated military intelligence facilities."
      },
      {
        "event_type": "advisory",
        "event_date": "2022-02-23",
        "description": "CISA and international partners publish joint advisory on Sandworm wiper deployments (AA22-054A)."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Supply-chain compromise of Ukrainian tax accounting software M.E.Doc (Intellect Service). Threat actors infiltrated the vendor's update infrastructure and backdoored the routine update binary ezvit.exe to deploy a malicious loader across thousands of corporate networks.",
      "blast_radius": "Exceeded $10 billion in global economic damages. Paralyzed A.P. Moller-Maersk (shutting down 76 shipping terminals worldwide), FedEx TNT Express (permanently destroying tracking databases and causing $400M in losses), Merck Pharmaceuticals ($870M in losses), and Heritage Valley Health System (disrupting patient surgical suites and emergency rooms).",
      "kill_chain": [
        {
          "phase": "Initial Infiltration",
          "title": "Software Supply Chain Compromise",
          "description": "Russian GRU operatives breached the internal update server of Intellect Service in Ukraine, replacing the legitimate ezvit.exe update binary with a backdoored variant that executed silently on client systems during tax report synchronization.",
          "technical_artifacts": [
            "ezvit.exe",
            "M.E.Doc update package",
            "BKDR_HERLOK.A"
          ],
          "mitre_technique_id": "T1190"
        },
        {
          "phase": "Credential Dumping",
          "title": "In-Memory LSASS Credential Harvesting",
          "description": "Upon execution, a bundled custom Mimikatz module extracted plaintext passwords and Kerberos tickets directly from Local Security Authority Subsystem Service (LSASS) memory to acquire domain administrator access.",
          "technical_artifacts": [
            "Mimikatz memory dumper",
            "LSASS.exe memory read"
          ],
          "mitre_technique_id": "T1003"
        },
        {
          "phase": "Lateral Traversal",
          "title": "Automated SMB and PsExec Subnet Propagation",
          "description": "NotPetya leveraged EternalBlue (CVE-2017-0144) alongside legitimate PsExec and Windows Management Instrumentation (WMI) utilities to automatically infect every accessible Windows host across local and peered RFC 1918 subnets.",
          "technical_artifacts": [
            "EternalBlue (MS17-010)",
            "PsExec.exe",
            "WMI command execution"
          ],
          "mitre_technique_id": "T1021.002"
        },
        {
          "phase": "Defense Evasion",
          "title": "Legitimate Process Masquerading",
          "description": "The malware wrote its secondary payload into C:\\Windows\\dllhost.dat, imitating the legitimate Microsoft Component Object Model surrogate host process to avoid endpoint detection.",
          "technical_artifacts": [
            "C:\\Windows\\dllhost.dat",
            "Process masquerading"
          ],
          "mitre_technique_id": "T1036.005"
        },
        {
          "phase": "Destruction & Impact",
          "title": "Irreversible Disk Wiper Detonation",
          "description": "NotPetya scrambled the Master File Table (MFT) with Salsa20 and overwrote the Master Boot Record (MBR) with a custom bootloader that displayed a fake Bitcoin ransom screen. The decryption key was deliberately unrecoverable, permanently destroying victim data.",
          "technical_artifacts": [
            "Salsa20 encryption",
            "MBR overwrite",
            "shutdown.exe /r /t 60"
          ],
          "mitre_technique_id": "T1485"
        }
      ],
      "defensive_takeaways": [
        "Disable SMBv1 across all operating systems and restrict internal SMB (port 445) traversal between workstation subnets.",
        "Enforce cryptographically verified, out-of-band code signing for third-party software updates.",
        "Tier Active Directory administration to ensure domain credentials are never cached on endpoints.",
        "Maintain immutable, air-gapped Master Boot Record and Active Directory state backups."
      ]
    }
  },
  {
    "id": "case-lockbit-takedown",
    "slug": "lockbit-ransomware-takedown",
    "title": "U.S. v. Khoroshev et al. (LockBit Ransomware Operation)",
    "summary": "Comprehensive global law enforcement takedown (Operation Cronos) of LockBit ransomware infrastructure, unmasking creator Dmitry Khoroshev (LockBitSupp) and multiple active affiliates who extorted over $500 million from thousands of victims.",
    "case_number": "2:24-cr-00330",
    "court": "U.S. District Court for the District of New Jersey",
    "district": "D.N.J.",
    "country": "United States",
    "opened_at": "2024-05-07",
    "status": "charged",
    "victim_sector": "Healthcare, Education, Manufacturing, Government, Financial Services",
    "victim_country": "United States, United Kingdom, France, Germany, Japan",
    "loss_amount_usd": 500000000,
    "loss_amount_note": "Extorted more than $500 million in ransom payments and caused billions in remediation costs across 2,500 victims.",
    "first_seen_at": "2019-09-01T00:00:00Z",
    "last_updated_at": "2026-09-18T10:00:00Z",
    "actor_slug": "lockbit-group",
    "defendant_slugs": [
      "dmitry-khoroshev",
      "mikhail-vasiliev",
      "ruslan-astamirov",
      "artur-sungatov"
    ],
    "cves": [
      "CVE-2023-4966",
      "CVE-2023-38831"
    ],
    "techniques": [
      {
        "technique_id": "T1486",
        "evidence_excerpt": "LockBit conspirators systematically deployed ransomware binaries that encrypted victim servers and left ransom notes instructing victims to access a Tor negotiation portal.",
        "evidence_locator": "Indictment \u00b6 12, Page 6",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Khoroshev",
        "source_url": "https://www.justice.gov/opa/pr/us-charges-russian-national-developing-and-operating-lockbit-ransomware",
        "technique_name": "Data Encrypted for Impact",
        "tactic": "Impact"
      },
      {
        "technique_id": "T1567",
        "evidence_excerpt": "Prior to encryption, defendants used StealBit and rclone to exfiltrate gigabytes of confidential trade secrets and patient health records to cloud storage accounts.",
        "evidence_locator": "Indictment \u00b6 18, Page 9",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Khoroshev",
        "source_url": "https://www.justice.gov/opa/pr/us-charges-russian-national-developing-and-operating-lockbit-ransomware",
        "technique_name": "Exfiltration Over Web Service",
        "tactic": "Exfiltration"
      },
      {
        "technique_id": "T1490",
        "evidence_excerpt": "The malware invoked commands including 'vssadmin delete shadows /all /quiet' and 'wmic shadowcopy delete' to prevent administrative recovery.",
        "evidence_locator": "Indictment \u00b6 14, Page 7",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA23-165A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-165a",
        "technique_name": "Inhibit System Recovery",
        "tactic": "Impact"
      },
      {
        "technique_id": "T1190",
        "evidence_excerpt": "Affiliates gained access by exploiting Citrix Bleed vulnerability CVE-2023-4966 in NetScaler ADC appliances.",
        "evidence_locator": "CISA Advisory AA23-325A",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA23-325A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-325a",
        "technique_name": "Exploit Public-Facing Application",
        "tactic": "Initial Access"
      },
      {
        "technique_id": "T1078",
        "evidence_excerpt": "Conspirators purchased compromised administrative account logins on Genesis Market to authenticate through victim VPN portals.",
        "evidence_locator": "Complaint \u00b6 22",
        "mapping_status": "proposed",
        "mapped_by": "rule",
        "source_title": "U.S. v. Astamirov Complaint",
        "source_url": "https://www.justice.gov/opa/pr/russian-national-arrested-connection-lockbit-ransomware-attacks",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1047",
        "evidence_excerpt": "LockBit 3.0 invoked Windows Management Instrumentation command lines to query domain controllers and enumerate reachable subnets.",
        "evidence_locator": "CISA Advisory AA23-165A \u00b6 12",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA23-165A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-165a",
        "technique_name": "Windows Management Instrumentation",
        "tactic": "Execution"
      },
      {
        "technique_id": "T1562.001",
        "evidence_excerpt": "LockBit payloads terminated endpoint protection services and cleared security event subscriptions before encryption.",
        "evidence_locator": "Indictment \u00b6 21, Page 11",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Khoroshev",
        "source_url": "https://www.justice.gov/opa/pr/us-charges-russian-national-developing-and-operating-lockbit-ransomware",
        "technique_name": "Disable or Modify Tools",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1558.003",
        "evidence_excerpt": "LockBit affiliates executed Kerberoasting scripts against local Active Directory servers to request service tickets and extract Kerberos hashes for offline cracking.",
        "evidence_locator": "CISA Advisory AA23-165A Appendix",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Joint Technical Report",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-165a",
        "technique_name": "Kerberoasting",
        "tactic": "Credential Access"
      },
      {
        "technique_id": "T1573",
        "evidence_excerpt": "C2 communications between infected hosts and the LockBit backend utilized custom AES-256 encrypted channels over TCP port 443.",
        "evidence_locator": "Indictment \u00b6 15, Page 8",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Khoroshev",
        "source_url": "https://www.justice.gov/opa/pr/us-charges-russian-national-developing-and-operating-lockbit-ransomware",
        "technique_name": "Encrypted Channel",
        "tactic": "Command and Control"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2022-11-10",
        "description": "Mikhail Vasiliev arrested in Ontario, Canada, pursuant to U.S. extradition request."
      },
      {
        "event_type": "arrest",
        "event_date": "2023-06-14",
        "description": "Ruslan Astamirov arrested in Arizona on charges of executing LockBit ransomware attacks."
      },
      {
        "event_type": "indictment",
        "event_date": "2024-05-07",
        "description": "Unsealing of 26-count indictment against LockBit creator Dmitry Yuryevich Khoroshev (LockBitSupp)."
      },
      {
        "event_type": "sanction",
        "event_date": "2024-05-07",
        "description": "U.S. Treasury OFAC, UK FCDO, and Australian DFAT impose coordinated sanctions against Khoroshev."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Exploitation of perimeter gateway vulnerabilities (such as Citrix Bleed CVE-2023-4966) and acquisition of compromised corporate VPN logins from Initial Access Brokers (IABs).",
      "blast_radius": "Over 2,500 organizations breached worldwide across 120 countries, including Boeing, the UK Royal Mail, hospitals, and emergency dispatch centers. Extorted more than $500 million in ransom payments before an international coalition of 10 law enforcement agencies seized the infrastructure under Operation Cronos.",
      "kill_chain": [
        {
          "phase": "Initial Access",
          "title": "Perimeter Vulnerability Exploitation & Broker Credentials",
          "description": "Affiliates leveraged unpatched edge vulnerabilities like Citrix Bleed (CVE-2023-4966) to bypass multifactor authentication, or purchased valid network access tokens directly from dark web access brokers.",
          "technical_artifacts": [
            "CVE-2023-4966",
            "Initial Access Broker logins"
          ],
          "mitre_technique_id": "T1190"
        },
        {
          "phase": "Defense Evasion",
          "title": "BYOVD Endpoint Protection Neutralization",
          "description": "Operatives deployed vulnerable, legitimately signed third-party kernel drivers (Bring Your Own Vulnerable Driver attack) to disable antivirus software and endpoint detection and response (EDR) agents.",
          "technical_artifacts": [
            "Vulnerable signed kernel drivers",
            "EDR termination scripts"
          ],
          "mitre_technique_id": "T1562.001"
        },
        {
          "phase": "High-Speed Exfiltration",
          "title": "StealBit Automated Data Theft",
          "description": "Before encrypting hosts, affiliates launched custom StealBit exfiltration executables, parsing local drives for office documents and intellectual property and parallel-uploading gigabytes of data to offshore servers.",
          "technical_artifacts": [
            "StealBit.exe",
            "Multi-connection FTP/HTTP uploads"
          ],
          "mitre_technique_id": "T1041"
        },
        {
          "phase": "Encryption",
          "title": "Multi-Threaded LockBit 3.0 Black Detonation",
          "description": "LockBit 3.0 executed with command-line passkeys, using multiple CPU threads to encrypt files with AES and ECC algorithms, appending random extension strings and deleting volume shadow copies.",
          "technical_artifacts": [
            "LockBit 3.0 payload",
            "vssadmin delete shadows /all /quiet"
          ],
          "mitre_technique_id": "T1486"
        },
        {
          "phase": "Extortion & Infrastructure Seizure",
          "title": "Automated Tor Panel Extortion & Operation Cronos Takedown",
          "description": "Victims were directed to a private Tor negotiation portal with a countdown clock. In February 2024, the FBI, UK NCA, and Europol executed Operation Cronos, taking over the admin panel and releasing decryption tools.",
          "technical_artifacts": [
            "Tor negotiation portal",
            "Operation Cronos law enforcement splash screen"
          ],
          "mitre_technique_id": "T1490"
        }
      ],
      "defensive_takeaways": [
        "Enable Microsoft Vulnerable Driver Blocklist and Driver Signature Enforcement to thwart BYOVD attacks.",
        "Patch public-facing SSL-VPN and gateway appliances within 24 hours of KEV notification.",
        "Block shadow copy deletion commands (vssadmin, wmic shadowcopy) via endpoint behavioral rules.",
        "Maintain immutable, physically isolated offline backups of Active Directory and critical servers."
      ]
    }
  },
  {
    "id": "case-volt-typhoon",
    "slug": "volt-typhoon-critical-infrastructure",
    "title": "Volt Typhoon Critical Infrastructure Pre-Positioning",
    "summary": "State-sponsored cyber group sponsored by the People's Republic of China breached dozens of U.S. critical infrastructure operators in communications, energy, transportation, and water systems to establish disruptive persistent access.",
    "case_number": "CISA-AA24-038A",
    "court": "Federal Law Enforcement Action / FISA Court Authorized Operations",
    "district": "S.D. Tex. & Multiple",
    "country": "United States",
    "opened_at": "2023-05-24",
    "status": "alleged",
    "victim_sector": "Communications, Energy, Transportation, Water, Defense Industrial Base",
    "victim_country": "United States, Guam",
    "loss_amount_usd": 150000000,
    "loss_amount_note": "Multi-million dollar disruption and extensive remediation costs across federal agencies, defense bases, and utilities.",
    "first_seen_at": "2021-06-01T00:00:00Z",
    "last_updated_at": "2026-09-15T14:00:00Z",
    "actor_slug": "volt-typhoon",
    "defendant_slugs": [],
    "cves": [
      "CVE-2023-27997",
      "CVE-2023-46805"
    ],
    "techniques": [
      {
        "technique_id": "T1078",
        "evidence_excerpt": "Volt Typhoon actors exclusively use legitimate credentials and built-in system administration tools (living off the land) to evade security detections.",
        "evidence_locator": "CISA Advisory AA24-038A \u00b6 3",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA24-038A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1190",
        "evidence_excerpt": "Initial access was achieved by exploiting zero-day vulnerabilities in edge network routers and VPN firewalls including Fortinet and Ivanti appliances.",
        "evidence_locator": "CISA Advisory AA24-038A \u00b6 12",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA24-038A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a",
        "technique_name": "Exploit Public-Facing Application",
        "tactic": "Initial Access"
      },
      {
        "technique_id": "T1584",
        "evidence_excerpt": "Adversaries routed traffic through the KV-botnet of infected small office and home office (SOHO) Cisco and Netgear routers across the United States.",
        "evidence_locator": "DOJ Press Release 24-118",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "DOJ Takedown of KV Botnet",
        "source_url": "https://www.justice.gov/opa/pr/us-government-disrupts-botnet-peoples-republic-china-used-conceal-hacking-critical",
        "technique_name": "Compromise Infrastructure",
        "tactic": "Resource Development"
      },
      {
        "technique_id": "T1059.003",
        "evidence_excerpt": "Adversaries executed native cmd.exe utilities including ping, tracert, and netsh to explore domain topology without deploying custom malware.",
        "evidence_locator": "Advisory Technical Appendix",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Joint Guidance",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a",
        "technique_name": "Windows Command Shell",
        "tactic": "Execution"
      },
      {
        "technique_id": "T1016",
        "evidence_excerpt": "Volt Typhoon operators ran 'ipconfig /all' and 'netsh interface portproxy show all' to document network interface routing.",
        "evidence_locator": "CISA Advisory AA24-038A \u00b6 18",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA24-038A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a",
        "technique_name": "System Network Configuration Discovery",
        "tactic": "Discovery"
      },
      {
        "technique_id": "T1018",
        "evidence_excerpt": "Adversaries executed ping sweeps and 'net group \"Domain Computers\" /domain' to identify neighboring workstation hostnames.",
        "evidence_locator": "CISA Advisory AA24-038A \u00b6 22",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA24-038A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a",
        "technique_name": "Remote System Discovery",
        "tactic": "Discovery"
      },
      {
        "technique_id": "T1033",
        "evidence_excerpt": "The threat group ran 'whoami' and 'net user' commands immediately upon authenticating to establish active privilege scope.",
        "evidence_locator": "CISA Technical Appendix",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA24-038A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a",
        "technique_name": "System Owner/User Discovery",
        "tactic": "Discovery"
      },
      {
        "technique_id": "T1057",
        "evidence_excerpt": "Volt Typhoon executed 'tasklist /v' to discover running security monitoring agents and backup daemons on critical servers.",
        "evidence_locator": "CISA Advisory AA24-038A \u00b6 19",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA24-038A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a",
        "technique_name": "Process Discovery",
        "tactic": "Discovery"
      },
      {
        "technique_id": "T1570",
        "evidence_excerpt": "Adversaries copied living-off-the-land scripts across internal shares using administrative SMB channels.",
        "evidence_locator": "CISA Advisory AA24-038A \u00b6 25",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA24-038A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a",
        "technique_name": "Lateral Tool Transfer",
        "tactic": "Lateral Movement"
      }
    ],
    "events": [
      {
        "event_type": "advisory",
        "event_date": "2023-05-24",
        "description": "CISA, NSA, FBI, and Five Eyes agencies issue first joint advisory on Volt Typhoon intrusion campaigns."
      },
      {
        "event_type": "court_order",
        "event_date": "2023-12-14",
        "description": "Federal court in the Southern District of Texas authorizes FBI operation to delete KV botnet malware from compromised routers."
      },
      {
        "event_type": "disclosure",
        "event_date": "2024-01-31",
        "description": "FBI Director Wray testifies before Congress on PRC cyber actor pre-positioning against American civilian infrastructure."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Exploitation of zero-day vulnerabilities in edge networking appliances (Fortinet, Ivanti, Cisco, NETGEAR routers) combined with the KV-botnet of compromised small-office/home-office (SOHO) routers used as obfuscation proxies.",
      "blast_radius": "Pre-positioned inside critical infrastructure facilities across the United States and Guam, including drinking water treatment plants, telecommunications switching hubs, electric utility grids, and maritime port facilities. The objective was not financial extortion or immediate espionage, but dormant pre-positioning for disruptive sabotage during a potential geopolitical crisis.",
      "kill_chain": [
        {
          "phase": "Perimeter Compromise",
          "title": "Edge Appliance Infiltration & KV-Botnet Proxying",
          "description": "Operatives exploited unpatched edge network appliances and routers to establish a multi-tier proxy mesh (KV-botnet), routing malicious traffic through residential IP addresses to bypass geolocation blocks.",
          "technical_artifacts": [
            "KV-botnet",
            "Compromised SOHO routers",
            "Fortinet / Ivanti exploits"
          ],
          "mitre_technique_id": "T1190"
        },
        {
          "phase": "Credential Access",
          "title": "Silent Valid Account Harvesting",
          "description": "Volt Typhoon acquired valid administrative user accounts without deploying malware, extracting passwords through local memory and registry inspection.",
          "technical_artifacts": [
            "Legitimate domain credentials",
            "Single sign-on tokens"
          ],
          "mitre_technique_id": "T1078"
        },
        {
          "phase": "Living-off-the-Land",
          "title": "Built-in System Administration Tool Abuse",
          "description": "The actors exclusively utilized native operating system utilities (cmd.exe, powershell.exe, wmic, net.exe) to execute reconnaissance and admin tasks, leaving virtually zero custom malware signatures on disk.",
          "technical_artifacts": [
            "wmic.exe",
            "net.exe",
            "powershell.exe",
            "Living-off-the-Land (LotL)"
          ],
          "mitre_technique_id": "T1059.001"
        },
        {
          "phase": "Discovery & Active Directory Theft",
          "title": "NTDS.dit Shadow Copy Extraction",
          "description": "Operators created volume shadow copies on domain controllers to extract the Active Directory database (ntds.dit) and SYSTEM registry hives, enabling offline password cracking.",
          "technical_artifacts": [
            "vssadmin create shadow /for=C:",
            "ntds.dit copy",
            "SYSTEM hive export"
          ],
          "mitre_technique_id": "T1003"
        },
        {
          "phase": "Dormant Pre-Positioning",
          "title": "Strategic Operational Technology Preparation",
          "description": "Operatives established footholds within municipal water, aviation, and power distribution systems, lying dormant for years to maintain persistent leverage for disruptive cyber sabotage during geopolitical conflict.",
          "technical_artifacts": [
            "Persistent network tunnels",
            "Unmonitored router configurations"
          ],
          "mitre_technique_id": "T1082"
        }
      ],
      "defensive_takeaways": [
        "Decommission end-of-life edge devices and immediately disable remote WAN administration on all network appliances.",
        "Audit and detect Living-off-the-Land commands (wmic, net, vssadmin) executed by non-administrative accounts.",
        "Enforce strict behavioral alerting on volume shadow copy creation commands targeting domain controllers.",
        "Physically isolate and air-gap operational technology (OT) control networks from enterprise IT environments."
      ]
    }
  },
  {
    "id": "case-alphv-change-healthcare",
    "slug": "alphv-blackcat-change-healthcare",
    "title": "ALPHV / BlackCat Ransomware Attack on Change Healthcare",
    "summary": "Devastating ransomware attack and data extortion of Change Healthcare (UnitedHealth Group) that paralyzed medical billing, prescription processing, and healthcare provider reimbursement nationwide.",
    "case_number": "SEC CIK 0000731766",
    "court": "U.S. District Court for the District of Minnesota",
    "district": "D. Minn.",
    "country": "United States",
    "opened_at": "2024-02-21",
    "status": "alleged",
    "victim_sector": "Healthcare and Public Health",
    "victim_country": "United States",
    "loss_amount_usd": 2450000000,
    "loss_amount_note": "UnitedHealth Group reported over $2.45 billion in direct response costs, loan advances to providers, and forensic investigations, plus a paid $22 million Bitcoin ransom.",
    "first_seen_at": "2024-02-12T00:00:00Z",
    "last_updated_at": "2026-09-19T16:00:00Z",
    "actor_slug": "alphv-blackcat",
    "defendant_slugs": [],
    "cves": [
      "CVE-2024-1709"
    ],
    "techniques": [
      {
        "technique_id": "T1078",
        "evidence_excerpt": "The threat actor gained entry to a Change Healthcare Citrix portal using compromised credentials for an account that lacked multifactor authentication.",
        "evidence_locator": "Senate Finance Committee Testimony \u00b6 4",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Congressional Testimony by UnitedHealth CEO",
        "source_url": "https://www.finance.senate.gov/hearings/hacking-healthcare-examining-the-change-healthcare-cyberattack",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1486",
        "evidence_excerpt": "ALPHV BlackCat ransomware was executed across corporate data centers, encrypting critical clearinghouse databases and disabling pharmacy claim gateways.",
        "evidence_locator": "SEC Form 8-K Item 1.05",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "UnitedHealth Group Form 8-K Item 1.05",
        "source_url": "https://www.sec.gov/ix?doc=/Archives/edgar/data/731766/000073176624000045/unh-20240221.htm",
        "technique_name": "Data Encrypted for Impact",
        "tactic": "Impact"
      },
      {
        "technique_id": "T1567",
        "evidence_excerpt": "Attackers exfiltrated 6 terabytes of protected health information and sensitive patient records before demanding a 350 Bitcoin ransom.",
        "evidence_locator": "SEC Form 8-K Disclosure",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "UnitedHealth Group SEC Filing",
        "source_url": "https://www.sec.gov/ix?doc=/Archives/edgar/data/731766/000073176624000045/unh-20240221.htm",
        "technique_name": "Exfiltration Over Web Service",
        "tactic": "Exfiltration"
      },
      {
        "technique_id": "T1041",
        "evidence_excerpt": "Stolen medical claims and personally identifiable information were uploaded to adversary-controlled cloud servers prior to payload delivery.",
        "evidence_locator": "HHS OCR Notice",
        "mapping_status": "proposed",
        "mapped_by": "rule",
        "source_title": "HHS Office for Civil Rights Breach Notice",
        "source_url": "https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/index.html",
        "technique_name": "Exfiltration Over C2 Channel",
        "tactic": "Exfiltration"
      },
      {
        "technique_id": "T1133",
        "evidence_excerpt": "Initial entry occurred via an external remote Citrix access gateway lacking multifactor authentication controls.",
        "evidence_locator": "UnitedHealth Senate Testimony \u00b6 5",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Senate Testimony",
        "source_url": "https://www.finance.senate.gov/hearings/hacking-healthcare-examining-the-change-healthcare-cyberattack",
        "technique_name": "External Remote Services",
        "tactic": "Initial Access"
      },
      {
        "technique_id": "T1087",
        "evidence_excerpt": "ALPHV BlackCat actors queried active directory LDAP services to identify enterprise domain administrator accounts.",
        "evidence_locator": "CISA Advisory AA23-353A \u00b6 7",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA23-353A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-353a",
        "technique_name": "Account Discovery",
        "tactic": "Discovery"
      }
    ],
    "events": [
      {
        "event_type": "disclosure",
        "event_date": "2024-02-21",
        "description": "UnitedHealth Group files Form 8-K Item 1.05 reporting cybersecurity incident affecting Change Healthcare systems."
      },
      {
        "event_type": "advisory",
        "event_date": "2024-02-27",
        "description": "CISA and FBI update Joint Advisory AA23-353A with technical indicators from ALPHV BlackCat Change Healthcare intrusion."
      },
      {
        "event_type": "disclosure",
        "event_date": "2024-04-22",
        "description": "UnitedHealth Group issues public statement acknowledging payment of $22 million extortion ransom to protect patient data."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Stolen credentials used to enter an unsegmented Citrix remote access portal lacking multifactor authentication, combined with exploitation of ScreenConnect (CVE-2024-1709) for persistence.",
      "blast_radius": "Disrupted 1 in every 3 medical prescriptions in the United States. Pharmacies were unable to process electronic insurance claims, military medical clinics were forced into manual paper forms, and hospital systems suffered severe cash flow crunches totaling over $2 billion. Change Healthcare paid a 350 BTC ($22M) ransom.",
      "kill_chain": [
        {
          "phase": "Initial Access",
          "title": "Single-Factor Citrix Remote Access Breach",
          "description": "The ALPHV affiliate authenticated into Change Healthcare internal networks through an unpatched Citrix gateway using valid corporate credentials that lacked multifactor authentication.",
          "technical_artifacts": [
            "Citrix Gateway portal",
            "Single-factor employee login"
          ],
          "mitre_technique_id": "T1078"
        },
        {
          "phase": "Persistence & Tooling",
          "title": "ScreenConnect Remote Administration Deployment",
          "description": "Threat actors established persistent secondary footholds using legitimate ScreenConnect remote monitoring agents, ensuring continuous access even if primary credentials were changed.",
          "technical_artifacts": [
            "ScreenConnect client",
            "CVE-2024-1709"
          ],
          "mitre_technique_id": "T1133"
        },
        {
          "phase": "Reconnaissance & Privilege Escalation",
          "title": "Claims Database and Protected Health Information Enumeration",
          "description": "Affiliates spent nine days surveying network shares and cloud environments, targeting database servers storing patient records, Medicare claims, and billing logs.",
          "technical_artifacts": [
            "PowerView scripts",
            "Database enumeration"
          ],
          "mitre_technique_id": "T1083"
        },
        {
          "phase": "Exfiltration",
          "title": "Six-Terabyte Medical Record Exfiltration",
          "description": "Using high-speed multithreaded file transfer utilities, attackers exfiltrated approximately 6 terabytes of confidential health data and personal identifying information to offshore servers.",
          "technical_artifacts": [
            "Exfiltration tools",
            "6TB medical database dump"
          ],
          "mitre_technique_id": "T1567"
        },
        {
          "phase": "Execution & Double Extortion",
          "title": "ALPHV Rust Ransomware Detonation & Affiliate Mutiny",
          "description": "The affiliate launched the high-performance ALPHV Rust ransomware, encrypting virtual machines and data volumes. After Change Healthcare paid $22 million, the ALPHV core operator pocketed the funds and executed an exit scam, triggering affiliate threats to leak the data.",
          "technical_artifacts": [
            "ALPHV.exe (Rust)",
            "Tor negotiation portal"
          ],
          "mitre_technique_id": "T1486"
        }
      ],
      "defensive_takeaways": [
        "Enforce hardware-backed MFA across every remote access gateway and vendor integration point.",
        "Restrict remote monitoring and management (RMM) software like ScreenConnect to explicit, monitored jump hosts.",
        "Maintain immutable, write-once-read-many (WORM) storage for critical healthcare transaction databases.",
        "Deploy real-time DLP detection rules for abnormal bulk egress transfers."
      ]
    }
  },
  {
    "id": "case-colonial-pipeline",
    "slug": "colonial-pipeline-ransomware",
    "title": "Colonial Pipeline DarkSide Ransomware Attack",
    "summary": "DarkSide ransomware extortion against the largest refined petroleum pipeline system in the United States, forcing the shutdown of 5,500 miles of fuel pipelines and triggering widespread East Coast fuel shortages.",
    "case_number": "1:21-mj-00454",
    "court": "U.S. District Court for the Northern District of California",
    "district": "N.D. Cal.",
    "country": "United States",
    "opened_at": "2021-05-07",
    "status": "pleaded",
    "victim_sector": "Energy, Oil and Gas",
    "victim_country": "United States",
    "loss_amount_usd": 4400000,
    "loss_amount_note": "Colonial Pipeline paid 75 Bitcoin ($4.4 million) ransom; DOJ seized and recovered 63.7 Bitcoin ($2.3 million) from the affiliate's wallet.",
    "first_seen_at": "2021-05-06T00:00:00Z",
    "last_updated_at": "2026-09-17T11:00:00Z",
    "actor_slug": "darkside",
    "defendant_slugs": [],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1078",
        "evidence_excerpt": "The initial entry vector was a legacy Virtual Private Network account that was active without multifactor authentication using a password discovered in a dark web leak.",
        "evidence_locator": "Senate Homeland Security Committee Testimony",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Senate Testimony of Colonial Pipeline CEO",
        "source_url": "https://www.hsgac.senate.gov/hearings/threats-to-critical-infrastructure-examining-the-colonial-pipeline-cyber-attack",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1486",
        "evidence_excerpt": "DarkSide ransomware encrypted billing and corporate IT systems within hours, prompting pipeline operators to halt physical fuel transmission as a precaution.",
        "evidence_locator": "CISA Alert AA21-131A",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA21-131A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-131a",
        "technique_name": "Data Encrypted for Impact",
        "tactic": "Impact"
      },
      {
        "technique_id": "T1041",
        "evidence_excerpt": "Adversaries exfiltrated approximately 100 gigabytes of internal corporate documents to cloud servers before deploying encryption routines.",
        "evidence_locator": "FBI Alert Flash",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "FBI Cyber Division Alert",
        "source_url": "https://www.fbi.gov/investigate/cyber",
        "technique_name": "Exfiltration Over C2 Channel",
        "tactic": "Exfiltration"
      },
      {
        "technique_id": "T1021.001",
        "evidence_excerpt": "The DarkSide affiliate logged in via single-factor VPN and established an interactive Remote Desktop session to lateral servers.",
        "evidence_locator": "House Homeland Security Committee Testimony",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Congressional Hearing Transcript",
        "source_url": "https://homeland.house.gov/hearing/cyber-threats-in-the-pipeline-lessons-from-the-colonial-pipeline-attack/",
        "technique_name": "Remote Desktop Protocol",
        "tactic": "Lateral Movement"
      }
    ],
    "events": [
      {
        "event_type": "advisory",
        "event_date": "2021-05-11",
        "description": "CISA and FBI publish joint advisory AA21-131A on DarkSide ransomware tactics."
      },
      {
        "event_type": "court_order",
        "event_date": "2021-06-07",
        "description": "DOJ unseals seizure warrant recovering 63.7 Bitcoins ($2.3 million) paid by Colonial Pipeline."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "A single compromised employee password found on a dark web breach compilation for an inactive legacy Virtual Private Network (VPN) account that lacked multifactor authentication (MFA).",
      "blast_radius": "Colonial Pipeline proactively shut down all 5,500 miles of its fuel transport pipeline for 6 days, cutting off 45% of the fuel supply to the East Coast of the United States. The shutdown sparked panic buying, gas station fuel outages across 17 states, and flight diversions. Colonial paid 75 Bitcoins ($4.4M) in extortion.",
      "kill_chain": [
        {
          "phase": "Initial Access",
          "title": "Legacy VPN Ingress Without MFA",
          "description": "DarkSide affiliates used valid domain credentials harvested from a prior third-party breach to authenticate through an inactive, unmonitored enterprise VPN gateway lacking multifactor verification.",
          "technical_artifacts": [
            "Legacy VPN profile",
            "Stolen Active Directory credential"
          ],
          "mitre_technique_id": "T1078"
        },
        {
          "phase": "Discovery & Reconnaissance",
          "title": "Domain Trust and Network Mapping",
          "description": "Attackers executed lightweight discovery utilities including AdFind and BloodHound to map internal network segments, identify domain controllers, and locate corporate billing infrastructure.",
          "technical_artifacts": [
            "AdFind.exe",
            "BloodHound graph data"
          ],
          "mitre_technique_id": "T1087"
        },
        {
          "phase": "Exfiltration",
          "title": "Automated Cloud Storage Data Theft",
          "description": "Threat actors gathered approximately 100 gigabytes of sensitive commercial files and employee records within two hours, staging and exfiltrating the archive to Mega cloud storage services.",
          "technical_artifacts": [
            "Mega cloud upload",
            "Encrypted 7-Zip archives"
          ],
          "mitre_technique_id": "T1567"
        },
        {
          "phase": "Lateral Movement & GPO Staging",
          "title": "Group Policy Object Payload Distribution",
          "description": "After securing domain administrative rights, the attackers pushed DarkSide ransomware binaries across internal network endpoints and billing servers via Active Directory Group Policy Objects.",
          "technical_artifacts": [
            "Active Directory GPO push",
            "DarkSide.exe"
          ],
          "mitre_technique_id": "T1021.002"
        },
        {
          "phase": "Impact & Operational Shutdown",
          "title": "Precautionary Physical OT Infrastructure Halting",
          "description": "Because the enterprise billing systems were encrypted and operators could not verify fuel delivery tallies, Colonial Pipeline proactively halted physical pipeline operations to prevent infection spillover into industrial SCADA controls.",
          "technical_artifacts": [
            "DarkSide payload",
            "Billing database encryption"
          ],
          "mitre_technique_id": "T1486"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across 100% of remote access endpoints without exceptions.",
        "Decommission and purge all legacy, test, and orphaned VPN accounts during continuous identity hygiene audits.",
        "Implement strict microsegmentation and one-way data diodes between IT billing systems and Operational Technology (OT) SCADA pipelines.",
        "Deploy network egress filtering and automated alerts on massive cloud storage uploads."
      ]
    }
  },
  {
    "id": "case-solarwinds-apt29",
    "slug": "solarwinds-orion-supply-chain-compromise",
    "title": "SolarWinds Orion Supply Chain Intrusion (APT29 / SVR)",
    "summary": "Sophisticated software supply chain compromise by the Russian Foreign Intelligence Service (SVR), inserting the SUNBURST backdoor into updates of SolarWinds Orion software and compromising multiple federal agencies.",
    "case_number": "SEC CIK 0001739942",
    "court": "U.S. District Court for the Southern District of New York",
    "district": "S.D.N.Y.",
    "country": "United States",
    "opened_at": "2020-12-13",
    "status": "alleged",
    "victim_sector": "Information Technology, Defense, Federal Government, Telecommunications",
    "victim_country": "United States, United Kingdom, Canada, European Union",
    "loss_amount_usd": 200000000,
    "loss_amount_note": "Multi-hundred million dollar investigation and incident remediation costs across the Department of Homeland Security, Treasury, and Fortune 500 firms.",
    "first_seen_at": "2019-09-04T00:00:00Z",
    "last_updated_at": "2026-09-18T18:00:00Z",
    "actor_slug": "apt29",
    "defendant_slugs": [],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1190",
        "evidence_excerpt": "Adversaries inserted malicious source code (SUNBURST) into legitimate SolarWinds Orion build pipelines, resulting in digitally signed malicious updates.",
        "evidence_locator": "CISA Advisory AA20-352A \u00b6 8",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA20-352A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-352a",
        "technique_name": "Exploit Public-Facing Application",
        "tactic": "Initial Access"
      },
      {
        "technique_id": "T1071.001",
        "evidence_excerpt": "The backdoor communicated with adversary command and control servers via HTTP requests designed to mimic legitimate SolarWinds Orion communication protocols.",
        "evidence_locator": "CISA Advisory AA20-352A \u00b6 14",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Technical Analysis",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-352a",
        "technique_name": "Web Protocols",
        "tactic": "Command and Control"
      },
      {
        "technique_id": "T1078",
        "evidence_excerpt": "Adversaries abused stolen SAML signing keys to forge authentication tokens and bypass multifactor authentication in victim Microsoft 365 environments.",
        "evidence_locator": "CISA Emergency Directive 21-01",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Emergency Directive 21-01",
        "source_url": "https://www.cisa.gov/news-events/directives/ed-21-01-mitigate-solarwinds-orion-code-compromise",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1132",
        "evidence_excerpt": "SUNBURST encoded stolen domain information into custom Base64-like strings disguised as GUID query parameters.",
        "evidence_locator": "CISA Advisory AA20-352A \u00b6 16",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA20-352A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-352a",
        "technique_name": "Data Encoding",
        "tactic": "Command and Control"
      },
      {
        "technique_id": "T1036",
        "evidence_excerpt": "The TEARDROP memory-only dropper masqueraded as legitimate Windows system services to maintain persistent memory presence.",
        "evidence_locator": "CISA Advisory AA20-352A \u00b6 21",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA20-352A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-352a",
        "technique_name": "Masquerading",
        "tactic": "Defense Evasion"
      }
    ],
    "events": [
      {
        "event_type": "disclosure",
        "event_date": "2020-12-14",
        "description": "SolarWinds files Form 8-K Item 8.01 disclosing cyber incident involving Orion software compromise."
      },
      {
        "event_type": "advisory",
        "event_date": "2020-12-17",
        "description": "CISA issues Alert AA20-352A: Advanced Persistent Threat Compromise of Government Agencies."
      },
      {
        "event_type": "sanction",
        "event_date": "2021-04-15",
        "description": "White House and Treasury formally attribute operation to Russian SVR and sanction associated IT contractors."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Russian Foreign Intelligence Service (SVR / APT29) operatives infiltrated SolarWinds internal software development environment and modified the automated build pipeline to inject the SUNBURST backdoor into legitimate Orion DLL source files.",
      "blast_radius": "Approximately 18,000 public and private organizations installed the poisoned software update, including the US Treasury, Department of Homeland Security, Department of Energy, and Microsoft. Attackers hand-selected high-value federal targets for second-stage espionage, monitoring internal email and cloud systems undetected for nine months.",
      "kill_chain": [
        {
          "phase": "Build Pipeline Infiltration",
          "title": "Temporary Source Injection via MSBuild Worker",
          "description": "Operatives installed a customized implant (SUNSPOT) on SolarWinds build servers that monitored for MSBuild processes, dynamically substituting legitimate source files with the backdoored code seconds before compilation.",
          "technical_artifacts": [
            "SUNSPOT implant",
            "SolarWinds.Orion.Core.BusinessLayer.dll",
            "MSBuild injection"
          ],
          "mitre_technique_id": "T1190"
        },
        {
          "phase": "Code Signing & Distribution",
          "title": "Legitimately Signed Commercial Software Update",
          "description": "The backdoored binary was compiled and digitally signed with SolarWinds authentic Symantec code-signing certificate, then distributed to thousands of global customers as a standard security release.",
          "technical_artifacts": [
            "Symantec digital certificate",
            "Orion update package"
          ],
          "mitre_technique_id": "T1588.002"
        },
        {
          "phase": "Evasion & Dormancy",
          "title": "Two-Week Dormancy and Host Environment Inspection",
          "description": "Once installed on customer networks, the SUNBURST backdoor stayed completely inert for up to two weeks, verifying that no analysis tools or security agents were actively debugging the process before activating.",
          "technical_artifacts": [
            "SUNBURST sleep timer",
            "Security product blacklists"
          ],
          "mitre_technique_id": "T1027"
        },
        {
          "phase": "C2 Communication",
          "title": "Dynamic DNS Generation Mimicking AWS Telemetry",
          "description": "SUNBURST encoded victim host details and domain names into DNS A-record queries destined for avsvmcloud[.]com, disguising command-and-control beacons as routine Amazon Web Services cloud traffic.",
          "technical_artifacts": [
            "avsvmcloud[.]com",
            "DNS tunneling",
            "DGA queries"
          ],
          "mitre_technique_id": "T1071.004"
        },
        {
          "phase": "Golden SAML & Cloud Compromise",
          "title": "Active Directory Federation Token Forgery",
          "description": "For priority targets, operatives stole the Active Directory Federation Services (AD FS) token-signing private certificate, forging SAML tokens to access Microsoft 365 email and cloud environments without passwords.",
          "technical_artifacts": [
            "Golden SAML assertion",
            "AD FS token-signing key theft",
            "TEARDROP loader"
          ],
          "mitre_technique_id": "T1558.003"
        }
      ],
      "defensive_takeaways": [
        "Implement hermetic, reproducible build pipelines with dual-signature code verification.",
        "Protect Active Directory Federation Services (AD FS) signing keys in Hardware Security Modules (HSMs).",
        "Continuously inspect DNS queries for high-entropy DGA subdomains and anomalous TXT/A-record patterns.",
        "Mandate zero-trust conditional access policies that verify device health regardless of valid SAML claims."
      ]
    }
  },
  {
    "id": "case-fin7-carbanak",
    "slug": "us-v-hladyr-fin7-carbanak",
    "title": "U.S. v. Hladyr, Kolpakov & Iarmak (FIN7 Cybercrime Syndicate)",
    "summary": "Prosecution of senior leaders of the FIN7 transnational cybercrime syndicate who hacked into thousands of computer systems across the United States, stealing more than 20 million customer credit card records from restaurants and hospitality chains.",
    "case_number": "2:18-cr-00067",
    "court": "U.S. District Court for the Western District of Washington",
    "district": "W.D. Wash.",
    "country": "United States",
    "opened_at": "2018-03-27",
    "status": "sentenced",
    "victim_sector": "Hospitality, Food Services, Retail",
    "victim_country": "United States",
    "loss_amount_usd": 1000000000,
    "loss_amount_note": "Stole over 20 million credit and debit card records, causing financial losses estimated between $1 billion and $3 billion across Chipotle, Red Robin, Arby's, and Jason's Deli.",
    "first_seen_at": "2015-08-01T00:00:00Z",
    "last_updated_at": "2026-09-12T14:00:00Z",
    "actor_slug": "fin7",
    "defendant_slugs": [
      "fedir-hladyr",
      "andrii-kolpakov",
      "denys-iarmak"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1566.001",
        "evidence_excerpt": "FIN7 members sent spearphishing emails with malicious Microsoft Word attachments to restaurant managers disguised as catering orders or customer complaints.",
        "evidence_locator": "Indictment \u00b6 14, Page 8",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Hladyr",
        "source_url": "https://www.justice.gov/opa/pr/three-members-notorious-international-cybercrime-group-fin7-custody-role-attacks-over-100",
        "technique_name": "Spearphishing Attachment",
        "tactic": "Initial Access"
      },
      {
        "technique_id": "T1059.001",
        "evidence_excerpt": "Malicious macros embedded in the documents launched hidden PowerShell scripts to download the Carbanak malware suite.",
        "evidence_locator": "Indictment \u00b6 16, Page 9",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Hladyr",
        "source_url": "https://www.justice.gov/opa/pr/three-members-notorious-international-cybercrime-group-fin7-custody-role-attacks-over-100",
        "technique_name": "PowerShell",
        "tactic": "Execution"
      },
      {
        "technique_id": "T1041",
        "evidence_excerpt": "Defendants harvested payment card track data from Point-of-Sale (POS) memory and exfiltrated records back to private C2 servers.",
        "evidence_locator": "Plea Agreement \u00b6 8",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "U.S. v. Hladyr Plea Agreement",
        "source_url": "https://www.justice.gov/usao-wdwa/pr/high-ranking-fin7-member-sentenced-10-years-prison-role-massive-cyber-scheme",
        "technique_name": "Exfiltration Over C2 Channel",
        "tactic": "Exfiltration"
      },
      {
        "technique_id": "T1056.001",
        "evidence_excerpt": "Carbanak malware contained keystroke logging modules to capture administrative credentials entered in terminal sessions.",
        "evidence_locator": "Indictment \u00b6 22, Page 12",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Hladyr",
        "source_url": "https://www.justice.gov/opa/pr/three-members-notorious-international-cybercrime-group-fin7-custody-role-attacks-over-100",
        "technique_name": "Keylogging",
        "tactic": "Credential Access"
      },
      {
        "technique_id": "T1113",
        "evidence_excerpt": "Defendants configured video screen-recording modules to capture point-of-sale terminal transactions in real time.",
        "evidence_locator": "Indictment \u00b6 25, Page 14",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Hladyr",
        "source_url": "https://www.justice.gov/opa/pr/three-members-notorious-international-cybercrime-group-fin7-custody-role-attacks-over-100",
        "technique_name": "Screen Capture",
        "tactic": "Collection"
      },
      {
        "technique_id": "T1074.001",
        "evidence_excerpt": "Stolen credit card tracks were staged in hidden directories under AppData\\Local\\Temp prior to scheduled exfiltration batches.",
        "evidence_locator": "Trial Exhibit 8-C",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Trial Record",
        "source_url": "https://www.justice.gov/usao-wdwa/pr/high-ranking-fin7-member-sentenced-10-years-prison-role-massive-cyber-scheme",
        "technique_name": "Local Data Staging",
        "tactic": "Collection"
      },
      {
        "technique_id": "T1020",
        "evidence_excerpt": "Automated batch scripts compressed and transmitted stolen point-of-sale logs every night at midnight to C2 drops.",
        "evidence_locator": "Plea Agreement \u00b6 9, Page 6",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Plea Agreement",
        "source_url": "https://www.justice.gov/usao-wdwa/pr/high-ranking-fin7-member-sentenced-10-years-prison-role-massive-cyber-scheme",
        "technique_name": "Automated Exfiltration",
        "tactic": "Exfiltration"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2018-01-20",
        "description": "Fedir Hladyr arrested in Dresden, Germany, and extradited to the Western District of Washington."
      },
      {
        "event_type": "plea",
        "event_date": "2019-09-11",
        "description": "Hladyr pleads guilty to conspiracy to commit wire fraud and computer hacking."
      },
      {
        "event_type": "sentencing",
        "event_date": "2021-04-16",
        "description": "Hladyr sentenced to 120 months (10 years) in federal prison and ordered to pay $2.5 million in restitution."
      },
      {
        "event_type": "sentencing",
        "event_date": "2021-06-24",
        "description": "Kolpakov sentenced to 84 months (7 years) in federal prison and ordered to pay $2.5 million in restitution."
      },
      {
        "event_type": "sentencing",
        "event_date": "2022-04-07",
        "description": "Iarmak sentenced to 60 months (5 years) in federal prison after pleading guilty."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Adversary breached the target network via Spearphishing Attachment. FIN7 members sent spearphishing emails with malicious Microsoft Word attachments to restaurant managers disguised as catering orders or customer complaints.",
      "blast_radius": "Stole over 20 million credit and debit card records, causing financial losses estimated between $1 billion and $3 billion across Chipotle, Red Robin, Arby's, and Jason's Deli. Impacted Hospitality, Food Services, Retail infrastructure and associated victim operations.",
      "kill_chain": [
        {
          "phase": "Phase 1: Initial Access",
          "title": "Initial Perimeter Infiltration",
          "description": "FIN7 members sent spearphishing emails with malicious Microsoft Word attachments to restaurant managers disguised as catering orders or customer complaints.",
          "technical_artifacts": [
            "T1566.001",
            "Spearphishing Attachment"
          ],
          "mitre_technique_id": "T1566.001"
        },
        {
          "phase": "Phase 2: Execution",
          "title": "Host Execution & Payload Staging",
          "description": "Malicious macros embedded in the documents launched hidden PowerShell scripts to download the Carbanak malware suite.",
          "technical_artifacts": [
            "T1059.001",
            "PowerShell"
          ],
          "mitre_technique_id": "T1059.001"
        },
        {
          "phase": "Phase 3: Credential Access",
          "title": "Credential Harvesting & Memory Dumping",
          "description": "Carbanak malware contained keystroke logging modules to capture administrative credentials entered in terminal sessions.",
          "technical_artifacts": [
            "T1056.001",
            "Keylogging"
          ],
          "mitre_technique_id": "T1056.001"
        },
        {
          "phase": "Phase 4: Collection",
          "title": "Target Data Harvesting & Archiving",
          "description": "Defendants configured video screen-recording modules to capture point-of-sale terminal transactions in real time.",
          "technical_artifacts": [
            "T1113",
            "Screen Capture"
          ],
          "mitre_technique_id": "T1113"
        },
        {
          "phase": "Phase 5: Exfiltration",
          "title": "Encrypted Cloud Data Exfiltration",
          "description": "Defendants harvested payment card track data from Point-of-Sale (POS) memory and exfiltrated records back to private C2 servers.",
          "technical_artifacts": [
            "T1041",
            "Exfiltration Over C2 Channel"
          ],
          "mitre_technique_id": "T1041"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
        "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
        "Maintain isolated, immutable backups of critical directory services and transaction databases.",
        "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
      ]
    }
  },
  {
    "id": "case-evil-corp-yakubets",
    "slug": "us-v-yakubets-evil-corp-dridex",
    "title": "U.S. v. Yakubets & Turashev (Evil Corp / Dridex Banking Malware)",
    "summary": "Leader and core administrator of Evil Corp charged with deploying Bugat/Dridex banking malware and ransomware, stealing dozens of millions of dollars from bank accounts of municipalities, school districts, and businesses.",
    "case_number": "2:19-cr-00336",
    "court": "U.S. District Court for the Western District of Pennsylvania",
    "district": "W.D. Pa.",
    "country": "United States",
    "opened_at": "2019-11-14",
    "status": "fugitive",
    "victim_sector": "Banking, Financial Services, Municipalities, Education",
    "victim_country": "United States, United Kingdom",
    "loss_amount_usd": 100000000,
    "loss_amount_note": "Caused at least $100 million in verified financial losses; State Department offered a $5 million reward under Transnational Organized Crime Rewards Program.",
    "first_seen_at": "2011-05-01T00:00:00Z",
    "last_updated_at": "2026-09-10T12:00:00Z",
    "actor_slug": "evil-corp",
    "defendant_slugs": [
      "maksim-yakubets",
      "igor-turashev"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1566.001",
        "evidence_excerpt": "Defendants distributed millions of phishing emails containing malicious macros disguised as invoices to infect corporate computers with Dridex.",
        "evidence_locator": "Indictment \u00b6 19, Page 11",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Yakubets",
        "source_url": "https://www.justice.gov/opa/pr/russian-national-indicted-charges-related-massive-cyber-attacks-stealing-tens-millions-dollars",
        "technique_name": "Spearphishing Attachment",
        "tactic": "Initial Access"
      },
      {
        "technique_id": "T1555",
        "evidence_excerpt": "Dridex injected web forms into web browsers to capture online banking credentials, passcodes, and transaction authorization numbers.",
        "evidence_locator": "Indictment \u00b6 24, Page 14",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Yakubets",
        "source_url": "https://www.justice.gov/opa/pr/russian-national-indicted-charges-related-massive-cyber-attacks-stealing-tens-millions-dollars",
        "technique_name": "Credentials from Password Stores",
        "tactic": "Credential Access"
      },
      {
        "technique_id": "T1486",
        "evidence_excerpt": "In later operations, conspirators deployed BitPaymer and WastedLocker ransomware against compromised networks to extort ransoms exceeding $5 million per victim.",
        "evidence_locator": "Treasury Designation Announcement",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "OFAC Sanctions Action",
        "source_url": "https://home.treasury.gov/news/press-releases/sm845",
        "technique_name": "Data Encrypted for Impact",
        "tactic": "Impact"
      },
      {
        "technique_id": "T1055",
        "evidence_excerpt": "Dridex injected dynamic link library code into running Internet Explorer and Chrome browser processes to intercept HTTPS traffic.",
        "evidence_locator": "Indictment \u00b6 23, Page 13",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Yakubets",
        "source_url": "https://www.justice.gov/opa/pr/russian-national-indicted-charges-related-massive-cyber-attacks-stealing-tens-millions-dollars",
        "technique_name": "Process Injection",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1547.001",
        "evidence_excerpt": "The malware wrote autorun entries into HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run to maintain persistence across reboots.",
        "evidence_locator": "Indictment \u00b6 26, Page 15",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Yakubets",
        "source_url": "https://www.justice.gov/opa/pr/russian-national-indicted-charges-related-massive-cyber-attacks-stealing-tens-millions-dollars",
        "technique_name": "Registry Run Keys / Startup Folder",
        "tactic": "Persistence"
      },
      {
        "technique_id": "T1053.005",
        "evidence_excerpt": "Conspirators created scheduled tasks via schtasks.exe to trigger periodic secondary bot payload downloads.",
        "evidence_locator": "CISA Advisory AA19-339A",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA19-339A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa19-339a",
        "technique_name": "Scheduled Task",
        "tactic": "Persistence"
      },
      {
        "technique_id": "T1102",
        "evidence_excerpt": "Dridex used public social media profile pages and paste sites as dead drop resolvers to retrieve active C2 IP addresses.",
        "evidence_locator": "CISA Technical Analysis Report",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Technical Report",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa19-339a",
        "technique_name": "Web Service: Dead Drop Resolver",
        "tactic": "Command and Control"
      }
    ],
    "events": [
      {
        "event_type": "indictment",
        "event_date": "2019-11-14",
        "description": "Federal grand jury indicts Maksim Viktorovich Yakubets and Igor Turashev for computer fraud, wire fraud, and bank fraud."
      },
      {
        "event_type": "sanction",
        "event_date": "2019-12-05",
        "description": "OFAC sanctions Evil Corp, Yakubets, Turashev, and 15 associated confederates."
      },
      {
        "event_type": "sanction",
        "event_date": "2024-10-01",
        "description": "Treasury and UK authorities unseal additional sanctions targeting Evil Corp family members and LockBit collaboration."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Adversary breached the target network via Spearphishing Attachment. Defendants distributed millions of phishing emails containing malicious macros disguised as invoices to infect corporate computers with Dridex.",
      "blast_radius": "Caused at least $100 million in verified financial losses; State Department offered a $5 million reward under Transnational Organized Crime Rewards Program. Impacted Banking, Financial Services, Municipalities, Education infrastructure and associated victim operations.",
      "kill_chain": [
        {
          "phase": "Phase 1: Initial Access",
          "title": "Initial Perimeter Infiltration",
          "description": "Defendants distributed millions of phishing emails containing malicious macros disguised as invoices to infect corporate computers with Dridex.",
          "technical_artifacts": [
            "T1566.001",
            "Spearphishing Attachment"
          ],
          "mitre_technique_id": "T1566.001"
        },
        {
          "phase": "Phase 2: Persistence",
          "title": "Persistent Foothold Establishment",
          "description": "The malware wrote autorun entries into HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run to maintain persistence across reboots.",
          "technical_artifacts": [
            "T1547.001",
            "Registry Run Keys / Startup Folder"
          ],
          "mitre_technique_id": "T1547.001"
        },
        {
          "phase": "Phase 3: Defense Evasion",
          "title": "Defense Evasion & Security Blindfolding",
          "description": "Dridex injected dynamic link library code into running Internet Explorer and Chrome browser processes to intercept HTTPS traffic.",
          "technical_artifacts": [
            "T1055",
            "Process Injection"
          ],
          "mitre_technique_id": "T1055"
        },
        {
          "phase": "Phase 4: Credential Access",
          "title": "Credential Harvesting & Memory Dumping",
          "description": "Dridex injected web forms into web browsers to capture online banking credentials, passcodes, and transaction authorization numbers.",
          "technical_artifacts": [
            "T1555",
            "Credentials from Password Stores"
          ],
          "mitre_technique_id": "T1555"
        },
        {
          "phase": "Phase 5: Impact",
          "title": "Operational Disruption or Extortion Detonation",
          "description": "In later operations, conspirators deployed BitPaymer and WastedLocker ransomware against compromised networks to extort ransoms exceeding $5 million per victim.",
          "technical_artifacts": [
            "T1486",
            "Data Encrypted for Impact"
          ],
          "mitre_technique_id": "T1486"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
        "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
        "Maintain isolated, immutable backups of critical directory services and transaction databases.",
        "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
      ]
    }
  },
  {
    "id": "case-lazarus-park-jin-hyok",
    "slug": "us-v-park-jin-hyok-lazarus",
    "title": "U.S. v. Park Jin Hyok (Lazarus Group / Chosun Expo)",
    "summary": "Department of Justice charges North Korean state-sponsored programmer with the 2014 Sony Pictures hack, the 2017 global WannaCry ransomware outbreak, and the $81 million Bangladesh Bank cyber heist.",
    "case_number": "2:18-mj-01479",
    "court": "U.S. District Court for the Central District of California",
    "district": "C.D. Cal.",
    "country": "United States",
    "opened_at": "2018-06-08",
    "status": "fugitive",
    "victim_sector": "Media and Entertainment, Financial Services, Healthcare",
    "victim_country": "United States, United Kingdom, Bangladesh, Philippines",
    "loss_amount_usd": 1300000000,
    "loss_amount_note": "Attempted to steal over $1.3 billion in cash and cryptocurrency, including the $81 million Bangladesh Bank heist and extensive WannaCry disruptions across NHS hospitals.",
    "first_seen_at": "2014-11-01T00:00:00Z",
    "last_updated_at": "2026-09-14T09:00:00Z",
    "actor_slug": "lazarus-group",
    "defendant_slugs": [
      "park-jin-hyok"
    ],
    "cves": [
      "CVE-2017-0144"
    ],
    "techniques": [
      {
        "technique_id": "T1485",
        "evidence_excerpt": "The Sony Pictures attack used the Destover wiper to destroy master boot records and overwrite hard drives, rendering thousands of workstations permanently inoperable.",
        "evidence_locator": "Criminal Complaint \u00b6 42, Page 27",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "DOJ Criminal Complaint",
        "source_url": "https://www.justice.gov/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyberattacks-and",
        "technique_name": "Data Destruction",
        "tactic": "Impact"
      },
      {
        "technique_id": "T1486",
        "evidence_excerpt": "Park and his co-conspirators developed and distributed the WannaCry ransomware worm that infected over 230,000 computers across 150 nations within days.",
        "evidence_locator": "Criminal Complaint \u00b6 88, Page 61",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "DOJ Criminal Complaint",
        "source_url": "https://www.justice.gov/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyberattacks-and",
        "technique_name": "Data Encrypted for Impact",
        "tactic": "Impact"
      },
      {
        "technique_id": "T1021.002",
        "evidence_excerpt": "WannaCry automated its spread using the EternalBlue SMB exploit code to compromise unpatched Windows servers.",
        "evidence_locator": "Criminal Complaint \u00b6 92, Page 64",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "DOJ Criminal Complaint",
        "source_url": "https://www.justice.gov/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyberattacks-and",
        "technique_name": "SMB / Windows Admin Shares",
        "tactic": "Lateral Movement"
      },
      {
        "technique_id": "T1566.002",
        "evidence_excerpt": "Spearphishing emails were sent to bank officials at Bangladesh Bank directing them to fake SWIFT messaging updates.",
        "evidence_locator": "Complaint \u00b6 55",
        "mapping_status": "proposed",
        "mapped_by": "rule",
        "source_title": "DOJ Criminal Complaint",
        "source_url": "https://www.justice.gov/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyberattacks-and",
        "technique_name": "Spearphishing Link",
        "tactic": "Initial Access"
      },
      {
        "technique_id": "T1027",
        "evidence_excerpt": "Park and his co-conspirators heavily obfuscated WannaCry and Destover binaries with custom XOR encoders and commercial packers.",
        "evidence_locator": "Criminal Complaint \u00b6 63, Page 42",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "DOJ Criminal Complaint",
        "source_url": "https://www.justice.gov/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyberattacks-and",
        "technique_name": "Obfuscated Files or Information",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1001.002",
        "evidence_excerpt": "Lazarus malware disguised executable payloads inside benign PNG image files using steganographic pixel modification algorithms.",
        "evidence_locator": "Criminal Complaint \u00b6 74, Page 51",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "DOJ Criminal Complaint",
        "source_url": "https://www.justice.gov/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyberattacks-and",
        "technique_name": "Steganography",
        "tactic": "Command and Control"
      },
      {
        "technique_id": "T1068",
        "evidence_excerpt": "WannaCry automated exploitation of kernel pool memory corruption via EternalBlue to execute ring 0 shellcode.",
        "evidence_locator": "Criminal Complaint \u00b6 94, Page 66",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "DOJ Criminal Complaint",
        "source_url": "https://www.justice.gov/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyberattacks-and",
        "technique_name": "Exploitation for Privilege Escalation",
        "tactic": "Privilege Escalation"
      }
    ],
    "events": [
      {
        "event_type": "indictment",
        "event_date": "2018-06-08",
        "description": "Criminal complaint filed charging Park Jin Hyok with computer fraud and wire fraud conspiracies."
      },
      {
        "event_type": "sanction",
        "event_date": "2018-09-06",
        "description": "Treasury sanctions Park Jin Hyok and front company Chosun Expo Joint Venture."
      },
      {
        "event_type": "indictment",
        "event_date": "2021-02-17",
        "description": "Unsealing of superseding indictment adding co-conspirators Jon Chang Hyok and Kim Il."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Targeted spearphishing emails with weaponized attachments targeting Sony Pictures Entertainment employees, followed by fraudulent SWIFT banking credentials targeting the Bangladesh Central Bank, and weaponization of EternalBlue in WannaCry.",
      "blast_radius": "Extorted and destroyed Sony Pictures studio servers (forcing the cancellation of the theatrical premiere of The Interview); stole $81 million from the Bangladesh Central Bank via fraudulent SWIFT wire transfers; and paralyzed 300,000+ computers across 150 countries with WannaCry, forcing the UK National Health Service to divert emergency ambulances.",
      "kill_chain": [
        {
          "phase": "Initial Access",
          "title": "Targeted Spearphishing Attachments",
          "description": "Lazarus operatives sent spearphishing emails disguised as job inquiries and resume submissions to corporate personnel, containing malicious document macros that dropped the Brambul and Destover backdoors.",
          "technical_artifacts": [
            "Destover backdoor",
            "Brambul worm",
            "Malicious Word macros"
          ],
          "mitre_technique_id": "T1566.001"
        },
        {
          "phase": "Privilege Escalation & Staging",
          "title": "Domain Controller Domination and Wiper Staging",
          "description": "Operatives traversed corporate networks, compromising domain controllers and staging destructive disk-wiping payloads across file shares and production database clusters.",
          "technical_artifacts": [
            "Domain administrator compromise",
            "Batch script execution"
          ],
          "mitre_technique_id": "T1078"
        },
        {
          "phase": "Destructive Wiper Detonation",
          "title": "Sony Pictures Wiper and Data Leak",
          "description": "The Destover malware wiped master boot records, destroyed system files, and published private executive emails, unreleased movies, and employee Social Security numbers to public file-sharing sites.",
          "technical_artifacts": [
            "Destover wiper",
            "MBR corruption",
            "Public leak dumps"
          ],
          "mitre_technique_id": "T1485"
        },
        {
          "phase": "Financial Cyber Heist",
          "title": "Bangladesh Bank SWIFT Credential Compromise",
          "description": "Lazarus operatives breached the Bangladesh Central Bank network, harvesting SWIFT alliance terminal credentials to issue 35 fraudulent wire transfer orders totaling $951 million, successfully stealing $81 million.",
          "technical_artifacts": [
            "SWIFT alliance terminal compromise",
            "Custom PDF reader malware",
            "Printer manipulation"
          ],
          "mitre_technique_id": "T1041"
        },
        {
          "phase": "Global Ransomware Worm",
          "title": "WannaCry 2.0 EternalBlue Epidemic",
          "description": "Operatives combined the NSA EternalBlue SMB exploit with a cryptographic ransomware payload, releasing WannaCry. The worm spread uncontrollably across 300,000 computers worldwide in hours until a security researcher registered its kill-switch domain.",
          "technical_artifacts": [
            "WannaCry.exe",
            "EternalBlue (CVE-2017-0144)",
            "Kill-switch domain check"
          ],
          "mitre_technique_id": "T1486"
        }
      ],
      "defensive_takeaways": [
        "Implement out-of-band dual verification and hardware token security for all financial wire transfers and SWIFT terminals.",
        "Deploy endpoint application allowlisting to prevent execution of unverified wiper and ransomware binaries.",
        "Disable SMBv1 and promptly apply critical security patches across all network devices.",
        "Educate staff on identifying spearphishing attempts disguised as employment and business communications."
      ]
    }
  },
  {
    "id": "case-netwalker-vachon",
    "slug": "us-v-vachon-desjardins-netwalker",
    "title": "U.S. v. Vachon-Desjardins (Netwalker Ransomware)",
    "summary": "Affiliate of Netwalker ransomware responsible for attacking dozens of healthcare systems, universities, and businesses during the COVID-19 pandemic, extorting tens of millions of dollars.",
    "case_number": "8:20-cr-00366",
    "court": "U.S. District Court for the Middle District of Florida",
    "district": "M.D. Fla.",
    "country": "United States",
    "opened_at": "2020-12-16",
    "status": "sentenced",
    "victim_sector": "Healthcare, Education, Municipal Government",
    "victim_country": "United States, Canada",
    "loss_amount_usd": 21500000,
    "loss_amount_note": "Extorted $21.5 million in ransom payments; law enforcement seized 719 Bitcoin ($28 million) from his Canadian residence.",
    "first_seen_at": "2020-04-01T00:00:00Z",
    "last_updated_at": "2026-09-11T16:00:00Z",
    "actor_slug": "netwalker",
    "defendant_slugs": [
      "sebastien-vachon-desjardins"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1486",
        "evidence_excerpt": "Defendant injected Netwalker ransomware payloads into victim enterprise environments, encrypting files and leaving extortion notes with victim-specific payment portals.",
        "evidence_locator": "Plea Agreement \u00b6 4, Page 12",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Plea Agreement: U.S. v. Vachon-Desjardins",
        "source_url": "https://www.justice.gov/opa/pr/netwalker-ransomware-affiliate-sentenced-20-years-prison-role-international-cybercrime-scheme",
        "technique_name": "Data Encrypted for Impact",
        "tactic": "Impact"
      },
      {
        "technique_id": "T1078",
        "evidence_excerpt": "Vachon-Desjardins obtained unauthorized access to corporate networks by purchasing stolen Remote Desktop Protocol credentials.",
        "evidence_locator": "Plea Agreement \u00b6 4, Page 13",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Plea Agreement",
        "source_url": "https://www.justice.gov/opa/pr/netwalker-ransomware-affiliate-sentenced-20-years-prison-role-international-cybercrime-scheme",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1490",
        "evidence_excerpt": "Before executing the ransomware payload, defendant disabled shadow copies and altered registry settings to prevent recovery.",
        "evidence_locator": "Indictment \u00b6 8",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Vachon-Desjardins",
        "source_url": "https://www.justice.gov/opa/pr/netwalker-ransomware-affiliate-sentenced-20-years-prison-role-international-cybercrime-scheme",
        "technique_name": "Inhibit System Recovery",
        "tactic": "Impact"
      },
      {
        "technique_id": "T1112",
        "evidence_excerpt": "Netwalker modified registry keys under HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa to weaken local security authority validation.",
        "evidence_locator": "Plea Agreement \u00b6 6, Page 14",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Plea Agreement",
        "source_url": "https://www.justice.gov/opa/pr/netwalker-ransomware-affiliate-sentenced-20-years-prison-role-international-cybercrime-scheme",
        "technique_name": "Modify Registry",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1548.002",
        "evidence_excerpt": "The attacker used CMSTP and eventvwr.exe registry hijack methods to bypass Windows User Account Control without user prompting.",
        "evidence_locator": "Indictment \u00b6 11, Page 6",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment",
        "source_url": "https://www.justice.gov/opa/pr/netwalker-ransomware-affiliate-sentenced-20-years-prison-role-international-cybercrime-scheme",
        "technique_name": "Bypass User Account Control",
        "tactic": "Privilege Escalation"
      },
      {
        "technique_id": "T1007",
        "evidence_excerpt": "Vachon-Desjardins executed net start and sc query to enumerate installed antivirus services before deploying ransomware.",
        "evidence_locator": "Plea Agreement \u00b6 5, Page 13",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Plea Agreement",
        "source_url": "https://www.justice.gov/opa/pr/netwalker-ransomware-affiliate-sentenced-20-years-prison-role-international-cybercrime-scheme",
        "technique_name": "System Service Discovery",
        "tactic": "Discovery"
      }
    ],
    "events": [
      {
        "event_type": "indictment",
        "event_date": "2020-12-16",
        "description": "Federal grand jury in Tampa returns indictment charging Vachon-Desjardins with conspiracy to commit computer fraud and damage."
      },
      {
        "event_type": "extradition",
        "event_date": "2022-03-09",
        "description": "Vachon-Desjardins extradited from Canada to the United States."
      },
      {
        "event_type": "plea",
        "event_date": "2022-06-29",
        "description": "Defendant pleads guilty to all counts in the indictment."
      },
      {
        "event_type": "sentencing",
        "event_date": "2022-10-04",
        "description": "Sentenced to 240 months (20 years) in federal prison and ordered to forfeit $21.5 million."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Healthcare, Education, Municipal Government networks. Affiliate of Netwalker ransomware responsible for attacking dozens of healthcare systems, universities, and businesses during the COVID-19 pandemic, extorting tens of millions of dollars.",
      "blast_radius": "Extorted $21.5 million in ransom payments; law enforcement seized 719 Bitcoin ($28 million) from his Canadian residence. Impacted Healthcare, Education, Municipal Government infrastructure and associated victim operations.",
      "kill_chain": [
        {
          "phase": "Phase 1: Privilege Escalation",
          "title": "Privilege Escalation & Account Takeover",
          "description": "The attacker used CMSTP and eventvwr.exe registry hijack methods to bypass Windows User Account Control without user prompting.",
          "technical_artifacts": [
            "T1548.002",
            "Bypass User Account Control"
          ],
          "mitre_technique_id": "T1548.002"
        },
        {
          "phase": "Phase 2: Defense Evasion",
          "title": "Defense Evasion & Security Blindfolding",
          "description": "Vachon-Desjardins obtained unauthorized access to corporate networks by purchasing stolen Remote Desktop Protocol credentials.",
          "technical_artifacts": [
            "T1078",
            "Valid Accounts"
          ],
          "mitre_technique_id": "T1078"
        },
        {
          "phase": "Phase 3: Discovery",
          "title": "Internal Subnet & Trust Reconnaissance",
          "description": "Vachon-Desjardins executed net start and sc query to enumerate installed antivirus services before deploying ransomware.",
          "technical_artifacts": [
            "T1007",
            "System Service Discovery"
          ],
          "mitre_technique_id": "T1007"
        },
        {
          "phase": "Phase 4: Impact",
          "title": "Operational Disruption or Extortion Detonation",
          "description": "Defendant injected Netwalker ransomware payloads into victim enterprise environments, encrypting files and leaving extortion notes with victim-specific payment portals.",
          "technical_artifacts": [
            "T1486",
            "Data Encrypted for Impact"
          ],
          "mitre_technique_id": "T1486"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
        "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
        "Maintain isolated, immutable backups of critical directory services and transaction databases.",
        "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
      ]
    }
  },
  {
    "id": "case-seleznev-point-of-sale",
    "slug": "us-v-seleznev-track2",
    "title": "U.S. v. Roman Seleznev (Track2 Point-of-Sale Carding)",
    "summary": "Prolific cybercriminal (Track2) who hacked into more than 500 small businesses and restaurants across the United States, stealing millions of credit card numbers and generating tens of millions of dollars in illicit sales on automated carding portals.",
    "case_number": "2:11-cr-00070",
    "court": "U.S. District Court for the Western District of Washington",
    "district": "W.D. Wash.",
    "country": "United States",
    "opened_at": "2011-03-03",
    "status": "sentenced",
    "victim_sector": "Retail, Hospitality, Small Business",
    "victim_country": "United States",
    "loss_amount_usd": 169000000,
    "loss_amount_note": "Caused verified financial fraud losses of $169 million to 3,700 financial institutions.",
    "first_seen_at": "2009-10-01T00:00:00Z",
    "last_updated_at": "2026-09-08T15:00:00Z",
    "actor_slug": "track2",
    "defendant_slugs": [
      "roman-seleznev"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1046",
        "evidence_excerpt": "Seleznev conducted port scans across internet subnets searching for open and vulnerable Remote Desktop Protocol (RDP) port 3389.",
        "evidence_locator": "Trial Transcript Day 4, Page 82",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Trial Record: U.S. v. Seleznev",
        "source_url": "https://www.justice.gov/usao-wdwa/pr/prolific-russian-cyber-criminal-sentenced-27-years-prison-massive-scheme-hack-and-steal",
        "technique_name": "Network Service Discovery",
        "tactic": "Discovery"
      },
      {
        "technique_id": "T1110",
        "evidence_excerpt": "He used automated password brute force tools to guess administrative passwords on POS point-of-sale systems.",
        "evidence_locator": "Trial Transcript Day 5, Page 112",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Trial Record",
        "source_url": "https://www.justice.gov/usao-wdwa/pr/prolific-russian-cyber-criminal-sentenced-27-years-prison-massive-scheme-hack-and-steal",
        "technique_name": "Brute Force",
        "tactic": "Credential Access"
      },
      {
        "technique_id": "T1041",
        "evidence_excerpt": "Malicious memory-scraping software extracted Track 2 payment card data from process memory and exfiltrated packets to Russian server drops.",
        "evidence_locator": "Trial Exhibit 14-A",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Government Trial Exhibit",
        "source_url": "https://www.justice.gov/usao-wdwa/pr/prolific-russian-cyber-criminal-sentenced-27-years-prison-massive-scheme-hack-and-steal",
        "technique_name": "Exfiltration Over C2 Channel",
        "tactic": "Exfiltration"
      },
      {
        "technique_id": "T1588.002",
        "evidence_excerpt": "Seleznev purchased specialized memory scraping tools and POS card harvesting scripts from Russian underground forums.",
        "evidence_locator": "Trial Transcript Day 6, Page 140",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Trial Record",
        "source_url": "https://www.justice.gov/usao-wdwa/pr/prolific-russian-cyber-criminal-sentenced-27-years-prison-massive-scheme-hack-and-steal",
        "technique_name": "Obtain Tool",
        "tactic": "Resource Development"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2014-07-05",
        "description": "Seleznev arrested by U.S. Secret Service in the Maldives with a laptop containing 1.7 million stolen credit cards."
      },
      {
        "event_type": "verdict",
        "event_date": "2016-08-25",
        "description": "Jury finds Seleznev guilty of 38 federal felony counts including wire fraud and computer hacking."
      },
      {
        "event_type": "sentencing",
        "event_date": "2017-04-21",
        "description": "Sentenced to 324 months (27 years) in federal prison, the longest computer hacking sentence in U.S. history at the time, and ordered to pay $169,879,276 restitution."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Retail, Hospitality, Small Business networks. Prolific cybercriminal (Track2) who hacked into more than 500 small businesses and restaurants across the United States, stealing millions of credit card numbers and generating tens of millions of dollars in illicit sales on automated carding portals.",
      "blast_radius": "Caused verified financial fraud losses of $169 million to 3,700 financial institutions. Impacted Retail, Hospitality, Small Business infrastructure and associated victim operations.",
      "kill_chain": [
        {
          "phase": "Phase 1: Credential Access",
          "title": "Credential Harvesting & Memory Dumping",
          "description": "He used automated password brute force tools to guess administrative passwords on POS point-of-sale systems.",
          "technical_artifacts": [
            "T1110",
            "Brute Force"
          ],
          "mitre_technique_id": "T1110"
        },
        {
          "phase": "Phase 2: Discovery",
          "title": "Internal Subnet & Trust Reconnaissance",
          "description": "Seleznev conducted port scans across internet subnets searching for open and vulnerable Remote Desktop Protocol (RDP) port 3389.",
          "technical_artifacts": [
            "T1046",
            "Network Service Discovery"
          ],
          "mitre_technique_id": "T1046"
        },
        {
          "phase": "Phase 3: Exfiltration",
          "title": "Encrypted Cloud Data Exfiltration",
          "description": "Malicious memory-scraping software extracted Track 2 payment card data from process memory and exfiltrated packets to Russian server drops.",
          "technical_artifacts": [
            "T1041",
            "Exfiltration Over C2 Channel"
          ],
          "mitre_technique_id": "T1041"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
        "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
        "Maintain isolated, immutable backups of critical directory services and transaction databases.",
        "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
      ]
    }
  },
  {
    "id": "case-kaseya-revil",
    "slug": "us-v-vasinskyi-kaseya-revil",
    "title": "U.S. v. Yaroslav Vasinskyi (Kaseya VSA / REvil Ransomware)",
    "summary": "Ukrainian national and REvil ransomware affiliate responsible for deploying the ransomware attack that hijacked Kaseya VSA management software, instantly encrypting up to 1,500 downstream businesses on July 4th weekend.",
    "case_number": "3:21-cr-00314",
    "court": "U.S. District Court for the Northern District of Texas",
    "district": "N.D. Tex.",
    "country": "United States",
    "opened_at": "2021-08-11",
    "status": "sentenced",
    "victim_sector": "Managed Service Providers, Information Technology, Retail, Education",
    "victim_country": "United States, Sweden, New Zealand",
    "loss_amount_usd": 70000000,
    "loss_amount_note": "Extortion demands totaled $70 million for universal decryptor; extensive operational stoppage across schools, grocery stores, and local governments.",
    "first_seen_at": "2021-07-02T00:00:00Z",
    "last_updated_at": "2026-09-14T11:00:00Z",
    "actor_slug": "revil-sodinokibi",
    "defendant_slugs": [
      "yaroslav-vasinskyi",
      "yevgeniy-polyanin"
    ],
    "cves": [
      "CVE-2021-30116",
      "CVE-2021-30117",
      "CVE-2021-30118"
    ],
    "techniques": [
      {
        "technique_id": "T1190",
        "evidence_excerpt": "Vasinskyi exploited zero-day authentication bypass and SQL injection vulnerabilities in internet-facing Kaseya VSA servers.",
        "evidence_locator": "Indictment \u00b6 14, Page 7",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Vasinskyi",
        "source_url": "https://www.justice.gov/opa/pr/man-sentenced-role-revil-ransomware-attacks",
        "technique_name": "Exploit Public-Facing Application",
        "tactic": "Initial Access"
      },
      {
        "technique_id": "T1574.002",
        "evidence_excerpt": "The attacker used DLL side-loading with an outdated signed Windows Defender executable (MsMpEng.exe) to execute the REvil ransomware payload.",
        "evidence_locator": "CISA Advisory AA21-189A",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA21-189A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-189a",
        "technique_name": "DLL Side-Loading",
        "tactic": "Persistence"
      },
      {
        "technique_id": "T1486",
        "evidence_excerpt": "Over 1,500 downstream client networks were locked with Salsa20 encryption in a synchronized automated broadcast on July 2, 2021.",
        "evidence_locator": "Indictment \u00b6 16, Page 8",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Vasinskyi",
        "source_url": "https://www.justice.gov/opa/pr/man-sentenced-role-revil-ransomware-attacks",
        "technique_name": "Data Encrypted for Impact",
        "tactic": "Impact"
      },
      {
        "technique_id": "T1569.002",
        "evidence_excerpt": "Vasinskyi used Kaseya VSA management agents to execute arbitrary PowerShell commands disguised as automated administrative service tasks.",
        "evidence_locator": "Indictment \u00b6 15, Page 8",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment",
        "source_url": "https://www.justice.gov/opa/pr/man-sentenced-role-revil-ransomware-attacks",
        "technique_name": "Service Execution",
        "tactic": "Execution"
      },
      {
        "technique_id": "T1082",
        "evidence_excerpt": "The REvil dropper checked host architecture and operating system language, aborting execution if Russian locale strings were detected.",
        "evidence_locator": "CISA Advisory AA21-189A",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA21-189A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-189a",
        "technique_name": "System Information Discovery",
        "tactic": "Discovery"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2021-10-08",
        "description": "Vasinskyi arrested by Polish authorities at the Polish-Ukrainian border."
      },
      {
        "event_type": "extradition",
        "event_date": "2022-03-03",
        "description": "Extradited from Poland to the Northern District of Texas."
      },
      {
        "event_type": "plea",
        "event_date": "2022-11-01",
        "description": "Pled guilty to conspiracy to commit computer fraud and damage, money laundering, and related charges."
      },
      {
        "event_type": "sentencing",
        "event_date": "2024-05-01",
        "description": "Sentenced to 163 months (over 13 years) in federal prison and ordered to pay $16 million in restitution."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Adversary initial penetration relied on exploitation of known vulnerabilities (CVE-2021-30116, CVE-2021-30117, CVE-2021-30118) combined with targeted spearphishing and stolen remote access credentials.",
      "blast_radius": "Extortion demands totaled $70 million for universal decryptor; extensive operational stoppage across schools, grocery stores, and local governments. Impacted Managed Service Providers, Information Technology, Retail, Education infrastructure and associated victim operations.",
      "kill_chain": [
        {
          "phase": "Phase 1: Initial Access",
          "title": "Initial Perimeter Infiltration",
          "description": "Vasinskyi exploited zero-day authentication bypass and SQL injection vulnerabilities in internet-facing Kaseya VSA servers.",
          "technical_artifacts": [
            "T1190",
            "Exploit Public-Facing Application",
            "CVE-2021-30116",
            "CVE-2021-30117"
          ],
          "mitre_technique_id": "T1190"
        },
        {
          "phase": "Phase 2: Execution",
          "title": "Host Execution & Payload Staging",
          "description": "Vasinskyi used Kaseya VSA management agents to execute arbitrary PowerShell commands disguised as automated administrative service tasks.",
          "technical_artifacts": [
            "T1569.002",
            "Service Execution",
            "CVE-2021-30116",
            "CVE-2021-30117"
          ],
          "mitre_technique_id": "T1569.002"
        },
        {
          "phase": "Phase 3: Persistence",
          "title": "Persistent Foothold Establishment",
          "description": "The attacker used DLL side-loading with an outdated signed Windows Defender executable (MsMpEng.exe) to execute the REvil ransomware payload.",
          "technical_artifacts": [
            "T1574.002",
            "DLL Side-Loading",
            "CVE-2021-30116",
            "CVE-2021-30117"
          ],
          "mitre_technique_id": "T1574.002"
        },
        {
          "phase": "Phase 4: Discovery",
          "title": "Internal Subnet & Trust Reconnaissance",
          "description": "The REvil dropper checked host architecture and operating system language, aborting execution if Russian locale strings were detected.",
          "technical_artifacts": [
            "T1082",
            "System Information Discovery",
            "CVE-2021-30116",
            "CVE-2021-30117"
          ],
          "mitre_technique_id": "T1082"
        },
        {
          "phase": "Phase 5: Impact",
          "title": "Operational Disruption or Extortion Detonation",
          "description": "Over 1,500 downstream client networks were locked with Salsa20 encryption in a synchronized automated broadcast on July 2, 2021.",
          "technical_artifacts": [
            "T1486",
            "Data Encrypted for Impact",
            "CVE-2021-30116",
            "CVE-2021-30117"
          ],
          "mitre_technique_id": "T1486"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
        "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
        "Maintain isolated, immutable backups of critical directory services and transaction databases.",
        "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
      ]
    }
  },
  {
    "id": "case-baratov-yahoo",
    "slug": "us-v-baratov-yahoo-breach",
    "title": "U.S. v. Baratov et al. (Yahoo 2014 Breach / FSB Officers)",
    "summary": "Conspiracy between Russian Federal Security Service (FSB) officers and criminal hackers to breach Yahoo's network, compromising 500 million user accounts to conduct espionage against journalists, government officials, and commercial executives.",
    "case_number": "3:17-cr-00103",
    "court": "U.S. District Court for the Northern District of California",
    "district": "N.D. Cal.",
    "country": "United States",
    "opened_at": "2017-02-28",
    "status": "sentenced",
    "victim_sector": "Internet Services, Telecommunications",
    "victim_country": "United States",
    "loss_amount_usd": 350000000,
    "loss_amount_note": "Breach reduced Verizon's acquisition price of Yahoo by $350 million and required $117 million in class action settlement funds.",
    "first_seen_at": "2014-01-01T00:00:00Z",
    "last_updated_at": "2026-09-09T18:00:00Z",
    "actor_slug": "fsb-center-18",
    "defendant_slugs": [
      "karim-baratov",
      "dmitry-dokuchaev",
      "igor-sushchin",
      "alexsey-belan"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1566.002",
        "evidence_excerpt": "Spearphishing emails with malicious web links were sent to Yahoo employees to steal privileged system access credentials.",
        "evidence_locator": "Indictment \u00b6 22, Page 12",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Dokuchaev et al.",
        "source_url": "https://www.justice.gov/opa/pr/us-charges-russian-fsb-officers-and-their-criminal-conspirators-hacking-yahoo-and-using-stolen",
        "technique_name": "Spearphishing Link",
        "tactic": "Initial Access"
      },
      {
        "technique_id": "T1078",
        "evidence_excerpt": "Adversaries created forged cryptographic authentication cookies to access Yahoo webmail accounts of targeted individuals without passwords.",
        "evidence_locator": "Indictment \u00b6 31, Page 18",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment",
        "source_url": "https://www.justice.gov/opa/pr/us-charges-russian-fsb-officers-and-their-criminal-conspirators-hacking-yahoo-and-using-stolen",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1003",
        "evidence_excerpt": "Adversaries stole Yahoo's proprietary user database containing names, email addresses, cryptographic salts, and hashed passwords.",
        "evidence_locator": "Indictment \u00b6 27, Page 15",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment",
        "source_url": "https://www.justice.gov/opa/pr/us-charges-russian-fsb-officers-and-their-criminal-conspirators-hacking-yahoo-and-using-stolen",
        "technique_name": "OS Credential Dumping",
        "tactic": "Credential Access"
      }
    ],
    "events": [
      {
        "event_type": "indictment",
        "event_date": "2017-02-28",
        "description": "Indictment unsealed charging two FSB officers (Dokuchaev, Sushchin) and hackers Alexsey Belan and Karim Baratov."
      },
      {
        "event_type": "arrest",
        "event_date": "2017-03-14",
        "description": "Baratov arrested by Canadian authorities in Hamilton, Ontario."
      },
      {
        "event_type": "plea",
        "event_date": "2017-11-28",
        "description": "Baratov pleads guilty to nine counts of computer hacking and wire fraud conspiracies."
      },
      {
        "event_type": "sentencing",
        "event_date": "2018-05-29",
        "description": "Baratov sentenced to 60 months (5 years) in prison and fined $250,000."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Adversary breached the target network via Spearphishing Link. Spearphishing emails with malicious web links were sent to Yahoo employees to steal privileged system access credentials.",
      "blast_radius": "Breach reduced Verizon's acquisition price of Yahoo by $350 million and required $117 million in class action settlement funds. Impacted Internet Services, Telecommunications infrastructure and associated victim operations.",
      "kill_chain": [
        {
          "phase": "Phase 1: Initial Access",
          "title": "Initial Perimeter Infiltration",
          "description": "Spearphishing emails with malicious web links were sent to Yahoo employees to steal privileged system access credentials.",
          "technical_artifacts": [
            "T1566.002",
            "Spearphishing Link"
          ],
          "mitre_technique_id": "T1566.002"
        },
        {
          "phase": "Phase 2: Defense Evasion",
          "title": "Defense Evasion & Security Blindfolding",
          "description": "Adversaries created forged cryptographic authentication cookies to access Yahoo webmail accounts of targeted individuals without passwords.",
          "technical_artifacts": [
            "T1078",
            "Valid Accounts"
          ],
          "mitre_technique_id": "T1078"
        },
        {
          "phase": "Phase 3: Credential Access",
          "title": "Credential Harvesting & Memory Dumping",
          "description": "Adversaries stole Yahoo's proprietary user database containing names, email addresses, cryptographic salts, and hashed passwords.",
          "technical_artifacts": [
            "T1003",
            "OS Credential Dumping"
          ],
          "mitre_technique_id": "T1003"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
        "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
        "Maintain isolated, immutable backups of critical directory services and transaction databases.",
        "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
      ]
    }
  },
  {
    "id": "case-schulte-vault7",
    "slug": "us-v-schulte-cia-vault-7",
    "title": "U.S. v. Joshua Schulte (CIA Vault 7 Leak)",
    "summary": "Former Central Intelligence Agency software developer convicted of the historic transmission of classified CIA cyber warfare tools, source code, and zero-day exploits (Vault 7) to WikiLeaks, causing catastrophic national security damage.",
    "case_number": "1:17-cr-00548",
    "court": "U.S. District Court for the Southern District of New York",
    "district": "S.D.N.Y.",
    "country": "United States",
    "opened_at": "2017-08-24",
    "status": "sentenced",
    "victim_sector": "Intelligence, National Defense, Federal Government",
    "victim_country": "United States",
    "loss_amount_usd": 500000000,
    "loss_amount_note": "Government loss estimated in hundreds of millions in operational capability destruction across global intelligence activities.",
    "first_seen_at": "2016-04-20T00:00:00Z",
    "last_updated_at": "2026-09-10T11:00:00Z",
    "actor_slug": "insider-threat",
    "defendant_slugs": [
      "joshua-schulte"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1078",
        "evidence_excerpt": "Schulte abused his administrative credentials as a CIA Center for Cyber Intelligence software engineer to grant himself backdoor access to secure development servers.",
        "evidence_locator": "Indictment \u00b6 14, Page 8",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Schulte",
        "source_url": "https://www.justice.gov/usao-sdny/pr/former-cia-software-engineer-joshua-adam-schulte-sentenced-40-years-prison-espionage-and",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1070",
        "evidence_excerpt": "Defendant deleted server log files and altered system configuration timestamps to conceal his exfiltration of the CIA development branch.",
        "evidence_locator": "Indictment \u00b6 18, Page 11",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment",
        "source_url": "https://www.justice.gov/usao-sdny/pr/former-cia-software-engineer-joshua-adam-schulte-sentenced-40-years-prison-espionage-and",
        "technique_name": "Indicator Removal",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1560.001",
        "evidence_excerpt": "He compressed the entire CCI codebase into encrypted archives before transferring the files offsite.",
        "evidence_locator": "Trial Transcript Day 8",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Trial Record",
        "source_url": "https://www.justice.gov/usao-sdny/pr/former-cia-software-engineer-joshua-adam-schulte-sentenced-40-years-prison-espionage-and",
        "technique_name": "Archive via Utility",
        "tactic": "Collection"
      }
    ],
    "events": [
      {
        "event_type": "indictment",
        "event_date": "2018-06-18",
        "description": "Grand jury indicts Schulte for illegal transmission of national defense information and computer hacking under the Espionage Act."
      },
      {
        "event_type": "verdict",
        "event_date": "2022-07-13",
        "description": "Jury convicts Schulte on all counts of espionage, computer hacking, and obstruction of justice."
      },
      {
        "event_type": "sentencing",
        "event_date": "2024-02-01",
        "description": "Sentenced to 480 months (40 years) in federal prison."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Intelligence, National Defense, Federal Government networks. Former Central Intelligence Agency software developer convicted of the historic transmission of classified CIA cyber warfare tools, source code, and zero-day exploits (Vault 7) to WikiLeaks, causing catastrophic national security damage.",
      "blast_radius": "Government loss estimated in hundreds of millions in operational capability destruction across global intelligence activities. Impacted Intelligence, National Defense, Federal Government infrastructure and associated victim operations.",
      "kill_chain": [
        {
          "phase": "Phase 1: Defense Evasion",
          "title": "Defense Evasion & Security Blindfolding",
          "description": "Schulte abused his administrative credentials as a CIA Center for Cyber Intelligence software engineer to grant himself backdoor access to secure development servers.",
          "technical_artifacts": [
            "T1078",
            "Valid Accounts"
          ],
          "mitre_technique_id": "T1078"
        },
        {
          "phase": "Phase 2: Collection",
          "title": "Target Data Harvesting & Archiving",
          "description": "He compressed the entire CCI codebase into encrypted archives before transferring the files offsite.",
          "technical_artifacts": [
            "T1560.001",
            "Archive via Utility"
          ],
          "mitre_technique_id": "T1560.001"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
        "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
        "Maintain isolated, immutable backups of critical directory services and transaction databases.",
        "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
      ]
    }
  },
  {
    "id": "case-pla-unit-61398",
    "slug": "us-v-sun-kailiang-pla-unit-61398",
    "title": "U.S. v. Sun Kailiang et al. (PLA Unit 61398 / APT1)",
    "summary": "Historic first-ever criminal indictment against state military actors: five Chinese military officers in People's Liberation Army Unit 61398 charged with cyber espionage against Westinghouse, U.S. Steel, Alcoa, and the United Steelworkers union.",
    "case_number": "2:14-cr-00118",
    "court": "U.S. District Court for the Western District of Pennsylvania",
    "district": "W.D. Pa.",
    "country": "United States",
    "opened_at": "2014-05-01",
    "status": "fugitive",
    "victim_sector": "Nuclear Energy, Metals, Manufacturing, Clean Energy",
    "victim_country": "United States",
    "loss_amount_usd": 100000000,
    "loss_amount_note": "Theft of proprietary nuclear reactor designs, solar panel technology, and commercial negotiation strategies.",
    "first_seen_at": "2006-01-01T00:00:00Z",
    "last_updated_at": "2026-09-07T12:00:00Z",
    "actor_slug": "pla-unit-61398",
    "defendant_slugs": [
      "sun-kailiang",
      "huang-zhenyu",
      "wen-xinyu",
      "wang-dong",
      "gu-chunhui"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1566.001",
        "evidence_excerpt": "Defendants sent spearphishing emails containing malicious attachments to corporate engineers, appearing to come from colleagues or trade groups.",
        "evidence_locator": "Indictment \u00b6 15, Page 7",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Sun Kailiang",
        "source_url": "https://www.justice.gov/opa/pr/us-charges-five-chinese-military-hackers-cyber-espionage-against-us-corporations-and-labor",
        "technique_name": "Spearphishing Attachment",
        "tactic": "Initial Access"
      },
      {
        "technique_id": "T1041",
        "evidence_excerpt": "Exfiltrated thousands of sensitive proprietary technical specifications including AP1000 nuclear reactor piping diagrams.",
        "evidence_locator": "Indictment \u00b6 29, Page 16",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment",
        "source_url": "https://www.justice.gov/opa/pr/us-charges-five-chinese-military-hackers-cyber-espionage-against-us-corporations-and-labor",
        "technique_name": "Exfiltration Over C2 Channel",
        "tactic": "Exfiltration"
      }
    ],
    "events": [
      {
        "event_type": "indictment",
        "event_date": "2014-05-01",
        "description": "Grand jury unseals 31-count indictment against five PLA Unit 61398 military officers."
      },
      {
        "event_type": "sanction",
        "event_date": "2015-09-25",
        "description": "Cyber espionage agreement signed between U.S. and PRC following sustained enforcement pressure."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Adversary breached the target network via Spearphishing Attachment. Defendants sent spearphishing emails containing malicious attachments to corporate engineers, appearing to come from colleagues or trade groups.",
      "blast_radius": "Theft of proprietary nuclear reactor designs, solar panel technology, and commercial negotiation strategies. Impacted Nuclear Energy, Metals, Manufacturing, Clean Energy infrastructure and associated victim operations.",
      "kill_chain": [
        {
          "phase": "Phase 1: Initial Access",
          "title": "Initial Perimeter Infiltration",
          "description": "Defendants sent spearphishing emails containing malicious attachments to corporate engineers, appearing to come from colleagues or trade groups.",
          "technical_artifacts": [
            "T1566.001",
            "Spearphishing Attachment"
          ],
          "mitre_technique_id": "T1566.001"
        },
        {
          "phase": "Phase 2: Exfiltration",
          "title": "Encrypted Cloud Data Exfiltration",
          "description": "Exfiltrated thousands of sensitive proprietary technical specifications including AP1000 nuclear reactor piping diagrams.",
          "technical_artifacts": [
            "T1041",
            "Exfiltration Over C2 Channel"
          ],
          "mitre_technique_id": "T1041"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
        "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
        "Maintain isolated, immutable backups of critical directory services and transaction databases.",
        "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
      ]
    }
  },
  {
    "id": "case-gonzalez-carding",
    "slug": "us-v-albert-gonzalez-tjx-heartland",
    "title": "U.S. v. Albert Gonzalez (TJX & Heartland Payment Systems)",
    "summary": "Mastermind of the largest credit card theft operation in history at the time, hacking TJX Companies, BJ's Wholesale Club, OfficeMax, and Heartland Payment Systems, stealing over 130 million payment cards.",
    "case_number": "1:08-cr-10223",
    "court": "U.S. District Court for the District of Massachusetts",
    "district": "D. Mass.",
    "country": "United States",
    "opened_at": "2008-08-05",
    "status": "sentenced",
    "victim_sector": "Retail, Financial Payment Processors",
    "victim_country": "United States",
    "loss_amount_usd": 200000000,
    "loss_amount_note": "Direct merchant and bank losses in excess of $200 million across TJX and Heartland.",
    "first_seen_at": "2005-07-01T00:00:00Z",
    "last_updated_at": "2026-09-06T10:00:00Z",
    "actor_slug": "shadowcrew",
    "defendant_slugs": [
      "albert-gonzalez"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1190",
        "evidence_excerpt": "Gonzalez used automated SQL injection scripts against web servers to gain back-end access to internal payment processing networks.",
        "evidence_locator": "Indictment \u00b6 14, Page 6",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Gonzalez",
        "source_url": "https://www.justice.gov/opa/pr/former-secret-service-informant-sentenced-20-years-prison-massive-credit-card-theft",
        "technique_name": "Exploit Public-Facing Application",
        "tactic": "Initial Access"
      },
      {
        "technique_id": "T1041",
        "evidence_excerpt": "Installed packet sniffer utilities inside Heartland's payment processing network that captured unencrypted credit card magnetic stripe data during authorization.",
        "evidence_locator": "Indictment \u00b6 22, Page 10",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment",
        "source_url": "https://www.justice.gov/opa/pr/former-secret-service-informant-sentenced-20-years-prison-massive-credit-card-theft",
        "technique_name": "Exfiltration Over C2 Channel",
        "tactic": "Exfiltration"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2008-05-07",
        "description": "Gonzalez arrested in a Miami Beach hotel room by U.S. Secret Service agents."
      },
      {
        "event_type": "plea",
        "event_date": "2009-08-28",
        "description": "Pleads guilty to 19 counts of conspiracy, computer fraud, wire fraud, and aggravated identity theft."
      },
      {
        "event_type": "sentencing",
        "event_date": "2010-03-25",
        "description": "Sentenced to 240 months (20 years) in federal prison."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Adversary breached the target network via Exploit Public-Facing Application. Gonzalez used automated SQL injection scripts against web servers to gain back-end access to internal payment processing networks.",
      "blast_radius": "Direct merchant and bank losses in excess of $200 million across TJX and Heartland. Impacted Retail, Financial Payment Processors infrastructure and associated victim operations.",
      "kill_chain": [
        {
          "phase": "Phase 1: Initial Access",
          "title": "Initial Perimeter Infiltration",
          "description": "Gonzalez used automated SQL injection scripts against web servers to gain back-end access to internal payment processing networks.",
          "technical_artifacts": [
            "T1190",
            "Exploit Public-Facing Application"
          ],
          "mitre_technique_id": "T1190"
        },
        {
          "phase": "Phase 2: Exfiltration",
          "title": "Encrypted Cloud Data Exfiltration",
          "description": "Installed packet sniffer utilities inside Heartland's payment processing network that captured unencrypted credit card magnetic stripe data during authorization.",
          "technical_artifacts": [
            "T1041",
            "Exfiltration Over C2 Channel"
          ],
          "mitre_technique_id": "T1041"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
        "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
        "Maintain isolated, immutable backups of critical directory services and transaction databases.",
        "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
      ]
    }
  },
  {
    "id": "case-tyurin-jpmorgan",
    "slug": "us-v-tyurin-jpmorgan-chase",
    "title": "U.S. v. Andrei Tyurin (JPMorgan Chase Data Breach)",
    "summary": "Russian hacker who penetrated JPMorgan Chase and eleven other major U.S. financial institutions and media companies, stealing personal data belonging to over 100 million customers to fuel securities pump-and-dump schemes.",
    "case_number": "1:15-cr-00393",
    "court": "U.S. District Court for the Southern District of New York",
    "district": "S.D.N.Y.",
    "country": "United States",
    "opened_at": "2015-11-10",
    "status": "sentenced",
    "victim_sector": "Financial Services, Banking, Publishing",
    "victim_country": "United States",
    "loss_amount_usd": 19000000,
    "loss_amount_note": "Court ordered $19,952,861 in restitution to victim financial institutions.",
    "first_seen_at": "2012-01-01T00:00:00Z",
    "last_updated_at": "2026-09-05T14:00:00Z",
    "actor_slug": "shalon-cyber-syndicate",
    "defendant_slugs": [
      "andrei-tyurin"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1190",
        "evidence_excerpt": "Tyurin gained entry to JPMorgan Chase's network by exploiting an unpatched web application server lacking two-factor authentication.",
        "evidence_locator": "Indictment \u00b6 12, Page 6",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Tyurin",
        "source_url": "https://www.justice.gov/usao-sdny/pr/russian-hacker-andrei-tyurin-sentenced-12-years-prison-massive-cyber-attacks-us-financial",
        "technique_name": "Exploit Public-Facing Application",
        "tactic": "Initial Access"
      },
      {
        "technique_id": "T1041",
        "evidence_excerpt": "Exfiltrated contact records of 83 million individual and small business accounts, the largest single corporate breach of a U.S. bank at the time.",
        "evidence_locator": "Indictment \u00b6 15, Page 8",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment",
        "source_url": "https://www.justice.gov/usao-sdny/pr/russian-hacker-andrei-tyurin-sentenced-12-years-prison-massive-cyber-attacks-us-financial",
        "technique_name": "Exfiltration Over C2 Channel",
        "tactic": "Exfiltration"
      }
    ],
    "events": [
      {
        "event_type": "extradition",
        "event_date": "2018-09-07",
        "description": "Extradited from the Republic of Georgia to the Southern District of New York."
      },
      {
        "event_type": "plea",
        "event_date": "2019-09-23",
        "description": "Pleads guilty to computer intrusion, wire fraud, bank fraud, and illegal gambling conspiracies."
      },
      {
        "event_type": "sentencing",
        "event_date": "2021-01-07",
        "description": "Sentenced to 144 months (12 years) in federal prison and ordered to forfeit $19,214,956."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Adversary breached the target network via Exploit Public-Facing Application. Tyurin gained entry to JPMorgan Chase's network by exploiting an unpatched web application server lacking two-factor authentication.",
      "blast_radius": "Court ordered $19,952,861 in restitution to victim financial institutions. Impacted Financial Services, Banking, Publishing infrastructure and associated victim operations.",
      "kill_chain": [
        {
          "phase": "Phase 1: Initial Access",
          "title": "Initial Perimeter Infiltration",
          "description": "Tyurin gained entry to JPMorgan Chase's network by exploiting an unpatched web application server lacking two-factor authentication.",
          "technical_artifacts": [
            "T1190",
            "Exploit Public-Facing Application"
          ],
          "mitre_technique_id": "T1190"
        },
        {
          "phase": "Phase 2: Exfiltration",
          "title": "Encrypted Cloud Data Exfiltration",
          "description": "Exfiltrated contact records of 83 million individual and small business accounts, the largest single corporate breach of a U.S. bank at the time.",
          "technical_artifacts": [
            "T1041",
            "Exfiltration Over C2 Channel"
          ],
          "mitre_technique_id": "T1041"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
        "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
        "Maintain isolated, immutable backups of critical directory services and transaction databases.",
        "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
      ]
    }
  },
  {
    "id": "case-paige-thompson-capitalone",
    "slug": "us-v-thompson-capital-one-breach",
    "title": "U.S. v. Paige Thompson (Capital One Cloud Breach)",
    "summary": "Former Seattle cloud engineer who identified misconfigured web application firewalls to gain unauthorized access to Capital One's Amazon Web Services storage buckets, exfiltrating 106 million customer credit card applications.",
    "case_number": "2:19-cr-00159",
    "court": "U.S. District Court for the Western District of Washington",
    "district": "W.D. Wash.",
    "country": "United States",
    "opened_at": "2019-07-29",
    "status": "convicted",
    "victim_sector": "Financial Services, Cloud Computing",
    "victim_country": "United States, Canada",
    "loss_amount_usd": 270000000,
    "loss_amount_note": "Capital One incurred $270 million in customer notifications, legal settlements, and regulatory fines.",
    "first_seen_at": "2019-03-01T00:00:00Z",
    "last_updated_at": "2026-09-04T11:00:00Z",
    "actor_slug": "erratic",
    "defendant_slugs": [
      "paige-thompson"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1190",
        "evidence_excerpt": "Thompson sent crafted HTTP requests exploiting a Server-Side Request Forgery (SSRF) flaw in a misconfigured open-source ModSecurity WAF.",
        "evidence_locator": "Indictment \u00b6 9, Page 4",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Thompson",
        "source_url": "https://www.justice.gov/usao-wdwa/pr/former-seattle-tech-worker-convicted-wire-fraud-and-computer-intrusions",
        "technique_name": "Exploit Public-Facing Application",
        "tactic": "Initial Access"
      },
      {
        "technique_id": "T1078",
        "evidence_excerpt": "Obtained temporary security credentials from the AWS EC2 instance metadata service to access private S3 storage buckets.",
        "evidence_locator": "Trial Transcript Day 3, Page 54",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Trial Record",
        "source_url": "https://www.justice.gov/usao-wdwa/pr/former-seattle-tech-worker-convicted-wire-fraud-and-computer-intrusions",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1083",
        "evidence_excerpt": "Thompson ran automated aws-s3 listing commands to enumerate bucket contents across victim customer directories.",
        "evidence_locator": "Indictment \u00b6 12, Page 6",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Thompson",
        "source_url": "https://www.justice.gov/usao-wdwa/pr/former-seattle-tech-worker-convicted-wire-fraud-and-computer-intrusions",
        "technique_name": "File and Directory Discovery",
        "tactic": "Discovery"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2019-07-29",
        "description": "FBI agents arrest Thompson at her residence in Seattle."
      },
      {
        "event_type": "verdict",
        "event_date": "2022-06-17",
        "description": "Jury finds Thompson guilty of wire fraud and six counts of unauthorized access to a protected computer."
      },
      {
        "event_type": "sentencing",
        "event_date": "2022-10-04",
        "description": "Sentenced to time served and five years of supervised release with restitution ordered."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Adversary breached the target network via Exploit Public-Facing Application. Thompson sent crafted HTTP requests exploiting a Server-Side Request Forgery (SSRF) flaw in a misconfigured open-source ModSecurity WAF.",
      "blast_radius": "Capital One incurred $270 million in customer notifications, legal settlements, and regulatory fines. Impacted Financial Services, Cloud Computing infrastructure and associated victim operations.",
      "kill_chain": [
        {
          "phase": "Phase 1: Initial Access",
          "title": "Initial Perimeter Infiltration",
          "description": "Thompson sent crafted HTTP requests exploiting a Server-Side Request Forgery (SSRF) flaw in a misconfigured open-source ModSecurity WAF.",
          "technical_artifacts": [
            "T1190",
            "Exploit Public-Facing Application"
          ],
          "mitre_technique_id": "T1190"
        },
        {
          "phase": "Phase 2: Defense Evasion",
          "title": "Defense Evasion & Security Blindfolding",
          "description": "Obtained temporary security credentials from the AWS EC2 instance metadata service to access private S3 storage buckets.",
          "technical_artifacts": [
            "T1078",
            "Valid Accounts"
          ],
          "mitre_technique_id": "T1078"
        },
        {
          "phase": "Phase 3: Discovery",
          "title": "Internal Subnet & Trust Reconnaissance",
          "description": "Thompson ran automated aws-s3 listing commands to enumerate bucket contents across victim customer directories.",
          "technical_artifacts": [
            "T1083",
            "File and Directory Discovery"
          ],
          "mitre_technique_id": "T1083"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
        "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
        "Maintain isolated, immutable backups of critical directory services and transaction databases.",
        "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
      ]
    }
  },
  {
    "id": "case-bitzlato-hydra",
    "slug": "us-v-legkodymov-bitzlato",
    "title": "U.S. v. Anatoly Legkodymov (Bitzlato Cryptocurrency Laundering)",
    "summary": "Founder of Hong Kong-registered cryptocurrency exchange Bitzlato charged with laundering over $700 million in ransomware and darknet market illicit proceeds, serving as a primary financial conduit for Hydra Market.",
    "case_number": "1:23-cr-00021",
    "court": "U.S. District Court for the Eastern District of New York",
    "district": "E.D.N.Y.",
    "country": "United States",
    "opened_at": "2023-01-17",
    "status": "sentenced",
    "victim_sector": "Cryptocurrency, Financial Services",
    "victim_country": "United States, Russia, France",
    "loss_amount_usd": 700000000,
    "loss_amount_note": "Processed over $4.58 billion in crypto transactions, with at least $700 million directly tied to darknet contraband and ransomware proceeds.",
    "first_seen_at": "2018-05-01T00:00:00Z",
    "last_updated_at": "2026-09-03T16:00:00Z",
    "actor_slug": "bitzlato",
    "defendant_slugs": [
      "anatoly-legkodymov"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1090",
        "evidence_excerpt": "Bitzlato operated with negligible anti-money laundering controls, advertising that users could open accounts with no identity verification via Tor.",
        "evidence_locator": "Plea Agreement \u00b6 6, Page 7",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Plea Agreement: U.S. v. Legkodymov",
        "source_url": "https://www.justice.gov/opa/pr/founder-and-majority-owner-bitzlato-pleads-guilty-unlicensed-money-transmitting",
        "technique_name": "Proxy",
        "tactic": "Command and Control"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2023-01-17",
        "description": "Legkodymov arrested in Miami by FBI agents in coordinated international operation."
      },
      {
        "event_type": "plea",
        "event_date": "2023-12-06",
        "description": "Defendant pleads guilty to operating an unlicensed money transmitting business."
      },
      {
        "event_type": "sentencing",
        "event_date": "2024-07-18",
        "description": "Sentenced to time served (18 months) and ordered to forfeit all interest in Bitzlato ($23 million)."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Cryptocurrency, Financial Services networks. Founder of Hong Kong-registered cryptocurrency exchange Bitzlato charged with laundering over $700 million in ransomware and darknet market illicit proceeds, serving as a primary financial conduit for Hydra Market.",
      "blast_radius": "Processed over $4.58 billion in crypto transactions, with at least $700 million directly tied to darknet contraband and ransomware proceeds. Impacted Cryptocurrency, Financial Services infrastructure and associated victim operations.",
      "kill_chain": [
        {
          "phase": "Phase 1: Infiltration",
          "title": "Perimeter Ingress",
          "description": "Operatives secured access to victim infrastructure within the Cryptocurrency, Financial Services sector.",
          "technical_artifacts": [
            "Network perimeter logs"
          ],
          "mitre_technique_id": "T1190"
        },
        {
          "phase": "Phase 2: Execution",
          "title": "Payload Deployment",
          "description": "Founder of Hong Kong-registered cryptocurrency exchange Bitzlato charged with laundering over $700 million in ransomware and darknet market illicit proceeds, serving as a primary financial conduit for Hydra Market.",
          "technical_artifacts": [
            "Malicious payload"
          ],
          "mitre_technique_id": "T1486"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
        "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
        "Maintain isolated, immutable backups of critical directory services and transaction databases.",
        "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
      ]
    }
  },
  {
    "id": "case-genesis-market",
    "slug": "genesis-market-takedown-cookie-monster",
    "title": "Operation Cookie Monster (Genesis Market Takedown)",
    "summary": "Coordinated multinational takedown of Genesis Market, the world's most prominent illicit broker of stolen digital browser fingerprints, cookies, and compromised account credentials.",
    "case_number": "Operation Cookie Monster",
    "court": "U.S. District Court for the Eastern District of Wisconsin",
    "district": "E.D. Wis.",
    "country": "United States",
    "opened_at": "2023-04-04",
    "status": "alleged",
    "victim_sector": "Consumer Accounts, Banking, E-Commerce",
    "victim_country": "United States, United Kingdom, European Union, Australia",
    "loss_amount_usd": 50000000,
    "loss_amount_note": "Facilitated millions of unauthorized account takeover transactions across 1.5 million infected computers worldwide.",
    "first_seen_at": "2018-01-01T00:00:00Z",
    "last_updated_at": "2026-09-02T13:00:00Z",
    "actor_slug": "genesis-market",
    "defendant_slugs": [],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1555",
        "evidence_excerpt": "Genesis Market marketed specialized bots that packaged stolen browser cookies, session tokens, and passwords harvested by info-stealer malware.",
        "evidence_locator": "DOJ Seizure Affidavit \u00b6 12",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "DOJ Press Release 23-388",
        "source_url": "https://www.justice.gov/opa/pr/genesis-market-seized-multinational-operation",
        "technique_name": "Credentials from Password Stores",
        "tactic": "Credential Access"
      },
      {
        "technique_id": "T1078",
        "evidence_excerpt": "Purchasers loaded stolen fingerprints into custom browser plugins to perfectly impersonate victim machines and bypass fraud detection.",
        "evidence_locator": "DOJ Seizure Affidavit \u00b6 16",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "DOJ Seizure Notice",
        "source_url": "https://www.justice.gov/opa/pr/genesis-market-seized-multinational-operation",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      }
    ],
    "events": [
      {
        "event_type": "court_order",
        "event_date": "2023-04-04",
        "description": "FBI and 17 international partner agencies seize 11 domains hosting the Genesis Market infrastructure."
      },
      {
        "event_type": "arrest",
        "event_date": "2023-04-05",
        "description": "Over 120 arrests executed globally against Genesis Market high-volume purchasers."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Consumer Accounts, Banking, E-Commerce networks. Coordinated multinational takedown of Genesis Market, the world's most prominent illicit broker of stolen digital browser fingerprints, cookies, and compromised account credentials.",
      "blast_radius": "Facilitated millions of unauthorized account takeover transactions across 1.5 million infected computers worldwide. Impacted Consumer Accounts, Banking, E-Commerce infrastructure and associated victim operations.",
      "kill_chain": [
        {
          "phase": "Phase 1: Defense Evasion",
          "title": "Defense Evasion & Security Blindfolding",
          "description": "Purchasers loaded stolen fingerprints into custom browser plugins to perfectly impersonate victim machines and bypass fraud detection.",
          "technical_artifacts": [
            "T1078",
            "Valid Accounts"
          ],
          "mitre_technique_id": "T1078"
        },
        {
          "phase": "Phase 2: Credential Access",
          "title": "Credential Harvesting & Memory Dumping",
          "description": "Genesis Market marketed specialized bots that packaged stolen browser cookies, session tokens, and passwords harvested by info-stealer malware.",
          "technical_artifacts": [
            "T1555",
            "Credentials from Password Stores"
          ],
          "mitre_technique_id": "T1555"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
        "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
        "Maintain isolated, immutable backups of critical directory services and transaction databases.",
        "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
      ]
    }
  },
  {
    "id": "case-chipmixer-nguyen",
    "slug": "us-v-nguyen-chipmixer",
    "title": "U.S. v. Minh Quoc Nguyen (ChipMixer Cryptocurrency Mixer)",
    "summary": "Operator of ChipMixer, one of the dark web's largest unlicensed cryptocurrency mixing services, charged with laundering more than $3 billion in Bitcoin associated with ransomware, North Korean state hackers, and darknet drug markets.",
    "case_number": "2:23-mj-00122",
    "court": "U.S. District Court for the Eastern District of Pennsylvania",
    "district": "E.D. Pa.",
    "country": "United States",
    "opened_at": "2023-03-15",
    "status": "fugitive",
    "victim_sector": "Financial Services, Blockchain Infrastructure",
    "victim_country": "United States, Germany",
    "loss_amount_usd": 3000000000,
    "loss_amount_note": "Laundered over $3 billion in Bitcoin, including $700 million tied to Hydra Market and $200 million tied to LockBit and Zeppelin ransomware.",
    "first_seen_at": "2017-08-01T00:00:00Z",
    "last_updated_at": "2026-09-01T15:00:00Z",
    "actor_slug": "chipmixer",
    "defendant_slugs": [
      "minh-quoc-nguyen"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1090",
        "evidence_excerpt": "ChipMixer chopped up Bitcoin deposits into fixed small denomination chips and redistributed them through multiple dummy wallets to defeat blockchain tracing.",
        "evidence_locator": "Criminal Complaint \u00b6 8, Page 4",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Complaint: U.S. v. Nguyen",
        "source_url": "https://www.justice.gov/opa/pr/justice-department-investigation-leads-shutdown-darknet-cryptocurrency-mixer-processed-over-3",
        "technique_name": "Proxy",
        "tactic": "Command and Control"
      },
      {
        "technique_id": "T1571",
        "evidence_excerpt": "ChipMixer communicated with relay nodes over non-standard high ports to evade firewall packet categorization.",
        "evidence_locator": "Affidavit \u00b6 14, Page 8",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "DOJ Affidavit",
        "source_url": "https://www.justice.gov/opa/pr/justice-department-investigation-leads-shutdown-darknet-cryptocurrency-mixer-processed-over-3",
        "technique_name": "Non-Standard Port",
        "tactic": "Command and Control"
      }
    ],
    "events": [
      {
        "event_type": "indictment",
        "event_date": "2023-03-15",
        "description": "Criminal complaint filed in the Eastern District of Pennsylvania charging Nguyen with money laundering and identity theft."
      },
      {
        "event_type": "court_order",
        "event_date": "2023-03-15",
        "description": "Federal court order and German BKA operation seize ChipMixer servers and $46 million in cryptocurrency."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Financial Services, Blockchain Infrastructure networks. Operator of ChipMixer, one of the dark web's largest unlicensed cryptocurrency mixing services, charged with laundering more than $3 billion in Bitcoin associated with ransomware, North Korean state hackers, and darknet drug markets.",
      "blast_radius": "Laundered over $3 billion in Bitcoin, including $700 million tied to Hydra Market and $200 million tied to LockBit and Zeppelin ransomware. Impacted Financial Services, Blockchain Infrastructure infrastructure and associated victim operations.",
      "kill_chain": [
        {
          "phase": "Phase 1: Infiltration",
          "title": "Perimeter Ingress",
          "description": "Operatives secured access to victim infrastructure within the Financial Services, Blockchain Infrastructure sector.",
          "technical_artifacts": [
            "Network perimeter logs"
          ],
          "mitre_technique_id": "T1190"
        },
        {
          "phase": "Phase 2: Execution",
          "title": "Payload Deployment",
          "description": "Operator of ChipMixer, one of the dark web's largest unlicensed cryptocurrency mixing services, charged with laundering more than $3 billion in Bitcoin associated with ransomware, North Korean state hackers, and darknet drug markets.",
          "technical_artifacts": [
            "Malicious payload"
          ],
          "mitre_technique_id": "T1486"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
        "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
        "Maintain isolated, immutable backups of critical directory services and transaction databases.",
        "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
      ]
    }
  },
  {
    "id": "case-trickbot-witte",
    "slug": "us-v-witte-dunaev-trickbot",
    "title": "U.S. v. Alla Witte & Vladimir Dunaev (Trickbot Malware Group)",
    "summary": "Key software developers and coders of the transnational Trickbot cybercrime group charged with infecting millions of victim computers with banking trojans and facilitating Conti/Ryuk ransomware deployments against hospitals.",
    "case_number": "1:20-cr-00384",
    "court": "U.S. District Court for the Northern District of Ohio",
    "district": "N.D. Ohio",
    "country": "United States",
    "opened_at": "2021-02-18",
    "status": "sentenced",
    "victim_sector": "Healthcare, Banking, Local Government",
    "victim_country": "United States, United Kingdom, Australia",
    "loss_amount_usd": 180000000,
    "loss_amount_note": "Extorted tens of millions of dollars and caused hundreds of millions in financial damages to hospitals and municipalities.",
    "first_seen_at": "2016-10-01T00:00:00Z",
    "last_updated_at": "2026-08-30T10:00:00Z",
    "actor_slug": "wizard-spider",
    "defendant_slugs": [
      "alla-witte",
      "vladimir-dunaev"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1566.001",
        "evidence_excerpt": "Trickbot was deployed via phishing emails masquerading as legal notices containing weaponized Word documents with malicious macros.",
        "evidence_locator": "Indictment \u00b6 14, Page 7",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Witte et al.",
        "source_url": "https://www.justice.gov/opa/pr/russian-national-sentenced-role-developing-and-deploying-trickbot-malware",
        "technique_name": "Spearphishing Attachment",
        "tactic": "Initial Access"
      },
      {
        "technique_id": "T1003",
        "evidence_excerpt": "Injected modular credential harvesters that pulled domain credentials from Windows memory to pave the way for ransomware.",
        "evidence_locator": "Indictment \u00b6 19, Page 11",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment",
        "source_url": "https://www.justice.gov/opa/pr/russian-national-sentenced-role-developing-and-deploying-trickbot-malware",
        "technique_name": "OS Credential Dumping",
        "tactic": "Credential Access"
      },
      {
        "technique_id": "T1486",
        "evidence_excerpt": "Trickbot acted as the primary access loader for Ryuk and Conti ransomware gangs targeting US medical facilities.",
        "evidence_locator": "CISA Advisory AA20-302A",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA20-302A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-302a",
        "technique_name": "Data Encrypted for Impact",
        "tactic": "Impact"
      }
    ],
    "events": [
      {
        "event_type": "extradition",
        "event_date": "2021-06-04",
        "description": "Alla Witte extradited from Suriname to the Northern District of Ohio."
      },
      {
        "event_type": "extradition",
        "event_date": "2021-10-20",
        "description": "Vladimir Dunaev extradited from the Republic of Korea to the Northern District of Ohio."
      },
      {
        "event_type": "sentencing",
        "event_date": "2023-06-20",
        "description": "Alla Witte sentenced to 32 months in prison after pleading guilty."
      },
      {
        "event_type": "sentencing",
        "event_date": "2024-01-24",
        "description": "Vladimir Dunaev sentenced to 64 months (5 years and 4 months) in federal prison."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Adversary breached the target network via Spearphishing Attachment. Trickbot was deployed via phishing emails masquerading as legal notices containing weaponized Word documents with malicious macros.",
      "blast_radius": "Extorted tens of millions of dollars and caused hundreds of millions in financial damages to hospitals and municipalities. Impacted Healthcare, Banking, Local Government infrastructure and associated victim operations.",
      "kill_chain": [
        {
          "phase": "Phase 1: Initial Access",
          "title": "Initial Perimeter Infiltration",
          "description": "Trickbot was deployed via phishing emails masquerading as legal notices containing weaponized Word documents with malicious macros.",
          "technical_artifacts": [
            "T1566.001",
            "Spearphishing Attachment"
          ],
          "mitre_technique_id": "T1566.001"
        },
        {
          "phase": "Phase 2: Credential Access",
          "title": "Credential Harvesting & Memory Dumping",
          "description": "Injected modular credential harvesters that pulled domain credentials from Windows memory to pave the way for ransomware.",
          "technical_artifacts": [
            "T1003",
            "OS Credential Dumping"
          ],
          "mitre_technique_id": "T1003"
        },
        {
          "phase": "Phase 3: Impact",
          "title": "Operational Disruption or Extortion Detonation",
          "description": "Trickbot acted as the primary access loader for Ryuk and Conti ransomware gangs targeting US medical facilities.",
          "technical_artifacts": [
            "T1486",
            "Data Encrypted for Impact"
          ],
          "mitre_technique_id": "T1486"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
        "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
        "Maintain isolated, immutable backups of critical directory services and transaction databases.",
        "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
      ]
    }
  },
  {
    "id": "case-kriuchkov-tesla",
    "slug": "us-v-kriuchkov-tesla-ransomware",
    "title": "U.S. v. Egor Igorevich Kriuchkov (Tesla Insider Threat Attempt)",
    "summary": "Russian national who traveled to Nevada and offered a $1 million Bitcoin bribe to an employee at the Tesla Gigafactory in Sparks, Nevada, to introduce malware onto the company's internal network.",
    "case_number": "3:20-cr-00032",
    "court": "U.S. District Court for the District of Nevada",
    "district": "D. Nev.",
    "country": "United States",
    "opened_at": "2020-08-25",
    "status": "sentenced",
    "victim_sector": "Automotive, Advanced Manufacturing, Clean Energy",
    "victim_country": "United States",
    "loss_amount_usd": 4000000,
    "loss_amount_note": "Intended extortion demand was $4 million; operation was intercepted before malware execution.",
    "first_seen_at": "2020-07-16T00:00:00Z",
    "last_updated_at": "2026-08-28T14:00:00Z",
    "actor_slug": "kriuchkov-group",
    "defendant_slugs": [
      "egor-kriuchkov"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1078",
        "evidence_excerpt": "Defendant recruited an insider with legitimate administrator privileges to connect an infected USB drive and execute custom malware within the company's intranet.",
        "evidence_locator": "Criminal Complaint \u00b6 12, Page 6",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Complaint: U.S. v. Kriuchkov",
        "source_url": "https://www.justice.gov/opa/pr/russian-national-sentenced-conspiracy-cause-damage-protected-computer",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1486",
        "evidence_excerpt": "The plan called for staging a diversionary distributed denial of service attack while simultaneously exfiltrating trade secrets and encrypting production servers.",
        "evidence_locator": "Plea Agreement \u00b6 6, Page 5",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Plea Agreement",
        "source_url": "https://www.justice.gov/opa/pr/russian-national-sentenced-conspiracy-cause-damage-protected-computer",
        "technique_name": "Data Encrypted for Impact",
        "tactic": "Impact"
      },
      {
        "technique_id": "T1498",
        "evidence_excerpt": "The plan included launching a distributed network denial of service flood against Tesla's external gateways to distract security staff during malware deployment.",
        "evidence_locator": "Complaint \u00b6 15, Page 7",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Complaint: U.S. v. Kriuchkov",
        "source_url": "https://www.justice.gov/opa/pr/russian-national-sentenced-conspiracy-cause-damage-protected-computer",
        "technique_name": "Network Denial of Service",
        "tactic": "Impact"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2020-08-22",
        "description": "Kriuchkov arrested in Los Angeles while attempting to flee the United States."
      },
      {
        "event_type": "plea",
        "event_date": "2021-03-18",
        "description": "Pleads guilty to conspiracy to intentionally cause damage to a protected computer."
      },
      {
        "event_type": "sentencing",
        "event_date": "2021-05-25",
        "description": "Sentenced to time served (10 months) and ordered to pay $14,825 in restitution before deportation."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Automotive, Advanced Manufacturing, Clean Energy networks. Russian national who traveled to Nevada and offered a $1 million Bitcoin bribe to an employee at the Tesla Gigafactory in Sparks, Nevada, to introduce malware onto the company's internal network.",
      "blast_radius": "Intended extortion demand was $4 million; operation was intercepted before malware execution. Impacted Automotive, Advanced Manufacturing, Clean Energy infrastructure and associated victim operations.",
      "kill_chain": [
        {
          "phase": "Phase 1: Defense Evasion",
          "title": "Defense Evasion & Security Blindfolding",
          "description": "Defendant recruited an insider with legitimate administrator privileges to connect an infected USB drive and execute custom malware within the company's intranet.",
          "technical_artifacts": [
            "T1078",
            "Valid Accounts"
          ],
          "mitre_technique_id": "T1078"
        },
        {
          "phase": "Phase 2: Impact",
          "title": "Operational Disruption or Extortion Detonation",
          "description": "The plan called for staging a diversionary distributed denial of service attack while simultaneously exfiltrating trade secrets and encrypting production servers.",
          "technical_artifacts": [
            "T1486",
            "Data Encrypted for Impact"
          ],
          "mitre_technique_id": "T1486"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
        "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
        "Maintain isolated, immutable backups of critical directory services and transaction databases.",
        "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
      ]
    }
  },
  {
    "id": "case-marcus-hutchins-kronos",
    "slug": "us-v-hutchins-kronos-malware",
    "title": "U.S. v. Marcus Hutchins (Kronos Banking Malware)",
    "summary": "British malware researcher who previously halted the global WannaCry ransomware outbreak charged with authoring the Kronos banking trojan and UPAS kit years earlier as a teenager.",
    "case_number": "2:17-cr-00124",
    "court": "U.S. District Court for the Eastern District of Wisconsin",
    "district": "E.D. Wis.",
    "country": "United States",
    "opened_at": "2017-07-12",
    "status": "sentenced",
    "victim_sector": "Banking, Consumer Finance",
    "victim_country": "United States, Germany, United Kingdom",
    "loss_amount_usd": 1500000,
    "loss_amount_note": "Stole banking credentials and redirected bank transactions in criminal markets.",
    "first_seen_at": "2014-06-01T00:00:00Z",
    "last_updated_at": "2026-08-25T11:00:00Z",
    "actor_slug": "malwaretech",
    "defendant_slugs": [
      "marcus-hutchins"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1555",
        "evidence_excerpt": "Kronos recorded user keystrokes and used form-grabbing browser hooks to intercept unencrypted login credentials from banking websites.",
        "evidence_locator": "Superseding Indictment \u00b6 8, Page 4",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Hutchins",
        "source_url": "https://www.justice.gov/usao-edwi/pr/british-national-pleads-guilty-developing-and-distributing-malicious-computer-code",
        "technique_name": "Credentials from Password Stores",
        "tactic": "Credential Access"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2017-08-02",
        "description": "Hutchins arrested at Las Vegas airport following the DEF CON security conference."
      },
      {
        "event_type": "plea",
        "event_date": "2019-04-19",
        "description": "Pleads guilty to two counts of conspiracy to distribute malicious software."
      },
      {
        "event_type": "sentencing",
        "event_date": "2019-07-26",
        "description": "Sentenced to time served and one year of supervised release with no prison time or fines, recognizing his positive contributions in halting WannaCry."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Banking, Consumer Finance networks. British malware researcher who previously halted the global WannaCry ransomware outbreak charged with authoring the Kronos banking trojan and UPAS kit years earlier as a teenager.",
      "blast_radius": "Stole banking credentials and redirected bank transactions in criminal markets. Impacted Banking, Consumer Finance infrastructure and associated victim operations.",
      "kill_chain": [
        {
          "phase": "Phase 1: Credential Access",
          "title": "Credential Harvesting & Memory Dumping",
          "description": "Kronos recorded user keystrokes and used form-grabbing browser hooks to intercept unencrypted login credentials from banking websites.",
          "technical_artifacts": [
            "T1555",
            "Credentials from Password Stores"
          ],
          "mitre_technique_id": "T1555"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
        "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
        "Maintain isolated, immutable backups of critical directory services and transaction databases.",
        "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
      ]
    }
  },
  {
    "id": "case-nikulin-linkedin",
    "slug": "us-v-nikulin-linkedin-dropbox",
    "title": "U.S. v. Yevgeniy Nikulin (LinkedIn & Dropbox Breaches)",
    "summary": "Russian national who hacked into the corporate networks of LinkedIn, Dropbox, and Formspring, stealing login credentials of over 100 million users and selling the stolen database dumps on darknet forums.",
    "case_number": "3:16-cr-00440",
    "court": "U.S. District Court for the Northern District of California",
    "district": "N.D. Cal.",
    "country": "United States",
    "opened_at": "2016-10-05",
    "status": "sentenced",
    "victim_sector": "Internet Services, Social Media, Cloud Storage",
    "victim_country": "United States",
    "loss_amount_usd": 15000000,
    "loss_amount_note": "LinkedIn and Dropbox incurred millions in incident response and mandatory security overhauls.",
    "first_seen_at": "2012-03-01T00:00:00Z",
    "last_updated_at": "2026-08-20T16:00:00Z",
    "actor_slug": "chinik",
    "defendant_slugs": [
      "yevgeniy-nikulin"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1566.002",
        "evidence_excerpt": "Nikulin infected a LinkedIn employee's personal computer with malware via spearphishing to obtain corporate VPN credentials.",
        "evidence_locator": "Trial Transcript Day 4, Page 61",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Trial Record: U.S. v. Nikulin",
        "source_url": "https://www.justice.gov/usao-ndca/pr/russian-national-sentenced-88-months-prison-massive-cyberattacks-linkedin-and-dropbox",
        "technique_name": "Spearphishing Link",
        "tactic": "Initial Access"
      },
      {
        "technique_id": "T1078",
        "evidence_excerpt": "He pivoted through the employee's authenticated corporate session into internal databases containing user password hashes.",
        "evidence_locator": "Indictment \u00b6 14, Page 7",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment",
        "source_url": "https://www.justice.gov/usao-ndca/pr/russian-national-sentenced-88-months-prison-massive-cyberattacks-linkedin-and-dropbox",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2016-10-05",
        "description": "Nikulin arrested in Prague, Czech Republic, by Czech police pursuant to Interpol red notice."
      },
      {
        "event_type": "extradition",
        "event_date": "2018-03-30",
        "description": "Extradited from the Czech Republic to the United States after competing extradition requests from Russia were denied."
      },
      {
        "event_type": "verdict",
        "event_date": "2020-07-10",
        "description": "Jury finds Nikulin guilty of nine counts of computer intrusion, damage, and aggravated identity theft."
      },
      {
        "event_type": "sentencing",
        "event_date": "2020-09-29",
        "description": "Sentenced to 88 months (7 years and 4 months) in federal prison."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Adversary breached the target network via Spearphishing Link. Nikulin infected a LinkedIn employee's personal computer with malware via spearphishing to obtain corporate VPN credentials.",
      "blast_radius": "LinkedIn and Dropbox incurred millions in incident response and mandatory security overhauls. Impacted Internet Services, Social Media, Cloud Storage infrastructure and associated victim operations.",
      "kill_chain": [
        {
          "phase": "Phase 1: Initial Access",
          "title": "Initial Perimeter Infiltration",
          "description": "Nikulin infected a LinkedIn employee's personal computer with malware via spearphishing to obtain corporate VPN credentials.",
          "technical_artifacts": [
            "T1566.002",
            "Spearphishing Link"
          ],
          "mitre_technique_id": "T1566.002"
        },
        {
          "phase": "Phase 2: Defense Evasion",
          "title": "Defense Evasion & Security Blindfolding",
          "description": "He pivoted through the employee's authenticated corporate session into internal databases containing user password hashes.",
          "technical_artifacts": [
            "T1078",
            "Valid Accounts"
          ],
          "mitre_technique_id": "T1078"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
        "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
        "Maintain isolated, immutable backups of critical directory services and transaction databases.",
        "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
      ]
    }
  },
  {
    "id": "case-levashov-kelihos",
    "slug": "us-v-levashov-kelihos-botnet",
    "title": "U.S. v. Peter Levashov (Kelihos Botnet)",
    "summary": "Russian operator (Severa) of the notorious Kelihos botnet, controlling over 100,000 infected computers worldwide used to harvest credentials, distribute ransomware, and blast billions of spam and stock pump-and-dump emails daily.",
    "case_number": "3:17-cr-00083",
    "court": "U.S. District Court for the District of Connecticut",
    "district": "D. Conn.",
    "country": "United States",
    "opened_at": "2017-04-07",
    "status": "pleaded",
    "victim_sector": "E-Commerce, Consumer Services, Telecommunications",
    "victim_country": "United States, Worldwide",
    "loss_amount_usd": 25000000,
    "loss_amount_note": "Generated tens of millions in fraudulent spam income and illicit botnet lease fees.",
    "first_seen_at": "2010-01-01T00:00:00Z",
    "last_updated_at": "2026-08-15T12:00:00Z",
    "actor_slug": "kelihos-crew",
    "defendant_slugs": [
      "peter-levashov"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1584",
        "evidence_excerpt": "Levashov leased out compromised zombie computers as an automated bulletproof proxy network to shield criminal infrastructure.",
        "evidence_locator": "Indictment \u00b6 11, Page 5",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Levashov",
        "source_url": "https://www.justice.gov/opa/pr/russian-national-pleads-guilty-operating-notorious-kelihos-botnet",
        "technique_name": "Compromise Infrastructure",
        "tactic": "Resource Development"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2017-04-07",
        "description": "Levashov arrested while vacationing in Barcelona, Spain, by Spanish National Police."
      },
      {
        "event_type": "extradition",
        "event_date": "2018-02-02",
        "description": "Extradited from Spain to the District of Connecticut."
      },
      {
        "event_type": "plea",
        "event_date": "2018-09-12",
        "description": "Pleads guilty to wire fraud, computer fraud, and identity theft charges."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against E-Commerce, Consumer Services, Telecommunications networks. Russian operator (Severa) of the notorious Kelihos botnet, controlling over 100,000 infected computers worldwide used to harvest credentials, distribute ransomware, and blast billions of spam and stock pump-and-dump emails daily.",
      "blast_radius": "Generated tens of millions in fraudulent spam income and illicit botnet lease fees. Impacted E-Commerce, Consumer Services, Telecommunications infrastructure and associated victim operations.",
      "kill_chain": [
        {
          "phase": "Phase 1: Infiltration",
          "title": "Perimeter Ingress",
          "description": "Operatives secured access to victim infrastructure within the E-Commerce, Consumer Services, Telecommunications sector.",
          "technical_artifacts": [
            "Network perimeter logs"
          ],
          "mitre_technique_id": "T1190"
        },
        {
          "phase": "Phase 2: Execution",
          "title": "Payload Deployment",
          "description": "Russian operator (Severa) of the notorious Kelihos botnet, controlling over 100,000 infected computers worldwide used to harvest credentials, distribute ransomware, and blast billions of spam and stock pump-and-dump emails daily.",
          "technical_artifacts": [
            "Malicious payload"
          ],
          "mitre_technique_id": "T1486"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
        "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
        "Maintain isolated, immutable backups of critical directory services and transaction databases.",
        "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
      ]
    }
  },
  {
    "id": "case-irgc-water-cyberav3ngers",
    "slug": "us-v-irgc-cyberav3ngers-water",
    "title": "U.S. v. IRGC Actors (CyberAv3ngers Critical Infrastructure Attacks)",
    "summary": "Indictment of members of the Iranian Islamic Revolutionary Guard Corps Cyber-Electronic Command who compromised Israeli-made Unitronics programmable logic controllers (PLCs) at American municipal water facilities.",
    "case_number": "2:24-cr-00185",
    "court": "U.S. District Court for the Western District of Pennsylvania",
    "district": "W.D. Pa.",
    "country": "United States",
    "opened_at": "2024-09-24",
    "status": "fugitive",
    "victim_sector": "Water and Wastewater Systems, Energy",
    "victim_country": "United States, Israel",
    "loss_amount_usd": 15000000,
    "loss_amount_note": "Forced manual pump operations at multiple municipal water authorities across Pennsylvania and New Jersey.",
    "first_seen_at": "2023-11-25T00:00:00Z",
    "last_updated_at": "2026-09-21T18:00:00Z",
    "actor_slug": "irgc-cyber-electronic-command",
    "defendant_slugs": [
      "hamid-reza-lashgarian",
      "mahdi-lashgarian"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1078",
        "evidence_excerpt": "Defendants gained access to internet-connected Unitronics Vision PLCs because the industrial devices remained configured with the default manufacturer password '1111'.",
        "evidence_locator": "CISA Advisory AA23-335A \u00b6 4",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA23-335A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-335a",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1485",
        "evidence_excerpt": "Attackers defaced screen displays on industrial pressure monitoring stations with anti-Israel political slogans and halted remote pump regulation.",
        "evidence_locator": "Indictment \u00b6 18, Page 9",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "DOJ Indictment Press Release",
        "source_url": "https://www.justice.gov/opa/pr/justice-department-charges-six-iranian-nationals-cyberattacks-us-critical-infrastructure",
        "technique_name": "Data Destruction",
        "tactic": "Impact"
      }
    ],
    "events": [
      {
        "event_type": "advisory",
        "event_date": "2023-11-28",
        "description": "CISA publishes alert on exploitation of Unitronics PLCs used in water systems."
      },
      {
        "event_type": "sanction",
        "event_date": "2024-02-02",
        "description": "Treasury OFAC sanctions officials of the IRGC Cyber-Electronic Command."
      },
      {
        "event_type": "indictment",
        "event_date": "2024-09-24",
        "description": "Unsealing of criminal indictment against six Iranian military cyber actors."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Water and Wastewater Systems, Energy networks. Indictment of members of the Iranian Islamic Revolutionary Guard Corps Cyber-Electronic Command who compromised Israeli-made Unitronics programmable logic controllers (PLCs) at American municipal water facilities.",
      "blast_radius": "Forced manual pump operations at multiple municipal water authorities across Pennsylvania and New Jersey. Impacted Water and Wastewater Systems, Energy infrastructure and associated victim operations.",
      "kill_chain": [
        {
          "phase": "Phase 1: Defense Evasion",
          "title": "Defense Evasion & Security Blindfolding",
          "description": "Defendants gained access to internet-connected Unitronics Vision PLCs because the industrial devices remained configured with the default manufacturer password '1111'.",
          "technical_artifacts": [
            "T1078",
            "Valid Accounts"
          ],
          "mitre_technique_id": "T1078"
        },
        {
          "phase": "Phase 2: Impact",
          "title": "Operational Disruption or Extortion Detonation",
          "description": "Attackers defaced screen displays on industrial pressure monitoring stations with anti-Israel political slogans and halted remote pump regulation.",
          "technical_artifacts": [
            "T1485",
            "Data Destruction"
          ],
          "mitre_technique_id": "T1485"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
        "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
        "Maintain isolated, immutable backups of critical directory services and transaction databases.",
        "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
      ]
    }
  },
  {
    "id": "case-netyksho-apt28",
    "slug": "us-v-netyksho-apt28-dnc",
    "title": "U.S. v. Netyksho et al. (APT28 / GRU Unit 26165 DNC Hack)",
    "summary": "Twelve Russian GRU military intelligence officers charged with hacking into the Democratic National Committee and Hillary Clinton presidential campaign servers, exfiltrating emails, and orchestrating strategic leaks via DCLeaks and Guccifer 2.0.",
    "case_number": "1:18-cr-00215",
    "court": "U.S. District Court for the District of Columbia",
    "district": "D.D.C.",
    "country": "United States",
    "opened_at": "2018-07-13",
    "status": "fugitive",
    "victim_sector": "Political Organizations, Government",
    "victim_country": "United States",
    "loss_amount_usd": 10000000,
    "loss_amount_note": "Extensive campaign disruption and federal investigative expenditure.",
    "first_seen_at": "2016-03-15T00:00:00Z",
    "last_updated_at": "2026-09-02T10:00:00Z",
    "actor_slug": "apt28",
    "defendant_slugs": [
      "viktor-netyksho",
      "boris-antonov",
      "dmitriy-badin"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1566.002",
        "evidence_excerpt": "Conspirators sent spearphishing emails containing spoofed Google security warnings directing campaign staff to enter passwords on adversary domains.",
        "evidence_locator": "Indictment \u00b6 21, Page 8",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Netyksho",
        "source_url": "https://www.justice.gov/opa/pr/grand-jury-indicts-12-russian-intelligence-officers-hacking-offenses-related-2016-presidential",
        "technique_name": "Spearphishing Link",
        "tactic": "Initial Access"
      },
      {
        "technique_id": "T1059.001",
        "evidence_excerpt": "Defendants used custom X-Agent malware and executed PowerShell scripts to automate file collection across internal exchange servers.",
        "evidence_locator": "Indictment \u00b6 33, Page 14",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment",
        "source_url": "https://www.justice.gov/opa/pr/grand-jury-indicts-12-russian-intelligence-officers-hacking-offenses-related-2016-presidential",
        "technique_name": "PowerShell",
        "tactic": "Execution"
      },
      {
        "technique_id": "T1583.001",
        "evidence_excerpt": "GRU officers registered misleading domain names such as dcleaks.com and actblues.com using cryptocurrency to stage leaks.",
        "evidence_locator": "Indictment \u00b6 28, Page 12",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Netyksho",
        "source_url": "https://www.justice.gov/opa/pr/grand-jury-indicts-12-russian-intelligence-officers-hacking-offenses-related-2016-presidential",
        "technique_name": "Domains",
        "tactic": "Resource Development"
      },
      {
        "technique_id": "T1071.004",
        "evidence_excerpt": "X-Agent malware used DNS tunneling over port 53 to transmit command output across restricted network perimeter firewalls.",
        "evidence_locator": "Indictment \u00b6 35, Page 16",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment",
        "source_url": "https://www.justice.gov/opa/pr/grand-jury-indicts-12-russian-intelligence-officers-hacking-offenses-related-2016-presidential",
        "technique_name": "DNS Tunneling",
        "tactic": "Command and Control"
      },
      {
        "technique_id": "T1546.003",
        "evidence_excerpt": "Adversaries created WMI event filters to ensure backdoor persistence whenever Windows booted.",
        "evidence_locator": "Indictment \u00b6 38, Page 17",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment",
        "source_url": "https://www.justice.gov/opa/pr/grand-jury-indicts-12-russian-intelligence-officers-hacking-offenses-related-2016-presidential",
        "technique_name": "Windows Management Instrumentation Event Subscription",
        "tactic": "Persistence"
      }
    ],
    "events": [
      {
        "event_type": "indictment",
        "event_date": "2018-07-13",
        "description": "Special Counsel Robert Mueller unseals 11-count indictment against 12 GRU military officers."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Adversary breached the target network via Spearphishing Link. Conspirators sent spearphishing emails containing spoofed Google security warnings directing campaign staff to enter passwords on adversary domains.",
      "blast_radius": "Extensive campaign disruption and federal investigative expenditure. Impacted Political Organizations, Government infrastructure and associated victim operations.",
      "kill_chain": [
        {
          "phase": "Phase 1: Initial Access",
          "title": "Initial Perimeter Infiltration",
          "description": "Conspirators sent spearphishing emails containing spoofed Google security warnings directing campaign staff to enter passwords on adversary domains.",
          "technical_artifacts": [
            "T1566.002",
            "Spearphishing Link"
          ],
          "mitre_technique_id": "T1566.002"
        },
        {
          "phase": "Phase 2: Execution",
          "title": "Host Execution & Payload Staging",
          "description": "Defendants used custom X-Agent malware and executed PowerShell scripts to automate file collection across internal exchange servers.",
          "technical_artifacts": [
            "T1059.001",
            "PowerShell"
          ],
          "mitre_technique_id": "T1059.001"
        },
        {
          "phase": "Phase 3: Persistence",
          "title": "Persistent Foothold Establishment",
          "description": "Adversaries created WMI event filters to ensure backdoor persistence whenever Windows booted.",
          "technical_artifacts": [
            "T1546.003",
            "Windows Management Instrumentation Event Subscription"
          ],
          "mitre_technique_id": "T1546.003"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
        "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
        "Maintain isolated, immutable backups of critical directory services and transaction databases.",
        "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
      ]
    }
  },
  {
    "id": "case-brovko-botnet",
    "slug": "us-v-brovko-botnet-logs",
    "title": "U.S. v. Aleksandr Brovko (Botnet Parsing & Credential Sales)",
    "summary": "Russian national who developed automated scripts to parse botnet logs, extracting financial information and account credentials from thousands of victim computers and marketing them on cybercrime forums.",
    "case_number": "1:20-cr-00037",
    "court": "U.S. District Court for the Eastern District of Virginia",
    "district": "E.D. Va.",
    "country": "United States",
    "opened_at": "2020-02-12",
    "status": "sentenced",
    "victim_sector": "Consumer Finance, Banking",
    "victim_country": "United States",
    "loss_amount_usd": 100000000,
    "loss_amount_note": "Parsed stolen data contributing to more than $100 million in estimated consumer fraud losses.",
    "first_seen_at": "2007-01-01T00:00:00Z",
    "last_updated_at": "2026-08-18T14:00:00Z",
    "actor_slug": "brovko-network",
    "defendant_slugs": [
      "aleksandr-brovko"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1555",
        "evidence_excerpt": "Defendant wrote Python scripts to parse massive unorganized text files exfiltrated by info-stealer trojans to isolate valid credit card numbers and passwords.",
        "evidence_locator": "Plea Agreement \u00b6 4, Page 5",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Plea Agreement: U.S. v. Brovko",
        "source_url": "https://www.justice.gov/usao-edva/pr/russian-national-sentenced-conspiracy-commit-wire-fraud",
        "technique_name": "Credentials from Password Stores",
        "tactic": "Credential Access"
      }
    ],
    "events": [
      {
        "event_type": "plea",
        "event_date": "2020-02-14",
        "description": "Pleads guilty to conspiracy to commit wire fraud and computer intrusion."
      },
      {
        "event_type": "sentencing",
        "event_date": "2020-10-30",
        "description": "Sentenced to 96 months (8 years) in federal prison."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Consumer Finance, Banking networks. Russian national who developed automated scripts to parse botnet logs, extracting financial information and account credentials from thousands of victim computers and marketing them on cybercrime forums.",
      "blast_radius": "Parsed stolen data contributing to more than $100 million in estimated consumer fraud losses. Impacted Consumer Finance, Banking infrastructure and associated victim operations.",
      "kill_chain": [
        {
          "phase": "Phase 1: Credential Access",
          "title": "Credential Harvesting & Memory Dumping",
          "description": "Defendant wrote Python scripts to parse massive unorganized text files exfiltrated by info-stealer trojans to isolate valid credit card numbers and passwords.",
          "technical_artifacts": [
            "T1555",
            "Credentials from Password Stores"
          ],
          "mitre_technique_id": "T1555"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
        "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
        "Maintain isolated, immutable backups of critical directory services and transaction databases.",
        "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
      ]
    }
  },
  {
    "id": "case-firsov-deerio",
    "slug": "us-v-firsov-deer-io",
    "title": "U.S. v. Kirill Victorovich Firsov (Deer.io Dark Web Shop)",
    "summary": "Russian administrator of Deer.io, a decentralized cyber storefront platform hosting over 24,000 active automated shops selling hacked accounts, corporate credentials, and identity documents.",
    "case_number": "3:20-cr-01053",
    "court": "U.S. District Court for the Southern District of California",
    "district": "S.D. Cal.",
    "country": "United States",
    "opened_at": "2020-03-04",
    "status": "sentenced",
    "victim_sector": "Consumer Services, E-Commerce, Identity Providers",
    "victim_country": "United States, Worldwide",
    "loss_amount_usd": 17000000,
    "loss_amount_note": "Deer.io stores generated at least $17 million in cryptocurrency sales of stolen accounts.",
    "first_seen_at": "2013-10-01T00:00:00Z",
    "last_updated_at": "2026-08-14T11:00:00Z",
    "actor_slug": "deer-io",
    "defendant_slugs": [
      "kirill-firsov"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1078",
        "evidence_excerpt": "Deer.io functioned as an automated turn-key storefront allowing hackers to upload and sell stolen user account databases in bulk.",
        "evidence_locator": "Indictment \u00b6 8, Page 4",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Firsov",
        "source_url": "https://www.justice.gov/usao-sdca/pr/russian-national-sentenced-operating-cybercrime-storefront-trafficked-stolen-credentials",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2020-03-04",
        "description": "Firsov arrested by FBI agents at New York's John F. Kennedy International Airport."
      },
      {
        "event_type": "plea",
        "event_date": "2021-01-22",
        "description": "Pleads guilty to trafficking in unauthorized access devices."
      },
      {
        "event_type": "sentencing",
        "event_date": "2021-04-26",
        "description": "Sentenced to 30 months in federal prison."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Consumer Services, E-Commerce, Identity Providers networks. Russian administrator of Deer.io, a decentralized cyber storefront platform hosting over 24,000 active automated shops selling hacked accounts, corporate credentials, and identity documents.",
      "blast_radius": "Deer.io stores generated at least $17 million in cryptocurrency sales of stolen accounts. Impacted Consumer Services, E-Commerce, Identity Providers infrastructure and associated victim operations.",
      "kill_chain": [
        {
          "phase": "Phase 1: Defense Evasion",
          "title": "Defense Evasion & Security Blindfolding",
          "description": "Deer.io functioned as an automated turn-key storefront allowing hackers to upload and sell stolen user account databases in bulk.",
          "technical_artifacts": [
            "T1078",
            "Valid Accounts"
          ],
          "mitre_technique_id": "T1078"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
        "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
        "Maintain isolated, immutable backups of critical directory services and transaction databases.",
        "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
      ]
    }
  },
  {
    "id": "case-medvedev-infraud",
    "slug": "us-v-medvedev-infraud-organization",
    "title": "U.S. v. Sergey Medvedev et al. (Infraud Organization)",
    "summary": "Global cybercrime enterprise operating under the slogan 'In Fraud We Trust' with over 10,000 members, trafficking in stolen identities, counterfeit documents, compromised credit cards, and banking trojans.",
    "case_number": "2:17-cr-00360",
    "court": "U.S. District Court for the District of Nevada",
    "district": "D. Nev.",
    "country": "United States",
    "opened_at": "2018-01-26",
    "status": "sentenced",
    "victim_sector": "Financial Services, Consumer Credit, Retail",
    "victim_country": "United States, Worldwide",
    "loss_amount_usd": 568000000,
    "loss_amount_note": "Caused actual financial losses of over $568 million to financial institutions and cardholders.",
    "first_seen_at": "2010-10-01T00:00:00Z",
    "last_updated_at": "2026-08-10T15:00:00Z",
    "actor_slug": "infraud-organization",
    "defendant_slugs": [
      "sergey-medvedev"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1078",
        "evidence_excerpt": "Infraud operated escrow systems enabling cybercriminals to buy and sell verified high-balance administrative account credentials.",
        "evidence_locator": "Indictment \u00b6 14, Page 7",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Medvedev",
        "source_url": "https://www.justice.gov/opa/pr/co-founder-infraud-organization-sentenced-10-years-prison-role-568-million-cyberfraud-enterprise",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2018-02-02",
        "description": "Medvedev arrested in Bangkok, Thailand, with over 100,000 Bitcoins in digital wallets."
      },
      {
        "event_type": "plea",
        "event_date": "2020-06-26",
        "description": "Pleads guilty to RICO conspiracy in federal court in Las Vegas."
      },
      {
        "event_type": "sentencing",
        "event_date": "2021-03-19",
        "description": "Sentenced to 120 months (10 years) in federal prison."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Financial Services, Consumer Credit, Retail networks. Global cybercrime enterprise operating under the slogan 'In Fraud We Trust' with over 10,000 members, trafficking in stolen identities, counterfeit documents, compromised credit cards, and banking trojans.",
      "blast_radius": "Caused actual financial losses of over $568 million to financial institutions and cardholders. Impacted Financial Services, Consumer Credit, Retail infrastructure and associated victim operations.",
      "kill_chain": [
        {
          "phase": "Phase 1: Defense Evasion",
          "title": "Defense Evasion & Security Blindfolding",
          "description": "Infraud operated escrow systems enabling cybercriminals to buy and sell verified high-balance administrative account credentials.",
          "technical_artifacts": [
            "T1078",
            "Valid Accounts"
          ],
          "mitre_technique_id": "T1078"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
        "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
        "Maintain isolated, immutable backups of critical directory services and transaction databases.",
        "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
      ]
    }
  },
  {
    "id": "case-barriss-swatting",
    "slug": "us-v-barriss-serial-swatting",
    "title": "U.S. v. Tyler Barriss (Serial Swatting / Wichita Incident)",
    "summary": "Perpetrator of dozens of fraudulent emergency 911 calls and bomb threats across the United States for hire, culminating in a fatal police shooting in Wichita, Kansas, over a Call of Duty video game dispute.",
    "case_number": "6:18-cr-10028",
    "court": "U.S. District Court for the District of Kansas",
    "district": "D. Kan.",
    "country": "United States",
    "opened_at": "2018-03-20",
    "status": "sentenced",
    "victim_sector": "Emergency Services, Municipalities, Schools",
    "victim_country": "United States",
    "loss_amount_usd": 1500000,
    "loss_amount_note": "Caused tragic loss of innocent human life, massive municipal emergency response mobilization, and $1.5 million in damages.",
    "first_seen_at": "2017-01-01T00:00:00Z",
    "last_updated_at": "2026-08-05T12:00:00Z",
    "actor_slug": "swatting-group",
    "defendant_slugs": [
      "tyler-barriss"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1090",
        "evidence_excerpt": "Barriss routed VoIP phone communications through anonymous proxies and spoofing apps to simulate local caller ID numbers during emergency calls.",
        "evidence_locator": "Plea Agreement \u00b6 5, Page 4",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Plea Agreement: U.S. v. Barriss",
        "source_url": "https://www.justice.gov/opa/pr/serial-swatter-sentenced-20-years-prison-fatal-wichita-kansas-swatting",
        "technique_name": "Proxy",
        "tactic": "Command and Control"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2017-12-29",
        "description": "Barriss arrested by Los Angeles police following the fatal Wichita swatting call."
      },
      {
        "event_type": "plea",
        "event_date": "2018-11-13",
        "description": "Pleads guilty to 51 federal charges including cyberstalking, false emergency reporting, and wire fraud."
      },
      {
        "event_type": "sentencing",
        "event_date": "2019-03-29",
        "description": "Sentenced to 240 months (20 years) in federal prison."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Emergency Services, Municipalities, Schools networks. Perpetrator of dozens of fraudulent emergency 911 calls and bomb threats across the United States for hire, culminating in a fatal police shooting in Wichita, Kansas, over a Call of Duty video game dispute.",
      "blast_radius": "Caused tragic loss of innocent human life, massive municipal emergency response mobilization, and $1.5 million in damages. Impacted Emergency Services, Municipalities, Schools infrastructure and associated victim operations.",
      "kill_chain": [
        {
          "phase": "Phase 1: Infiltration",
          "title": "Perimeter Ingress",
          "description": "Operatives secured access to victim infrastructure within the Emergency Services, Municipalities, Schools sector.",
          "technical_artifacts": [
            "Network perimeter logs"
          ],
          "mitre_technique_id": "T1190"
        },
        {
          "phase": "Phase 2: Execution",
          "title": "Payload Deployment",
          "description": "Perpetrator of dozens of fraudulent emergency 911 calls and bomb threats across the United States for hire, culminating in a fatal police shooting in Wichita, Kansas, over a Call of Duty video game dispute.",
          "technical_artifacts": [
            "Malicious payload"
          ],
          "mitre_technique_id": "T1486"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
        "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
        "Maintain isolated, immutable backups of critical directory services and transaction databases.",
        "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
      ]
    }
  },
  {
    "id": "case-brett-johnson-shadowcrew",
    "slug": "us-v-johnson-shadowcrew",
    "title": "U.S. v. Brett Johnson (ShadowCrew Cybercrime Syndicate)",
    "summary": "Pioneering cybercriminal known as 'The Original Internet Godfather' who built and operated ShadowCrew, the prototypical dark web marketplace for trafficking in stolen identities and credit card data.",
    "case_number": "2:04-cr-00725",
    "court": "U.S. District Court for the District of New Jersey",
    "district": "D.N.J.",
    "country": "United States",
    "opened_at": "2004-10-26",
    "status": "sentenced",
    "victim_sector": "Banking, Consumer Identity, E-Commerce",
    "victim_country": "United States",
    "loss_amount_usd": 4000000,
    "loss_amount_note": "Facilitated millions in fraudulent debit card cloning transactions.",
    "first_seen_at": "2002-05-01T00:00:00Z",
    "last_updated_at": "2026-08-01T10:00:00Z",
    "actor_slug": "shadowcrew",
    "defendant_slugs": [
      "brett-johnson"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1566.002",
        "evidence_excerpt": "Johnson established early phishing operations that cloned PayPal and eBay authentication web pages to steal account credentials.",
        "evidence_locator": "Indictment \u00b6 11, Page 6",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Johnson",
        "source_url": "https://www.justice.gov/archive/criminal/cybercrime/press-releases/2004/shadowcrewIndict.htm",
        "technique_name": "Spearphishing Link",
        "tactic": "Initial Access"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2005-02-08",
        "description": "Johnson arrested by U.S. Secret Service in Operation Open Market."
      },
      {
        "event_type": "sentencing",
        "event_date": "2007-06-20",
        "description": "Sentenced to 90 months (7.5 years) in federal prison."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Adversary breached the target network via Spearphishing Link. Johnson established early phishing operations that cloned PayPal and eBay authentication web pages to steal account credentials.",
      "blast_radius": "Facilitated millions in fraudulent debit card cloning transactions. Impacted Banking, Consumer Identity, E-Commerce infrastructure and associated victim operations.",
      "kill_chain": [
        {
          "phase": "Phase 1: Initial Access",
          "title": "Initial Perimeter Infiltration",
          "description": "Johnson established early phishing operations that cloned PayPal and eBay authentication web pages to steal account credentials.",
          "technical_artifacts": [
            "T1566.002",
            "Spearphishing Link"
          ],
          "mitre_technique_id": "T1566.002"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
        "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
        "Maintain isolated, immutable backups of critical directory services and transaction databases.",
        "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
      ]
    }
  },
  {
    "id": "case-max-vision-cardersmarket",
    "slug": "us-v-vision-cardersmarket",
    "title": "U.S. v. Max Ray Vision (Iceman / CardersMarket)",
    "summary": "Former white-hat computer security analyst turned master cybercriminal who operated CardersMarket, hacking rival criminal forums to steal their user databases and monopolize illicit credit card trafficking.",
    "case_number": "3:07-cr-00624",
    "court": "U.S. District Court for the Northern District of California",
    "district": "N.D. Cal.",
    "country": "United States",
    "opened_at": "2007-09-10",
    "status": "sentenced",
    "victim_sector": "Financial Services, Retail",
    "victim_country": "United States",
    "loss_amount_usd": 86000000,
    "loss_amount_note": "Stole approximately 2 million credit card numbers, causing $86 million in fraudulent charges.",
    "first_seen_at": "2004-01-01T00:00:00Z",
    "last_updated_at": "2026-07-28T14:00:00Z",
    "actor_slug": "cardersmarket",
    "defendant_slugs": [
      "max-vision"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1190",
        "evidence_excerpt": "Vision exploited web application vulnerabilities in competitor dark web portals to compromise forum SQL databases and hijack customer accounts.",
        "evidence_locator": "Indictment \u00b6 14, Page 7",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Vision",
        "source_url": "https://www.justice.gov/archive/criminal/cybercrime/press-releases/2010/visionSent.pdf",
        "technique_name": "Exploit Public-Facing Application",
        "tactic": "Initial Access"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2007-09-08",
        "description": "Vision arrested at his San Francisco apartment by federal agents."
      },
      {
        "event_type": "plea",
        "event_date": "2009-06-29",
        "description": "Pleads guilty to two counts of wire fraud conspiracy."
      },
      {
        "event_type": "sentencing",
        "event_date": "2010-02-12",
        "description": "Sentenced to 168 months (14 years) in federal prison and ordered to pay $27.5 million in restitution."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Adversary breached the target network via Exploit Public-Facing Application. Vision exploited web application vulnerabilities in competitor dark web portals to compromise forum SQL databases and hijack customer accounts.",
      "blast_radius": "Stole approximately 2 million credit card numbers, causing $86 million in fraudulent charges. Impacted Financial Services, Retail infrastructure and associated victim operations.",
      "kill_chain": [
        {
          "phase": "Phase 1: Initial Access",
          "title": "Initial Perimeter Infiltration",
          "description": "Vision exploited web application vulnerabilities in competitor dark web portals to compromise forum SQL databases and hijack customer accounts.",
          "technical_artifacts": [
            "T1190",
            "Exploit Public-Facing Application"
          ],
          "mitre_technique_id": "T1190"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
        "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
        "Maintain isolated, immutable backups of critical directory services and transaction databases.",
        "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
      ]
    }
  },
  {
    "id": "case-khusyaynova-lakhta",
    "slug": "us-v-khusyaynova-project-lakhta",
    "title": "U.S. v. Elena Alekseevna Khusyaynova (Project Lakhta)",
    "summary": "Russian chief accountant charged with managing the financial administration of Project Lakhta, a massive state-funded covert influence and cyber operation designed to sow political discord in U.S. elections.",
    "case_number": "1:18-mj-00464",
    "court": "U.S. District Court for the Eastern District of Virginia",
    "district": "E.D. Va.",
    "country": "United States",
    "opened_at": "2018-09-28",
    "status": "fugitive",
    "victim_sector": "Electoral Systems, Social Media, Public Institutions",
    "victim_country": "United States",
    "loss_amount_usd": 35000000,
    "loss_amount_note": "Managed an operating budget exceeding $35 million for covert information warfare activities.",
    "first_seen_at": "2014-04-01T00:00:00Z",
    "last_updated_at": "2026-07-25T11:00:00Z",
    "actor_slug": "project-lakhta",
    "defendant_slugs": [
      "elena-khusyaynova"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1584",
        "evidence_excerpt": "Operatives purchased thousands of virtual private servers and compromised proxy networks in the United States to disguise Russian origins.",
        "evidence_locator": "Criminal Complaint \u00b6 24, Page 12",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Complaint: U.S. v. Khusyaynova",
        "source_url": "https://www.justice.gov/opa/pr/russian-national-charged-interfering-us-political-system",
        "technique_name": "Compromise Infrastructure",
        "tactic": "Resource Development"
      }
    ],
    "events": [
      {
        "event_type": "indictment",
        "event_date": "2018-09-28",
        "description": "Criminal complaint filed charging Khusyaynova with conspiracy to defraud the United States."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Electoral Systems, Social Media, Public Institutions networks. Russian chief accountant charged with managing the financial administration of Project Lakhta, a massive state-funded covert influence and cyber operation designed to sow political discord in U.S. elections.",
      "blast_radius": "Managed an operating budget exceeding $35 million for covert information warfare activities. Impacted Electoral Systems, Social Media, Public Institutions infrastructure and associated victim operations.",
      "kill_chain": [
        {
          "phase": "Phase 1: Infiltration",
          "title": "Perimeter Ingress",
          "description": "Operatives secured access to victim infrastructure within the Electoral Systems, Social Media, Public Institutions sector.",
          "technical_artifacts": [
            "Network perimeter logs"
          ],
          "mitre_technique_id": "T1190"
        },
        {
          "phase": "Phase 2: Execution",
          "title": "Payload Deployment",
          "description": "Russian chief accountant charged with managing the financial administration of Project Lakhta, a massive state-funded covert influence and cyber operation designed to sow political discord in U.S. elections.",
          "technical_artifacts": [
            "Malicious payload"
          ],
          "mitre_technique_id": "T1486"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
        "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
        "Maintain isolated, immutable backups of critical directory services and transaction databases.",
        "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
      ]
    }
  },
  {
    "id": "case-kulkov-try2check",
    "slug": "us-v-kulkov-try2check",
    "title": "U.S. v. Denis Gennadievich Kulkov (Try2Check Card Checking Service)",
    "summary": "Creator of Try2Check, the preeminent criminal card-checking platform that processed tens of millions of card verification requests annually for cybercriminals buying stolen credit cards.",
    "case_number": "1:23-cr-00171",
    "court": "U.S. District Court for the Eastern District of New York",
    "district": "E.D.N.Y.",
    "country": "United States",
    "opened_at": "2023-04-18",
    "status": "fugitive",
    "victim_sector": "Financial Services, Payment Networks",
    "victim_country": "United States",
    "loss_amount_usd": 18000000,
    "loss_amount_note": "Earned over $18 million in Bitcoin fees running the unauthorized credit card verification service.",
    "first_seen_at": "2005-01-01T00:00:00Z",
    "last_updated_at": "2026-07-20T16:00:00Z",
    "actor_slug": "try2check",
    "defendant_slugs": [
      "denis-kulkov"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1078",
        "evidence_excerpt": "Try2Check executed automated test transactions against merchant payment gateway APIs using stolen account logins.",
        "evidence_locator": "Indictment \u00b6 14, Page 7",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Kulkov",
        "source_url": "https://www.justice.gov/usao-edny/pr/justice-and-state-departments-announce-action-against-russian-national-operating-major",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      }
    ],
    "events": [
      {
        "event_type": "indictment",
        "event_date": "2023-04-18",
        "description": "Federal indictment unsealed charging Kulkov with access device fraud, computer intrusion, and money laundering; Try2Check domains seized in coordination with Austrian and German authorities."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Financial Services, Payment Networks networks. Creator of Try2Check, the preeminent criminal card-checking platform that processed tens of millions of card verification requests annually for cybercriminals buying stolen credit cards.",
      "blast_radius": "Earned over $18 million in Bitcoin fees running the unauthorized credit card verification service. Impacted Financial Services, Payment Networks infrastructure and associated victim operations.",
      "kill_chain": [
        {
          "phase": "Phase 1: Defense Evasion",
          "title": "Defense Evasion & Security Blindfolding",
          "description": "Try2Check executed automated test transactions against merchant payment gateway APIs using stolen account logins.",
          "technical_artifacts": [
            "T1078",
            "Valid Accounts"
          ],
          "mitre_technique_id": "T1078"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
        "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
        "Maintain isolated, immutable backups of critical directory services and transaction databases.",
        "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
      ]
    }
  },
  {
    "id": "case-incognito-siew",
    "slug": "us-v-siew-incognito-market",
    "title": "U.S. v. Rui-Siang Siew (Incognito Market Darknet Extortion)",
    "summary": "Owner and operator of Incognito Market who facilitated over $100 million in illicit darknet transactions before orchestrating an exit scam and extorting registered vendors and buyers with doxxing threats.",
    "case_number": "1:24-cr-00305",
    "court": "U.S. District Court for the Southern District of New York",
    "district": "S.D.N.Y.",
    "country": "United States",
    "opened_at": "2024-05-20",
    "status": "charged",
    "victim_sector": "Consumer Privacy, Cryptocurrency",
    "victim_country": "United States, Taiwan",
    "loss_amount_usd": 100000000,
    "loss_amount_note": "Processed over $100 million in illicit crypto sales and demanded extortion fees up to $20,000 per vendor.",
    "first_seen_at": "2020-10-01T00:00:00Z",
    "last_updated_at": "2026-07-15T12:00:00Z",
    "actor_slug": "incognito-market",
    "defendant_slugs": [
      "rui-siang-siew"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1090",
        "evidence_excerpt": "Operated hidden onion services over the Tor network equipped with automated cryptocurrency escrow mechanisms.",
        "evidence_locator": "Criminal Complaint \u00b6 8, Page 4",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Complaint: U.S. v. Siew",
        "source_url": "https://www.justice.gov/usao-sdny/pr/owner-and-operator-incognito-market-dark-web-narcotics-marketplace-arrested-and-charged",
        "technique_name": "Proxy",
        "tactic": "Command and Control"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2024-05-18",
        "description": "Siew arrested at JFK International Airport in New York upon arrival from Taiwan."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Consumer Privacy, Cryptocurrency networks. Owner and operator of Incognito Market who facilitated over $100 million in illicit darknet transactions before orchestrating an exit scam and extorting registered vendors and buyers with doxxing threats.",
      "blast_radius": "Processed over $100 million in illicit crypto sales and demanded extortion fees up to $20,000 per vendor. Impacted Consumer Privacy, Cryptocurrency infrastructure and associated victim operations.",
      "kill_chain": [
        {
          "phase": "Phase 1: Infiltration",
          "title": "Perimeter Ingress",
          "description": "Operatives secured access to victim infrastructure within the Consumer Privacy, Cryptocurrency sector.",
          "technical_artifacts": [
            "Network perimeter logs"
          ],
          "mitre_technique_id": "T1190"
        },
        {
          "phase": "Phase 2: Execution",
          "title": "Payload Deployment",
          "description": "Owner and operator of Incognito Market who facilitated over $100 million in illicit darknet transactions before orchestrating an exit scam and extorting registered vendors and buyers with doxxing threats.",
          "technical_artifacts": [
            "Malicious payload"
          ],
          "mitre_technique_id": "T1486"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
        "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
        "Maintain isolated, immutable backups of critical directory services and transaction databases.",
        "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
      ]
    }
  },
  {
    "id": "case-boiko-qqaazz",
    "slug": "us-v-boiko-qqaazz-laundering",
    "title": "U.S. v. Maksim Boiko (QQAAZZ Cyber Laundering Network)",
    "summary": "Russian cryptocurrency trader and Instagram influencer who operated as a high-level money launderer for QQAAZZ, an all-in-one cashout network servicing Dridex, Trickbot, and BitPaymer ransomware gangs.",
    "case_number": "2:20-cr-00227",
    "court": "U.S. District Court for the Western District of Pennsylvania",
    "district": "W.D. Pa.",
    "country": "United States",
    "opened_at": "2020-09-15",
    "status": "sentenced",
    "victim_sector": "Financial Institutions, Ransomware Victims",
    "victim_country": "United States, United Kingdom, Latvia, Georgia",
    "loss_amount_usd": 20000000,
    "loss_amount_note": "Laundered tens of millions of dollars stolen from corporate victims via hundreds of dummy shell bank accounts across Europe.",
    "first_seen_at": "2016-01-01T00:00:00Z",
    "last_updated_at": "2026-07-10T14:00:00Z",
    "actor_slug": "qqaazz",
    "defendant_slugs": [
      "maksim-boiko"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1090",
        "evidence_excerpt": "QQAAZZ used hundreds of bank accounts opened in the names of fake shell companies to rapidly layer stolen wire funds before converting them into Bitcoin.",
        "evidence_locator": "Indictment \u00b6 16, Page 9",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Boiko",
        "source_url": "https://www.justice.gov/opa/pr/fourteen-alleged-members-qqaazz-cybercrime-network-charged-laundering-millions-stolen-cyber",
        "technique_name": "Proxy",
        "tactic": "Command and Control"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2020-03-28",
        "description": "Boiko arrested in Miami, Florida, with $3.8 million in seized cryptocurrency."
      },
      {
        "event_type": "plea",
        "event_date": "2021-04-12",
        "description": "Pleads guilty to conspiracy to commit money laundering in federal court in Pittsburgh."
      },
      {
        "event_type": "sentencing",
        "event_date": "2021-07-16",
        "description": "Sentenced to time served and ordered to forfeit over $3.8 million in illicit cryptocurrency."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Financial Institutions, Ransomware Victims networks. Russian cryptocurrency trader and Instagram influencer who operated as a high-level money launderer for QQAAZZ, an all-in-one cashout network servicing Dridex, Trickbot, and BitPaymer ransomware gangs.",
      "blast_radius": "Laundered tens of millions of dollars stolen from corporate victims via hundreds of dummy shell bank accounts across Europe. Impacted Financial Institutions, Ransomware Victims infrastructure and associated victim operations.",
      "kill_chain": [
        {
          "phase": "Phase 1: Infiltration",
          "title": "Perimeter Ingress",
          "description": "Operatives secured access to victim infrastructure within the Financial Institutions, Ransomware Victims sector.",
          "technical_artifacts": [
            "Network perimeter logs"
          ],
          "mitre_technique_id": "T1190"
        },
        {
          "phase": "Phase 2: Execution",
          "title": "Payload Deployment",
          "description": "Russian cryptocurrency trader and Instagram influencer who operated as a high-level money launderer for QQAAZZ, an all-in-one cashout network servicing Dridex, Trickbot, and BitPaymer ransomware gangs.",
          "technical_artifacts": [
            "Malicious payload"
          ],
          "mitre_technique_id": "T1486"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
        "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
        "Maintain isolated, immutable backups of critical directory services and transaction databases.",
        "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
      ]
    }
  },
  {
    "id": "case-radchenko-sec-edgar-hack",
    "slug": "us-v-radchenko-sec-edgar-intrusion",
    "title": "U.S. v. Artem Radchenko (SEC EDGAR Insider Trading Hack)",
    "summary": "Ukrainian cybercriminals who hacked into the SEC EDGAR corporate filing test system, exfiltrating non-public quarterly earnings reports for hundreds of publicly traded companies before their official release to generate $4.1 million in illegal insider trades.",
    "case_number": "2:19-cr-00040",
    "court": "U.S. District Court for the District of New Jersey",
    "district": "D.N.J.",
    "country": "United States",
    "opened_at": "2019-01-15",
    "status": "fugitive",
    "victim_sector": "Regulatory Agencies, Securities Markets, Public Corporations",
    "victim_country": "United States",
    "loss_amount_usd": 4100000,
    "loss_amount_note": "Generated $4.1 million in illegal trading profits using stolen corporate filings.",
    "first_seen_at": "2016-05-01T00:00:00Z",
    "last_updated_at": "2026-07-05T11:00:00Z",
    "actor_slug": "edgar-hack-syndicate",
    "defendant_slugs": [
      "artem-radchenko"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1190",
        "evidence_excerpt": "Radchenko exploited a software vulnerability in the SEC EDGAR test server software to extract unpublished draft 8-K and 10-Q reports.",
        "evidence_locator": "Indictment \u00b6 14, Page 8",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Radchenko",
        "source_url": "https://www.justice.gov/opa/pr/two-ukrainian-nationals-indicted-computer-hacking-and-securities-fraud-scheme",
        "technique_name": "Exploit Public-Facing Application",
        "tactic": "Initial Access"
      }
    ],
    "events": [
      {
        "event_type": "indictment",
        "event_date": "2019-01-15",
        "description": "Grand jury in Newark, New Jersey, indicts Radchenko and Oleksandr Ieremenko for computer fraud and wire fraud."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Adversary breached the target network via Exploit Public-Facing Application. Radchenko exploited a software vulnerability in the SEC EDGAR test server software to extract unpublished draft 8-K and 10-Q reports.",
      "blast_radius": "Generated $4.1 million in illegal trading profits using stolen corporate filings. Impacted Regulatory Agencies, Securities Markets, Public Corporations infrastructure and associated victim operations.",
      "kill_chain": [
        {
          "phase": "Phase 1: Initial Access",
          "title": "Initial Perimeter Infiltration",
          "description": "Radchenko exploited a software vulnerability in the SEC EDGAR test server software to extract unpublished draft 8-K and 10-Q reports.",
          "technical_artifacts": [
            "T1190",
            "Exploit Public-Facing Application"
          ],
          "mitre_technique_id": "T1190"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
        "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
        "Maintain isolated, immutable backups of critical directory services and transaction databases.",
        "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
      ]
    }
  },
  {
    "id": "case-daniel-rhyne-ransomware",
    "slug": "us-v-rhyne-insider-ransomware-extortion",
    "title": "U.S. v. Daniel Rhyne (Industrial Insider Extortion)",
    "summary": "Core infrastructure systems engineer who staged an extortion scheme against his own industrial employer, locking coworkers out of Active Directory domain controllers, changing administrator passwords, and demanding $750,000 in cryptocurrency.",
    "case_number": "3:24-cr-00122",
    "court": "U.S. District Court for the Western District of Missouri",
    "district": "W.D. Mo.",
    "country": "United States",
    "opened_at": "2024-04-16",
    "status": "charged",
    "victim_sector": "Industrial Manufacturing, Critical Infrastructure",
    "victim_country": "United States",
    "loss_amount_usd": 750000,
    "loss_amount_note": "Demanded $750,000 ransom and caused significant corporate operational stoppage.",
    "first_seen_at": "2023-11-20T00:00:00Z",
    "last_updated_at": "2026-07-01T15:00:00Z",
    "actor_slug": "insider-threat",
    "defendant_slugs": [
      "daniel-rhyne"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1078",
        "evidence_excerpt": "Rhyne accessed domain controllers using an unauthorized administrative service account that he covertly provisioned weeks earlier.",
        "evidence_locator": "Criminal Complaint \u00b6 9, Page 4",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Complaint: U.S. v. Rhyne",
        "source_url": "https://www.justice.gov/usao-wdmo/pr/former-systems-administrator-charged-extortion-and-intentionally-damaging-protected",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2024-04-18",
        "description": "Rhyne arrested in Kansas City by FBI agents."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Industrial Manufacturing, Critical Infrastructure networks. Core infrastructure systems engineer who staged an extortion scheme against his own industrial employer, locking coworkers out of Active Directory domain controllers, changing administrator passwords, and demanding $750,000 in cryptocurrency.",
      "blast_radius": "Demanded $750,000 ransom and caused significant corporate operational stoppage. Impacted Industrial Manufacturing, Critical Infrastructure infrastructure and associated victim operations.",
      "kill_chain": [
        {
          "phase": "Phase 1: Defense Evasion",
          "title": "Defense Evasion & Security Blindfolding",
          "description": "Rhyne accessed domain controllers using an unauthorized administrative service account that he covertly provisioned weeks earlier.",
          "technical_artifacts": [
            "T1078",
            "Valid Accounts"
          ],
          "mitre_technique_id": "T1078"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
        "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
        "Maintain isolated, immutable backups of critical directory services and transaction databases.",
        "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
      ]
    }
  },
  {
    "id": "case-snowflake-credential-stuffing",
    "slug": "snowflake-multi-tenant-credential-attacks",
    "title": "Snowflake Customer Multi-Tenant Credential Stuffing Campaign",
    "summary": "Coordinated cybercrime campaign targeting over 165 corporate customer tenants of cloud database provider Snowflake using credentials harvested by infostealer malware, exfiltrating billions of consumer records from Ticketmaster, Santander, and AT&T.",
    "case_number": "SEC CIK 0001640147",
    "court": "U.S. District Court for the Northern District of California",
    "district": "N.D. Cal.",
    "country": "United States",
    "opened_at": "2024-05-31",
    "status": "alleged",
    "victim_sector": "Telecommunications, Entertainment, Banking, Cloud Services",
    "victim_country": "United States, Spain, Worldwide",
    "loss_amount_usd": 150000000,
    "loss_amount_note": "Stole records of 110 million AT&T phone accounts and 560 million Ticketmaster users, leading to extensive class-action lawsuits and regulatory filings.",
    "first_seen_at": "2024-04-14T00:00:00Z",
    "last_updated_at": "2026-06-25T14:00:00Z",
    "actor_slug": "unc5537",
    "defendant_slugs": [],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1078",
        "evidence_excerpt": "Threat actors authenticated to victim Snowflake tenants using valid usernames and passwords that had been stolen by info-stealers (Lumma, RedLine) months earlier.",
        "evidence_locator": "Mandiant Joint Advisory \u00b6 2",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Mandiant & Snowflake Joint Security Bulletin",
        "source_url": "https://cloud.google.com/blog/topics/threat-intelligence/unc5537-snowflake-data-theft-extortion",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1041",
        "evidence_excerpt": "Adversaries executed native SQL commands in Snowflake command-line clients (snowsql) to stage and export customer database tables.",
        "evidence_locator": "CISA Advisory Alert",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Alert",
        "source_url": "https://www.cisa.gov/news-events/alerts",
        "technique_name": "Exfiltration Over C2 Channel",
        "tactic": "Exfiltration"
      }
    ],
    "events": [
      {
        "event_type": "advisory",
        "event_date": "2024-06-05",
        "description": "CISA issues alert warning organizations with Snowflake tenants to enforce multi-factor authentication and review network allowlists."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Telecommunications, Entertainment, Banking, Cloud Services networks. Coordinated cybercrime campaign targeting over 165 corporate customer tenants of cloud database provider Snowflake using credentials harvested by infostealer malware, exfiltrating billions of consumer records from Ticketmaster, Santander, and AT&T.",
      "blast_radius": "Stole records of 110 million AT&T phone accounts and 560 million Ticketmaster users, leading to extensive class-action lawsuits and regulatory filings. Impacted Telecommunications, Entertainment, Banking, Cloud Services infrastructure and associated victim operations.",
      "kill_chain": [
        {
          "phase": "Phase 1: Defense Evasion",
          "title": "Defense Evasion & Security Blindfolding",
          "description": "Threat actors authenticated to victim Snowflake tenants using valid usernames and passwords that had been stolen by info-stealers (Lumma, RedLine) months earlier.",
          "technical_artifacts": [
            "T1078",
            "Valid Accounts"
          ],
          "mitre_technique_id": "T1078"
        },
        {
          "phase": "Phase 2: Exfiltration",
          "title": "Encrypted Cloud Data Exfiltration",
          "description": "Adversaries executed native SQL commands in Snowflake command-line clients (snowsql) to stage and export customer database tables.",
          "technical_artifacts": [
            "T1041",
            "Exfiltration Over C2 Channel"
          ],
          "mitre_technique_id": "T1041"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
        "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
        "Maintain isolated, immutable backups of critical directory services and transaction databases.",
        "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
      ]
    }
  },
  {
    "id": "case-james-zhong-silkroad-theft",
    "slug": "us-v-zhong-silk-road-bitcoin-seizure",
    "title": "U.S. v. James Zhong (Silk Road 50,000 Bitcoin Theft)",
    "summary": "Historic seizure of over 50,676 Bitcoins ($3.36 billion at seizure) hidden in an underground floor safe and popcorn tin, stolen by James Zhong from the Silk Road darknet market in 2012 by triggering race conditions in the withdrawal logic.",
    "case_number": "1:22-cr-00594",
    "court": "U.S. District Court for the Southern District of New York",
    "district": "S.D.N.Y.",
    "country": "United States",
    "opened_at": "2022-11-04",
    "status": "sentenced",
    "victim_sector": "Cryptocurrency, Darknet Markets",
    "victim_country": "United States",
    "loss_amount_usd": 3360000000,
    "loss_amount_note": "Largest cryptocurrency seizure in DOJ history at the time: 50,676 Bitcoins valued at $3.36 billion.",
    "first_seen_at": "2012-09-01T00:00:00Z",
    "last_updated_at": "2026-06-20T10:00:00Z",
    "actor_slug": "zhong-silkroad",
    "defendant_slugs": [
      "james-zhong"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1190",
        "evidence_excerpt": "Zhong registered accounts and rapidly executed simultaneous withdrawal requests within fractions of a second, causing the automated withdrawal daemon to pay out double balances.",
        "evidence_locator": "Information \u00b6 8, Page 4",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Information: U.S. v. Zhong",
        "source_url": "https://www.justice.gov/usao-sdny/pr/us-attorney-announces-historic-336-billion-cryptocurrency-seizure-and-conviction-connection",
        "technique_name": "Exploit Public-Facing Application",
        "tactic": "Initial Access"
      }
    ],
    "events": [
      {
        "event_type": "court_order",
        "event_date": "2021-11-09",
        "description": "IRS Criminal Investigation and federal agents execute search warrant at Zhong's Gainesville residence, seizing 50,491 Bitcoins."
      },
      {
        "event_type": "plea",
        "event_date": "2022-11-04",
        "description": "Zhong pleads guilty to wire fraud in Manhattan federal court."
      },
      {
        "event_type": "sentencing",
        "event_date": "2023-04-14",
        "description": "Sentenced to 12 months and one day in prison."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Adversary breached the target network via Exploit Public-Facing Application. Zhong registered accounts and rapidly executed simultaneous withdrawal requests within fractions of a second, causing the automated withdrawal daemon to pay out double balances.",
      "blast_radius": "Largest cryptocurrency seizure in DOJ history at the time: 50,676 Bitcoins valued at $3.36 billion. Impacted Cryptocurrency, Darknet Markets infrastructure and associated victim operations.",
      "kill_chain": [
        {
          "phase": "Phase 1: Initial Access",
          "title": "Initial Perimeter Infiltration",
          "description": "Zhong registered accounts and rapidly executed simultaneous withdrawal requests within fractions of a second, causing the automated withdrawal daemon to pay out double balances.",
          "technical_artifacts": [
            "T1190",
            "Exploit Public-Facing Application"
          ],
          "mitre_technique_id": "T1190"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
        "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
        "Maintain isolated, immutable backups of critical directory services and transaction databases.",
        "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
      ]
    }
  },
  {
    "id": "case-lichtenstein-bitfinex",
    "slug": "us-v-lichtenstein-bitfinex-heist-laundering",
    "title": "U.S. v. Ilya Lichtenstein & Heather Morgan (Bitfinex Hack & Laundering)",
    "summary": "Conviction of Ilya Lichtenstein and Heather Morgan for executing the 2016 hack of the Bitfinex virtual currency exchange, stealing 119,754 Bitcoins (valued at $4.5 billion at arrest), and laundering the funds through complex cryptocurrency mixers and darknet markets.",
    "case_number": "1:23-cr-00239",
    "court": "U.S. District Court for the District of Columbia",
    "district": "D.D.C.",
    "country": "United States",
    "opened_at": "2022-02-07",
    "status": "sentenced",
    "victim_sector": "Cryptocurrency Exchanges, Financial Services",
    "victim_country": "United States, Hong Kong",
    "loss_amount_usd": 4500000000,
    "loss_amount_note": "Stole 119,754 Bitcoins from Bitfinex; DOJ recovered 94,000 Bitcoins valued at $3.6 billion in the largest single financial seizure in U.S. history.",
    "first_seen_at": "2016-08-02T00:00:00Z",
    "last_updated_at": "2026-06-15T16:00:00Z",
    "actor_slug": "bitfinex-heist",
    "defendant_slugs": [
      "ilya-lichtenstein",
      "heather-morgan"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1078",
        "evidence_excerpt": "Lichtenstein gained access to Bitfinex's internal systems and authorized over 2,000 fraudulent cryptocurrency withdrawal transactions to private wallets.",
        "evidence_locator": "Statement of Offense \u00b6 6, Page 3",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Statement of Offense: U.S. v. Lichtenstein",
        "source_url": "https://www.justice.gov/opa/pr/two-individuals-plead-guilty-money-laundering-conspiracies-connection-bitfinex-hack",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2022-02-08",
        "description": "Lichtenstein and Morgan arrested in Manhattan by federal agents with recovery of 94,000 Bitcoins."
      },
      {
        "event_type": "plea",
        "event_date": "2023-08-03",
        "description": "Defendants plead guilty to conspiracy to commit money laundering in D.D.C."
      },
      {
        "event_type": "sentencing",
        "event_date": "2024-11-14",
        "description": "Lichtenstein sentenced to 60 months (5 years) in federal prison; Morgan sentenced to 18 months."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Cryptocurrency Exchanges, Financial Services networks. Conviction of Ilya Lichtenstein and Heather Morgan for executing the 2016 hack of the Bitfinex virtual currency exchange, stealing 119,754 Bitcoins (valued at $4.5 billion at arrest), and laundering the funds through complex cryptocurrency mixers and darknet markets.",
      "blast_radius": "Stole 119,754 Bitcoins from Bitfinex; DOJ recovered 94,000 Bitcoins valued at $3.6 billion in the largest single financial seizure in U.S. history. Impacted Cryptocurrency Exchanges, Financial Services infrastructure and associated victim operations.",
      "kill_chain": [
        {
          "phase": "Phase 1: Defense Evasion",
          "title": "Defense Evasion & Security Blindfolding",
          "description": "Lichtenstein gained access to Bitfinex's internal systems and authorized over 2,000 fraudulent cryptocurrency withdrawal transactions to private wallets.",
          "technical_artifacts": [
            "T1078",
            "Valid Accounts"
          ],
          "mitre_technique_id": "T1078"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
        "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
        "Maintain isolated, immutable backups of critical directory services and transaction databases.",
        "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
      ]
    }
  },
  {
    "id": "case-ross-ulbricht-silkroad",
    "slug": "us-v-ross-ulbricht-silk-road",
    "title": "U.S. v. Ross Ulbricht (Dread Pirate Roberts / Silk Road)",
    "summary": "Historic trial and life sentencing of Ross William Ulbricht, creator and operator of Silk Road, the internet's first comprehensive darknet market using Tor and Bitcoin.",
    "case_number": "1:14-cr-00068",
    "court": "U.S. District Court for the Southern District of New York",
    "district": "S.D.N.Y.",
    "country": "United States",
    "opened_at": "2014-02-04",
    "status": "sentenced",
    "victim_sector": "Public Safety, E-Commerce, Controlled Substances",
    "victim_country": "United States, Worldwide",
    "loss_amount_usd": 213000000,
    "loss_amount_note": "Generated $213 million in total sales and $13 million in commissions across 1.5 million transactions.",
    "first_seen_at": "2011-01-01T00:00:00Z",
    "last_updated_at": "2026-06-10T12:00:00Z",
    "actor_slug": "silk-road",
    "defendant_slugs": [
      "ross-ulbricht"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1090",
        "evidence_excerpt": "Ulbricht built Silk Road as a hidden service on the Tor network to conceal server IP addresses and protect buyer and seller anonymity.",
        "evidence_locator": "Indictment \u00b6 8, Page 4",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Ulbricht",
        "source_url": "https://www.justice.gov/usao-sdny/pr/ross-ulbricht-creator-and-operator-silk-road-website-sentenced-manhattan-federal-court",
        "technique_name": "Proxy",
        "tactic": "Command and Control"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2013-10-01",
        "description": "Ulbricht arrested in the Glen Park branch of the San Francisco Public Library by FBI agents while logged into the Silk Road admin panel."
      },
      {
        "event_type": "verdict",
        "event_date": "2015-02-04",
        "description": "Jury finds Ulbricht guilty on all seven felony counts including narcotics conspiracy and computer hacking."
      },
      {
        "event_type": "sentencing",
        "event_date": "2015-05-29",
        "description": "Sentenced to two life terms of imprisonment plus 40 years without parole and ordered to forfeit $183 million."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Public Safety, E-Commerce, Controlled Substances networks. Historic trial and life sentencing of Ross William Ulbricht, creator and operator of Silk Road, the internet's first comprehensive darknet market using Tor and Bitcoin.",
      "blast_radius": "Generated $213 million in total sales and $13 million in commissions across 1.5 million transactions. Impacted Public Safety, E-Commerce, Controlled Substances infrastructure and associated victim operations.",
      "kill_chain": [
        {
          "phase": "Phase 1: Infiltration",
          "title": "Perimeter Ingress",
          "description": "Operatives secured access to victim infrastructure within the Public Safety, E-Commerce, Controlled Substances sector.",
          "technical_artifacts": [
            "Network perimeter logs"
          ],
          "mitre_technique_id": "T1190"
        },
        {
          "phase": "Phase 2: Execution",
          "title": "Payload Deployment",
          "description": "Historic trial and life sentencing of Ross William Ulbricht, creator and operator of Silk Road, the internet's first comprehensive darknet market using Tor and Bitcoin.",
          "technical_artifacts": [
            "Malicious payload"
          ],
          "mitre_technique_id": "T1486"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
        "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
        "Maintain isolated, immutable backups of critical directory services and transaction databases.",
        "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
      ]
    }
  },
  {
    "id": "case-dmitry-badin-bundestag",
    "slug": "us-v-badin-german-bundestag-apt28",
    "title": "U.S. & International Action: Dmitry Badin (German Bundestag Hack)",
    "summary": "Russian GRU military officer charged with the 2015 cyber intrusion into the German Federal Parliament (Bundestag), which compromised parliamentary IT infrastructure and exfiltrated thousands of emails from Chancellor Angela Merkel's office.",
    "case_number": "German Federal Prosecutor Warrant / U.S. D.D.C. 1:18-cr-00215",
    "court": "Federal Court of Justice (Germany) & U.S. District Court for the District of Columbia",
    "district": "D.D.C. & BGH Karlsruhe",
    "country": "Germany & United States",
    "opened_at": "2020-05-05",
    "status": "fugitive",
    "victim_sector": "Legislative Bodies, National Government",
    "victim_country": "Germany",
    "loss_amount_usd": 15000000,
    "loss_amount_note": "Forced the total decommissioning and complete rebuild of the Bundestag computer network.",
    "first_seen_at": "2015-04-30T00:00:00Z",
    "last_updated_at": "2026-06-05T14:00:00Z",
    "actor_slug": "apt28",
    "defendant_slugs": [
      "dmitriy-badin"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1566.001",
        "evidence_excerpt": "Attackers sent spearphishing emails with malicious attachments disguised as United Nations newsletters to German members of parliament.",
        "evidence_locator": "BKA Investigation Summary",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "EU Sanctions Notice",
        "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32020D1537",
        "technique_name": "Spearphishing Attachment",
        "tactic": "Initial Access"
      }
    ],
    "events": [
      {
        "event_type": "sanction",
        "event_date": "2020-10-22",
        "description": "European Union imposes sanctions against Dmitry Badin and GRU Unit 26165."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Adversary breached the target network via Spearphishing Attachment. Attackers sent spearphishing emails with malicious attachments disguised as United Nations newsletters to German members of parliament.",
      "blast_radius": "Forced the total decommissioning and complete rebuild of the Bundestag computer network. Impacted Legislative Bodies, National Government infrastructure and associated victim operations.",
      "kill_chain": [
        {
          "phase": "Phase 1: Initial Access",
          "title": "Initial Perimeter Infiltration",
          "description": "Attackers sent spearphishing emails with malicious attachments disguised as United Nations newsletters to German members of parliament.",
          "technical_artifacts": [
            "T1566.001",
            "Spearphishing Attachment"
          ],
          "mitre_technique_id": "T1566.001"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
        "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
        "Maintain isolated, immutable backups of critical directory services and transaction databases.",
        "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
      ]
    }
  },
  {
    "id": "case-sikerin-polyanin-revil",
    "slug": "us-v-sikerin-polyanin-revil-affiliates",
    "title": "U.S. v. Aleksandr Sikerin & Yevgeniy Polyanin (REvil Operations)",
    "summary": "International enforcement action against REvil ransomware money exchangers and operators, recovering $6.1 million in ransomware proceeds extorted from businesses and local governments across the United States.",
    "case_number": "3:21-cr-00315",
    "court": "U.S. District Court for the Northern District of Texas",
    "district": "N.D. Tex.",
    "country": "United States",
    "opened_at": "2021-11-08",
    "status": "fugitive",
    "victim_sector": "Local Government, Healthcare, Manufacturing",
    "victim_country": "United States",
    "loss_amount_usd": 13000000,
    "loss_amount_note": "Extorted $13 million; federal seizure warrants recovered $6.1 million from crypto deposit wallets.",
    "first_seen_at": "2019-08-01T00:00:00Z",
    "last_updated_at": "2026-05-30T11:00:00Z",
    "actor_slug": "revil-sodinokibi",
    "defendant_slugs": [
      "yevgeniy-polyanin"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1486",
        "evidence_excerpt": "Polyanin deployed Sodinokibi/REvil ransomware against dozens of municipal government agencies across Texas, encrypting servers and demanding ransoms in Monero.",
        "evidence_locator": "Indictment \u00b6 14, Page 7",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Polyanin",
        "source_url": "https://www.justice.gov/opa/pr/justice-department-announces-first-extradition-revil-ransomware-attacks-seizure-61-million",
        "technique_name": "Data Encrypted for Impact",
        "tactic": "Impact"
      }
    ],
    "events": [
      {
        "event_type": "indictment",
        "event_date": "2021-11-08",
        "description": "DOJ unseals indictment against Polyanin and announces recovery of $6.1 million in extorted funds."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Local Government, Healthcare, Manufacturing networks. International enforcement action against REvil ransomware money exchangers and operators, recovering $6.1 million in ransomware proceeds extorted from businesses and local governments across the United States.",
      "blast_radius": "Extorted $13 million; federal seizure warrants recovered $6.1 million from crypto deposit wallets. Impacted Local Government, Healthcare, Manufacturing infrastructure and associated victim operations.",
      "kill_chain": [
        {
          "phase": "Phase 1: Impact",
          "title": "Operational Disruption or Extortion Detonation",
          "description": "Polyanin deployed Sodinokibi/REvil ransomware against dozens of municipal government agencies across Texas, encrypting servers and demanding ransoms in Monero.",
          "technical_artifacts": [
            "T1486",
            "Data Encrypted for Impact"
          ],
          "mitre_technique_id": "T1486"
        }
      ],
      "defensive_takeaways": [
        "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
        "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
        "Maintain isolated, immutable backups of critical directory services and transaction databases.",
        "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
      ]
    }
  },
  {
    "id": "case-wu-equifax-pla",
    "slug": "us-v-wu-equifax-pla",
    "title": "U.S. v. Wu et al. (Equifax PLA Unit 54th Research Institute)",
    "summary": "Four military officers with the Chinese People's Liberation Army (PLA) 54th Research Institute charged with hacking into Equifax networks, stealing trade secrets, and exfiltrating personally identifiable information (PII) of roughly 147 million American citizens.",
    "case_number": "1:20-cr-00071",
    "court": "U.S. District Court for the Northern District of Georgia",
    "district": "N.D. Ga.",
    "country": "United States",
    "opened_at": "2020-01-28",
    "status": "fugitive",
    "victim_sector": "Financial Services, Consumer Credit",
    "victim_country": "United States",
    "loss_amount_usd": 1400000000,
    "loss_amount_note": "Equifax incurred over $1.4 billion in remediation, technological overhauls, and federal class action settlement expenditures.",
    "first_seen_at": "2017-05-13T00:00:00Z",
    "last_updated_at": "2026-09-15T12:00:00Z",
    "actor_slug": "pla-unit-54th",
    "defendant_slugs": [
      "wu-zhiyong",
      "wang-qian",
      "xu-ke",
      "liu-lei"
    ],
    "cves": [
      "CVE-2017-5638"
    ],
    "techniques": [
      {
        "technique_id": "T1190",
        "evidence_excerpt": "The conspirators exploited a known vulnerability in the Apache Struts Web Framework (CVE-2017-5638) on Equifax's online dispute portal to obtain initial remote shell execution.",
        "evidence_locator": "Indictment \u00b6 14, Page 6",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Wu et al.",
        "source_url": "https://www.justice.gov/opa/pr/chinese-military-personnel-charged-computer-fraud-economic-espionage-and-wire-fraud-hacked",
        "technique_name": "Exploit Public-Facing Application",
        "tactic": "Initial Access"
      },
      {
        "technique_id": "T1070",
        "evidence_excerpt": "Defendants routinely deleted temporary files and log entries, routed communications through encrypted tunnels, and ran roughly 9,000 queries to mask their database reconnaissance.",
        "evidence_locator": "Indictment \u00b6 22, Page 11",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Wu et al.",
        "source_url": "https://www.justice.gov/opa/pr/chinese-military-personnel-charged-computer-fraud-economic-espionage-and-wire-fraud-hacked",
        "technique_name": "Indicator Removal",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1567",
        "evidence_excerpt": "Operatives packaged stolen records containing names, Social Security numbers, and birth dates into compressed archives and exfiltrated them to overseas staging servers.",
        "evidence_locator": "Indictment \u00b6 26, Page 13",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment",
        "source_url": "https://www.justice.gov/opa/pr/chinese-military-personnel-charged-computer-fraud-economic-espionage-and-wire-fraud-hacked",
        "technique_name": "Exfiltration Over Web Service",
        "tactic": "Exfiltration"
      }
    ],
    "events": [
      {
        "event_type": "indictment",
        "event_date": "2020-01-28",
        "description": "Federal grand jury returns nine-count indictment against four Chinese PLA military intelligence hackers."
      },
      {
        "event_type": "advisory",
        "event_date": "2020-02-10",
        "description": "Attorney General William Barr publicly announces the unsealing of charges against members of the 54th Research Institute."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Remote code execution via an unpatched Apache Struts vulnerability (CVE-2017-5638) on Equifax's public online dispute portal, which remained vulnerable for 66 days despite the release of a security patch.",
      "blast_radius": "Compromised the sensitive personally identifiable information (PII) of approximately 147 million Americans, including names, Social Security numbers, dates of birth, and driver's license numbers. Equifax spent over $1.4 billion on remediation, infrastructure overhauls, and federal class-action settlements.",
      "kill_chain": [
        {
          "phase": "Initial Exploitation",
          "title": "Apache Struts Web Server RCE",
          "description": "Chinese PLA military intelligence hackers exploited CVE-2017-5638 by sending malicious HTTP requests with crafted Content-Type headers, executing commands with web server privileges.",
          "technical_artifacts": [
            "CVE-2017-5638",
            "Apache Struts OGNL expression payload",
            "China Chopper webshell"
          ],
          "mitre_technique_id": "T1190"
        },
        {
          "phase": "Internal Reconnaissance & Queries",
          "title": "Database Schema and Credentials Enumeration",
          "description": "Operatives ran approximately 9,000 internal database queries to locate consumer credit data, extracting unencrypted credentials stored in plaintext configuration files.",
          "technical_artifacts": [
            "Plaintext database credentials",
            "Automated SQL reconnaissance scripts"
          ],
          "mitre_technique_id": "T1083"
        },
        {
          "phase": "Defense Evasion",
          "title": "Log Purging and Encrypted Tunneling",
          "description": "Defendants established encrypted communications through proxy servers in Germany and Switzerland and systematically purged server access logs daily to conceal their presence.",
          "technical_artifacts": [
            "SSH encrypted tunnels",
            "log wipe commands"
          ],
          "mitre_technique_id": "T1070"
        },
        {
          "phase": "Exfiltration",
          "title": "Segmented Archive Cloud Exfiltration",
          "description": "Stolen records were split into compressed archives and exfiltrated to overseas staging servers over 76 separate intrusion days.",
          "technical_artifacts": [
            "tar.gz archives",
            "Segmented file downloads"
          ],
          "mitre_technique_id": "T1567"
        }
      ],
      "defensive_takeaways": [
        "Maintain an authoritative software asset inventory to identify and patch vulnerable software components within 48 hours of public CVE disclosure.",
        "Deploy Web Application Firewalls (WAF) with inspection rules for malicious HTTP headers and OGNL injection attacks.",
        "Encrypt sensitive database fields at rest and prohibit plaintext credentials in application config files.",
        "Inspect outbound SSL/TLS traffic with network decryption to detect unauthorized bulk data exfiltration."
      ]
    }
  },
  {
    "id": "case-target-hvac-breach",
    "slug": "target-corporation-hvac-breach",
    "title": "Target Corporation Point-of-Sale Data Breach (Fazio Mechanical Ingress)",
    "summary": "Landmark retail cyberattack where attackers penetrated Target internal corporate networks using stolen billing portal credentials from a third-party refrigeration and HVAC vendor, subsequently deploying BlackPOS memory scraping malware to steal 40 million credit card numbers and 70 million customer records.",
    "case_number": "0:14-md-02522",
    "court": "U.S. District Court for the District of Minnesota",
    "district": "D. Minn.",
    "country": "United States",
    "opened_at": "2014-04-02",
    "status": "settled",
    "victim_sector": "Retail, Financial Services",
    "victim_country": "United States",
    "loss_amount_usd": 292000000,
    "loss_amount_note": "Target reported $292 million in cumulative gross expenses from the breach, offset by $90 million in insurance recoveries.",
    "first_seen_at": "2013-11-27T00:00:00Z",
    "last_updated_at": "2026-08-10T14:00:00Z",
    "actor_slug": "resator-blackpos",
    "defendant_slugs": [],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1078",
        "evidence_excerpt": "Attackers gained initial network entry using legitimate credentials stolen via a spearphishing email directed at Fazio Mechanical Services, an external HVAC contractor.",
        "evidence_locator": "Senate Commerce Committee Forensic Report, Page 12",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Senate Commerce Committee Report on Target Breach",
        "source_url": "https://www.commerce.senate.gov",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1056.001",
        "evidence_excerpt": "Operatives deployed a customized variant of BlackPOS (Kaptoxa) malware across thousands of cash register POS terminals to scrape payment card magnetic stripe tracks from process memory.",
        "evidence_locator": "US-CERT Advisory TA14-002A",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory TA14-002A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/ta14-002a",
        "technique_name": "Keylogging",
        "tactic": "Credential Access"
      },
      {
        "technique_id": "T1041",
        "evidence_excerpt": "Track 1 and Track 2 payment card data harvested from memory was temporarily staged on internal compromised servers before being batched and exfiltrated to compromised FTP servers in Russia and Brazil.",
        "evidence_locator": "Forensic Investigation Report, Section 4.2",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Target Special Litigation Committee Report",
        "source_url": "https://www.sec.gov",
        "technique_name": "Exfiltration Over C2 Channel",
        "tactic": "Exfiltration"
      }
    ],
    "events": [
      {
        "event_type": "incident",
        "event_date": "2013-11-27",
        "description": "BlackPOS memory scraping malware begins collecting customer payment card data across Target cash registers."
      },
      {
        "event_type": "disclosure",
        "event_date": "2013-12-19",
        "description": "Target officially confirms unauthorized access to payment card data affecting approximately 40 million customer accounts."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Stolen electronic vendor credentials from Fazio Mechanical Services, a small heating and air conditioning (HVAC) contractor in Pennsylvania, compromised via a phishing email harboring Citadel malware.",
      "blast_radius": "Approximately 40 million credit and debit card records and 70 million customer personal records compromised. Target incurred $292 million in total gross breach expenses, executive resignations (CEO and CIO), and paid an $18.5 million multistate settlement.",
      "kill_chain": [
        {
          "phase": "Third-Party Vendor Ingress",
          "title": "Compromised Contractor Billing Credentials",
          "description": "Attackers infected an HVAC subcontractor with Citadel malware to harvest legitimate login credentials for Target vendor portal, which lacked multifactor authentication.",
          "technical_artifacts": [
            "Citadel banking trojan",
            "Vendor billing portal login"
          ],
          "mitre_technique_id": "T1078"
        },
        {
          "phase": "Internal Lateral Traversal",
          "title": "Active Directory and Subnet Infiltration",
          "description": "Because the vendor portal was connected to Target's broader corporate network without microsegmentation, attackers traversed internal subnets to reach point-of-sale management servers.",
          "technical_artifacts": [
            "PsExec utility",
            "Internal administrative shares"
          ],
          "mitre_technique_id": "T1021.002"
        },
        {
          "phase": "Payload Deployment",
          "title": "BlackPOS Memory Scraper Rollout",
          "description": "Operatives deployed a customized version of BlackPOS (Kaptoxa) malware across thousands of cash register POS terminals during the Black Friday holiday shopping surge.",
          "technical_artifacts": [
            "BlackPOS / Kaptoxa executable",
            "POS-RAM scraper"
          ],
          "mitre_technique_id": "T1056.001"
        },
        {
          "phase": "Data Staging & Exfiltration",
          "title": "Internal FTP Staging and Multi-Hop Exfiltration",
          "description": "Scraped Track 1 and Track 2 magnetic stripe data was saved to internal staging servers and periodically pushed to external compromised FTP servers in Russia and Brazil.",
          "technical_artifacts": [
            "Internal FTP staging server",
            "Encrypted batch exfiltration"
          ],
          "mitre_technique_id": "T1041"
        }
      ],
      "defensive_takeaways": [
        "Strictly segregate third-party vendor portals from internal production and payment card processing networks.",
        "Deploy Point-to-Point Encryption (P2PE) on all cash register terminals so card data is never decrypted in system memory.",
        "Enforce multifactor authentication for 100% of vendor and supply chain access gateways.",
        "Configure real-time monitoring and alerting for unauthorized lateral connections into POS subnets."
      ]
    }
  },
  {
    "id": "case-mgm-scattered-spider",
    "slug": "mgm-resorts-scattered-spider",
    "title": "MGM Resorts Cyberattack (Scattered Spider / ALPHV Vishing Ingress)",
    "summary": "Sophisticated social engineering and ransomware attack carried out by cybercrime collective Scattered Spider partnering with ALPHV/BlackCat, utilizing a 10-minute phone call to the Okta IT helpdesk to bypass MFA, hijack administrative privileges, and paralyze hotel reservations, digital keys, and casino slot machines.",
    "case_number": "2:23-cv-01584",
    "court": "U.S. District Court for the District of Nevada",
    "district": "D. Nev.",
    "country": "United States",
    "opened_at": "2023-10-05",
    "status": "alleged",
    "victim_sector": "Hospitality, Gaming, Entertainment",
    "victim_country": "United States",
    "loss_amount_usd": 100000000,
    "loss_amount_note": "MGM Resorts disclosed a negative adjusted EBITDAR impact of roughly $100 million in its SEC Form 8-K filing.",
    "first_seen_at": "2023-09-08T00:00:00Z",
    "last_updated_at": "2026-09-18T10:00:00Z",
    "actor_slug": "scattered-spider",
    "defendant_slugs": [],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1566.004",
        "evidence_excerpt": "Operatives conducted targeted voice phishing (vishing) calls to the internal IT helpdesk, impersonating an MGM employee identified on LinkedIn to successfully request a password reset and MFA credential registration.",
        "evidence_locator": "CISA & FBI Joint Advisory AA23-320A",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA23-320A: Scattered Spider",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a"
      },
      {
        "technique_id": "T1078",
        "evidence_excerpt": "After securing initial access, attackers elevated their privileges into Okta Identity Cloud and Microsoft Azure tenants, establishing super administrator roles to persist across the enterprise.",
        "evidence_locator": "CISA Advisory AA23-320A, Page 4",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA23-320A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1486",
        "evidence_excerpt": "Upon encountering administrative containment attempts by defenders, the threat actors deployed ALPHV/BlackCat ransomware binaries across ESXi virtual machines, shutting down hotel check-in and gaming operations.",
        "evidence_locator": "MGM SEC Form 8-K Filing",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "SEC Form 8-K Disclosure: MGM Resorts",
        "source_url": "https://www.sec.gov",
        "technique_name": "Data Encrypted for Impact",
        "tactic": "Impact"
      }
    ],
    "events": [
      {
        "event_type": "incident",
        "event_date": "2023-09-10",
        "description": "MGM Resorts discovers unauthorized cybersecurity incident and proactively shuts down guest portals and gaming floors."
      },
      {
        "event_type": "filing",
        "event_date": "2023-10-12",
        "description": "MGM Resorts files Form 8-K disclosure detailing $100 million operating income impact and $10 million in one-off technology expenses."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "A 10-minute social engineering voice phishing (vishing) call to the Okta IT helpdesk impersonating an employee found on LinkedIn, convincing technicians to reset their MFA credentials.",
      "blast_radius": "Paralyzed MGM Resorts operations for 10 days, shutting down digital hotel room keys, casino slot machines, ATM cash-out terminals, and online reservation systems across the Las Vegas Strip. MGM incurred a $100 million negative operating earnings impact and $10 million in technology costs.",
      "kill_chain": [
        {
          "phase": "Social Engineering Ingress",
          "title": "Helpdesk Vishing and MFA Registration",
          "description": "Scattered Spider operatives called the IT support desk impersonating a corporate employee, successfully convincing the helpdesk technician to enroll an attacker-controlled MFA device.",
          "technical_artifacts": [
            "Voice phishing (vishing)",
            "LinkedIn employee OSINT"
          ],
          "mitre_technique_id": "T1566.004"
        },
        {
          "phase": "Identity Cloud Takeover",
          "title": "Okta Super Admin and Azure AD Elevation",
          "description": "Attackers manipulated identity federation trusts, assigning themselves Global Administrator privileges in Microsoft Azure Active Directory and Super Admin roles in Okta.",
          "technical_artifacts": [
            "Okta Identity Cloud tenant takeover",
            "Azure AD Global Admin"
          ],
          "mitre_technique_id": "T1078"
        },
        {
          "phase": "Virtualization Encryption",
          "title": "ALPHV/BlackCat ESXi Hypervisor Detonation",
          "description": "When defenders initiated containment actions, the threat actors retaliated by deploying ALPHV/BlackCat ransomware across VMware ESXi virtual hypervisors, encrypting hundreds of virtual machines simultaneously.",
          "technical_artifacts": [
            "ALPHV Linux/ESXi ransomware",
            "VMware vSphere console abuse"
          ],
          "mitre_technique_id": "T1486"
        }
      ],
      "defensive_takeaways": [
        "Implement mandatory out-of-band video or manager verification for all helpdesk MFA and password resets.",
        "Transition to FIDO2 phishing-resistant hardware security keys that cannot be phished over the phone.",
        "Restrict ESXi hypervisor management interfaces to isolated out-of-band management subnets.",
        "Enable conditional access rules that detect anomalous location and device changes on administrative accounts."
      ]
    }
  },
  {
    "id": "case-thompson-capital-one",
    "slug": "us-v-thompson-capital-one",
    "title": "U.S. v. Paige Thompson (Capital One AWS Cloud SSRF Breach)",
    "summary": "Former Amazon Web Services systems engineer convicted under the Computer Fraud and Abuse Act for exploiting a misconfigured open-source Web Application Firewall (WAF) using Server-Side Request Forgery (SSRF) to query AWS metadata services and steal over 100 million credit card applications from Capital One.",
    "case_number": "2:19-cr-00159",
    "court": "U.S. District Court for the Western District of Pennsylvania and Western District of Washington",
    "district": "W.D. Wash.",
    "country": "United States",
    "opened_at": "2019-08-28",
    "status": "sentenced",
    "victim_sector": "Financial Services, Cloud Computing",
    "victim_country": "United States",
    "loss_amount_usd": 270000000,
    "loss_amount_note": "Capital One agreed to pay an $80 million regulatory fine to the OCC and a $190 million class-action consumer settlement.",
    "first_seen_at": "2019-03-22T00:00:00Z",
    "last_updated_at": "2026-09-01T15:00:00Z",
    "actor_slug": "paige-thompson-erratic",
    "defendant_slugs": [
      "paige-thompson"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1190",
        "evidence_excerpt": "Thompson executed Server-Side Request Forgery (SSRF) requests against a misconfigured ModSecurity WAF running on an EC2 instance, instructing the server to query the local AWS instance metadata service at 169.254.169.254.",
        "evidence_locator": "Indictment \u00b6 8, Page 3",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Thompson",
        "source_url": "https://www.justice.gov/usao-wdwa/pr/former-seattle-tech-worker-convicted-wire-fraud-and-computer-intrusions",
        "technique_name": "Exploit Public-Facing Application",
        "tactic": "Initial Access"
      },
      {
        "technique_id": "T1078",
        "evidence_excerpt": "The metadata response yielded temporary security credentials for an IAM role named *PRIV_WA_SCAN*, which possessed excessive permissions to enumerate and download files from Capital One Amazon S3 buckets.",
        "evidence_locator": "Trial Exhibit 14, Criminal Complaint \u00b6 12",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Criminal Complaint: U.S. v. Thompson",
        "source_url": "https://www.justice.gov",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1567",
        "evidence_excerpt": "Using multithreaded cloud CLI commands, the defendant downloaded over 700 S3 buckets containing approximately 100 million credit card applications, Social Security numbers, and bank account details.",
        "evidence_locator": "Indictment \u00b6 11, Page 5",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment",
        "source_url": "https://www.justice.gov",
        "technique_name": "Exfiltration Over Web Service",
        "tactic": "Exfiltration"
      }
    ],
    "events": [
      {
        "event_type": "indictment",
        "event_date": "2019-08-28",
        "description": "Federal grand jury indicts Thompson on wire fraud and seven counts of computer intrusion."
      },
      {
        "event_type": "verdict",
        "event_date": "2022-06-17",
        "description": "Jury finds Thompson guilty of wire fraud, unauthorized access to a protected computer, and damaging a protected computer."
      },
      {
        "event_type": "sentencing",
        "event_date": "2022-10-04",
        "description": "Court sentences Thompson to time served and five years of supervised release."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Server-Side Request Forgery (SSRF) flaw in a misconfigured open-source ModSecurity Web Application Firewall (WAF) hosted on an Amazon Web Services EC2 instance.",
      "blast_radius": "Over 100 million credit card applications, 140,000 Social Security numbers, and 80,000 linked bank account numbers exfiltrated from 700 Amazon S3 storage buckets. Capital One paid an $80 million regulatory fine and a $190 million class action settlement.",
      "kill_chain": [
        {
          "phase": "SSRF Exploitation",
          "title": "Metadata Service Credential Theft",
          "description": "Thompson sent crafted HTTP requests to the misconfigured WAF, tricking it into querying the AWS local metadata service (169.254.169.254) and returning temporary security credentials for an IAM role.",
          "technical_artifacts": [
            "SSRF vulnerability",
            "AWS EC2 Instance Metadata Service (IMDSv1)"
          ],
          "mitre_technique_id": "T1190"
        },
        {
          "phase": "Privilege Abuse",
          "title": "Overprivileged IAM Role Enumeration",
          "description": "The stolen IAM role (*PRIV_WA_SCAN*) possessed excessive permissions allowing the attacker to list and read all files across Capital One's Amazon S3 object storage environment.",
          "technical_artifacts": [
            "AWS IAM role: PRIV_WA_SCAN",
            "aws s3 ls commands"
          ],
          "mitre_technique_id": "T1078"
        },
        {
          "phase": "Automated Cloud Exfiltration",
          "title": "Mass S3 Bucket Download and Public Boasting",
          "description": "Using high-speed multithreaded cloud CLI scripts, Thompson downloaded over 700 buckets containing 100M+ customer applications to her personal server, then discussed the breach on Slack and posted scripts to GitHub.",
          "technical_artifacts": [
            "aws s3 sync scripts",
            "GitHub public repository commits"
          ],
          "mitre_technique_id": "T1567"
        }
      ],
      "defensive_takeaways": [
        "Enforce AWS Instance Metadata Service Version 2 (IMDSv2) across all EC2 instances to require session tokens and block SSRF attacks.",
        "Apply principle of least privilege to IAM roles, ensuring WAF instances cannot read customer databases or S3 storage.",
        "Deploy S3 Object Lock and real-time AWS CloudTrail alerts for anomalous bulk S3 GetObject API calls.",
        "Regularly audit cloud configurations against CIS AWS Foundations Benchmarks."
      ]
    }
  },
  {
    "id": "case-clark-twitter-bitcoin",
    "slug": "us-v-clark-twitter-bitcoin",
    "title": "State of Florida v. Graham Ivan Clark (Twitter VIP Bitcoin Hijack)",
    "summary": "17-year-old hacker orchestrated a spearphishing and social engineering scheme targeting Twitter employees, gaining access to internal administrative customer service tools and hijacking 130 high-profile verified accounts (including Joe Biden, Barack Obama, Elon Musk, and Apple) to promote a fraudulent Bitcoin giveaway.",
    "case_number": "20-CF-008922",
    "court": "Hillsborough County 13th Judicial Circuit Court",
    "district": "Hillsborough County",
    "country": "United States",
    "opened_at": "2020-07-31",
    "status": "sentenced",
    "victim_sector": "Social Media, Public Institutions, Financial Services",
    "victim_country": "United States",
    "loss_amount_usd": 117000,
    "loss_amount_note": "Extorted $117,000 in direct Bitcoin transfers in under three hours, causing immense international security concerns and stock volatility.",
    "first_seen_at": "2020-07-15T15:00:00Z",
    "last_updated_at": "2026-08-14T11:00:00Z",
    "actor_slug": "kirk-clark-twitter-conspiracy",
    "defendant_slugs": [
      "graham-ivan-clark"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1566.004",
        "evidence_excerpt": "Clark called Twitter employees on their cellular phones claiming to be from the internal IT department, directing them to enter VPN credentials on a convincing phishing website.",
        "evidence_locator": "Criminal Information \u00b6 4, Page 2",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Florida State Attorney Information",
        "source_url": "https://www.sao13th.com"
      },
      {
        "technique_id": "T1078",
        "evidence_excerpt": "Using stolen employee credentials, Clark logged into Twitter internal customer service management portal ('God Mode'), which allowed direct account recovery email changes and instant password overrides.",
        "evidence_locator": "Twitter Technical Post-Mortem Investigation",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Twitter Official Incident Report",
        "source_url": "https://blog.twitter.com",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      }
    ],
    "events": [
      {
        "event_type": "incident",
        "event_date": "2020-07-15",
        "description": "Attackers hijack 130 verified Twitter accounts and post Bitcoin doubling scam addresses, earning 12.8 BTC."
      },
      {
        "event_type": "arrest",
        "event_date": "2020-07-31",
        "description": "FBI, Secret Service, and Florida Department of Law Enforcement arrest 17-year-old Graham Ivan Clark in Tampa."
      },
      {
        "event_type": "sentencing",
        "event_date": "2021-03-16",
        "description": "Clark pleads guilty as a youthful offender and is sentenced to three years in juvenile prison followed by three years probation."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Targeted phone spearphishing and employee social engineering scheme compromising Twitter customer support credentials to access internal administrative account management utilities.",
      "blast_radius": "Hijacked 130 high-profile verified accounts (including Joe Biden, Barack Obama, Bill Gates, Elon Musk, Kanye West, and Apple), generating $117,000 in fraudulent Bitcoin payments in three hours and creating unprecedented international security panic.",
      "kill_chain": [
        {
          "phase": "Phone Spearphishing",
          "title": "Employee Helpdesk Impersonation",
          "description": "Clark contacted Twitter customer support staff via telephone claiming to be from the corporate IT support team, directing them to enter their credentials on a spoofed VPN portal.",
          "technical_artifacts": [
            "Spoofed VPN portal",
            "Phone social engineering"
          ],
          "mitre_technique_id": "T1566.004"
        },
        {
          "phase": "Tooling Abuse",
          "title": "Twitter Internal Administrative Tool Hijack",
          "description": "Using legitimate internal administrative utilities, Clark changed the registered email addresses on 130 target accounts, bypassed 2FA, and reset account passwords instantly.",
          "technical_artifacts": [
            "Twitter internal support dashboard ('God Mode')",
            "Email override API"
          ],
          "mitre_technique_id": "T1078"
        },
        {
          "phase": "Cryptocurrency Extortion",
          "title": "Automated Social Media Bitcoin Scam",
          "description": "Attackers posted identical messages promising to double any Bitcoin sent to a specific wallet address, collecting over 12.8 Bitcoin before Twitter locked down verified account posting privileges.",
          "technical_artifacts": [
            "Bitcoin vanity address",
            "Automated tweet posting"
          ],
          "mitre_technique_id": "T1486"
        }
      ],
      "defensive_takeaways": [
        "Require multiple independent administrative approvals for sensitive actions on high-profile accounts.",
        "Enforce FIDO2 hardware security keys for internal tool authentication, blocking credential harvesting over the phone.",
        "Implement automated anomaly detection on bulk password resets and email modifications.",
        "Adopt principle of least privilege, restricting customer support representatives from full account takeover capabilities."
      ]
    }
  },
  {
    "id": "case-ulbricht-silk-road",
    "slug": "us-v-ulbricht-silk-road",
    "title": "U.S. v. Ross Ulbricht (Silk Road Darknet Marketplace)",
    "summary": "Landmark prosecution of Ross Ulbricht, creator and operator of the Silk Road dark web marketplace, which processed hundreds of millions in anonymous Bitcoin transactions for illicit narcotics, computer hacking tools, and money laundering services. Federal agents seized over $3.3 billion in Bitcoin.",
    "case_number": "1:14-cr-00068",
    "court": "U.S. District Court for the Southern District of New York",
    "district": "S.D.N.Y.",
    "country": "United States",
    "opened_at": "2014-02-04",
    "status": "sentenced",
    "victim_sector": "Public Safety, E-Commerce, Controlled Substances",
    "victim_country": "United States",
    "loss_amount_usd": 3360000000,
    "loss_amount_note": "U.S. Government seized over 144,000 Bitcoins from Ulbricht's laptop, and subsequent civil forfeiture actions recovered over 50,000 additional Bitcoins valued at $3.36 billion.",
    "first_seen_at": "2011-01-15T00:00:00Z",
    "last_updated_at": "2026-09-10T12:00:00Z",
    "actor_slug": "dread-pirate-roberts",
    "defendant_slugs": [
      "ross-ulbricht"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1090",
        "evidence_excerpt": "Ulbricht designed the Silk Road website to operate exclusively as a Tor hidden service with .onion addresses, utilizing onion routing to obscure server IP locations and operator identities.",
        "evidence_locator": "Indictment \u00b6 6, Page 3",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Ulbricht",
        "source_url": "https://www.justice.gov/usao-sdny/pr/ross-ulbricht-aka-dread-pirate-roberts-sentenced-manhattan-federal-court-life-prison",
        "technique_name": "Proxy",
        "tactic": "Command and Control"
      },
      {
        "technique_id": "T1071.001",
        "evidence_excerpt": "The Silk Road platform incorporated automated Bitcoin tumbling and internal escrow wallets to break transactional linkages on the public blockchain.",
        "evidence_locator": "Trial Exhibit 122, Trial Transcript Page 842",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Trial Records: U.S. v. Ulbricht",
        "source_url": "https://www.courtlistener.com",
        "technique_name": "Web Protocols",
        "tactic": "Command and Control"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2013-10-01",
        "description": "FBI agents arrest Ulbricht at the Glen Park Public Library in San Francisco with his administrative laptop unencrypted."
      },
      {
        "event_type": "verdict",
        "event_date": "2015-02-04",
        "description": "Federal jury in Manhattan convicts Ulbricht on all seven counts including narcotics trafficking, computer hacking, and money laundering conspiracy."
      },
      {
        "event_type": "sentencing",
        "event_date": "2015-05-29",
        "description": "Judge Katherine Forrest sentences Ulbricht to two life terms plus 40 years imprisonment without parole."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Creation and multi-year operation of the Silk Road hidden service marketplace on the Tor darknet, processing over 9.5 million Bitcoins for illicit drugs, hacking tools, and money laundering.",
      "blast_radius": "Facilitated over $213 million in illegal transactions, leading to the landmark forfeiture of 144,000 Bitcoins from Ulbricht's laptop and an additional 50,000 Bitcoins seized from James Zhong, totaling over $3.3 billion.",
      "kill_chain": [
        {
          "phase": "Anonymized Ingress",
          "title": "Tor Hidden Service Architecture",
          "description": "Ulbricht designed the marketplace as a Tor .onion hidden service, utilizing onion routing cryptography to conceal the server physical IP location and operator identity.",
          "technical_artifacts": [
            "Tor .onion hidden service",
            "PGP encryption keys"
          ],
          "mitre_technique_id": "T1090"
        },
        {
          "phase": "Cryptocurrency Obfuscation",
          "title": "Internal Bitcoin Tumbling and Escrow",
          "description": "The Silk Road platform incorporated automated Bitcoin tumbling and micro-transaction mixing to break the chain of custody on the public Bitcoin blockchain.",
          "technical_artifacts": [
            "Bitcoin tumbling mixer",
            "Cold storage wallet clusters"
          ],
          "mitre_technique_id": "T1071.001"
        },
        {
          "phase": "Physical Apprehension",
          "title": "San Francisco Public Library Seizure",
          "description": "FBI agents arrested Ulbricht at a public library by staging a distraction behind him, seizing his Samsung laptop unencrypted while he was actively logged into the Silk Road Mastermind control panel.",
          "technical_artifacts": [
            "Samsung laptop",
            "Silk Road admin panel session"
          ],
          "mitre_technique_id": "T1078"
        }
      ],
      "defensive_takeaways": [
        "Perform behavioral blockchain analytics (Chainalysis, Elliptic) to trace cryptocurrency clustering and mixer deposits.",
        "Ensure full-disk encryption requires continuous hardware token proximity or short timeout locks.",
        "Implement robust logging and audit trails for infrastructure management access.",
        "Train operational security protocols for sensitive administrative key custody."
      ]
    }
  },
  {
    "id": "case-olympic-games-stuxnet",
    "slug": "operation-olympic-games-stuxnet",
    "title": "Operation Olympic Games (Stuxnet Industrial SCADA Cyberweapon)",
    "summary": "Joint United States and Israeli covert cyber operation that deployed the Stuxnet computer worm, the first known malware capable of causing physical destruction to industrial hardware. The worm exploited four Windows zero-day vulnerabilities and compromised Siemens Step7 PLC software to spin Natanz nuclear centrifuges out of control.",
    "case_number": "N/A (Covert Operation)",
    "court": "U.S. Federal Executive Attribution",
    "district": "Executive Branch",
    "country": "United States",
    "opened_at": "2010-06-17",
    "status": "uncharged",
    "victim_sector": "Industrial Manufacturing, Critical Infrastructure, Energy",
    "victim_country": "Iran",
    "loss_amount_usd": 1000000000,
    "loss_amount_note": "Physically destroyed approximately 1,000 IR-1 uranium enrichment centrifuges at the Natanz enrichment plant, delaying the Iranian nuclear program by years.",
    "first_seen_at": "2009-11-20T00:00:00Z",
    "last_updated_at": "2026-09-04T12:00:00Z",
    "actor_slug": "tailored-access-operations",
    "defendant_slugs": [],
    "cves": [
      "CVE-2010-2568"
    ],
    "techniques": [
      {
        "technique_id": "T1190",
        "evidence_excerpt": "Stuxnet utilized a Windows zero-day vulnerability in shortcut icon rendering (CVE-2010-2568 LNK vulnerability) allowing automatic binary execution upon viewing a malicious USB drive in Windows Explorer.",
        "evidence_locator": "Symantec Security Response Technical Dossier v1.4, Page 14",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Symantec Stuxnet Dossier",
        "source_url": "https://www.cisa.gov",
        "technique_name": "Exploit Public-Facing Application",
        "tactic": "Initial Access"
      },
      {
        "technique_id": "T1485",
        "evidence_excerpt": "The worm intercepted Siemens Step7 communications with programmable logic controllers (PLCs), secretly overriding centrifuge rotational frequencies while transmitting recorded normal telemetry back to control room displays.",
        "evidence_locator": "CISA Industrial Control Systems Advisory ICSA-10-272-01",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory ICSA-10-272-01",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-10-272-01",
        "technique_name": "Data Destruction",
        "tactic": "Impact"
      }
    ],
    "events": [
      {
        "event_type": "incident",
        "event_date": "2010-06-17",
        "description": "VirusBlokAda security firm identifies Stuxnet worm propagating in the wild on infected Windows systems."
      },
      {
        "event_type": "advisory",
        "event_date": "2010-09-29",
        "description": "CISA publishes technical advisory on Stuxnet targeting Siemens Simatic Step7 and WinCC industrial control software."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Four zero-day Windows vulnerabilities combined with weaponized Siemens Step7 logic and stolen Realtek and JMicron digital certificates, delivered via infected USB flash drives.",
      "blast_radius": "Physically damaged approximately 1,000 IR-1 uranium enrichment centrifuges at Iran's Natanz enrichment facility, delaying the Iranian nuclear enrichment program by an estimated two years.",
      "kill_chain": [
        {
          "phase": "Air-Gap Ingress",
          "title": "LNK Zero-Day USB Propagation",
          "description": "Operatives deployed Stuxnet via USB thumb drives exploiting a Windows shortcut rendering zero-day (CVE-2010-2568), executing code automatically the moment a user browsed the drive in Windows Explorer.",
          "technical_artifacts": [
            "CVE-2010-2568 (LNK flaw)",
            "USB payload",
            "Stolen Realtek digital certificate"
          ],
          "mitre_technique_id": "T1190"
        },
        {
          "phase": "Industrial Environment Identification",
          "title": "Siemens Simatic WinCC Inspection",
          "description": "The worm verified whether the host was running Siemens Step7 or WinCC software connected to specific frequency converter drives manufactured by Fararo Paya and Vacon.",
          "technical_artifacts": [
            "s7otbxdx.dll hook",
            "WinCC database query"
          ],
          "mitre_technique_id": "T1082"
        },
        {
          "phase": "Physical Sabotage & Sensor Spoofing",
          "title": "Centrifuge Over-Speeding and Sensor Replay",
          "description": "Stuxnet intercepted communications with the Siemens S7-300 PLCs, commanding the centrifuges to spin up to 1,410 Hz (causing physical rotor destruction) while transmitting prerecorded normal sensor readings back to the operators.",
          "technical_artifacts": [
            "PLC block injection (OB35, OB1)",
            "Frequency inverter manipulation"
          ],
          "mitre_technique_id": "T1485"
        }
      ],
      "defensive_takeaways": [
        "Disable USB mass storage access on air-gapped critical infrastructure engineering workstations.",
        "Deploy independent, out-of-band analog vibration and frequency sensors that cannot be overridden by SCADA software.",
        "Enforce cryptographic verification and firmware integrity checks on all Programmable Logic Controllers (PLCs).",
        "Implement physical microsegmentation and strict unidirectional security gateways between IT and OT networks."
      ]
    }
  },
  {
    "id": "case-saudi-aramco-shamoon",
    "slug": "saudi-aramco-shamoon-wiper",
    "title": "Saudi Aramco Shamoon Wiper Attack (Cutting Sword of Justice)",
    "summary": "Devastating state-sponsored wiper attack attributed to Iranian threat actors ('Cutting Sword of Justice') that detonated the Shamoon (Disttrack) wiper across Saudi Aramco, simultaneously wiping 35,000 workstation hard drives and overwriting Master Boot Records with an image of a burning American flag.",
    "case_number": "N/A (State-Sponsored Attribution)",
    "court": "U.S. Intelligence Community Attribution",
    "district": "National Security",
    "country": "Saudi Arabia",
    "opened_at": "2012-08-15",
    "status": "uncharged",
    "victim_sector": "Energy, Oil & Gas",
    "victim_country": "Saudi Arabia",
    "loss_amount_usd": 1000000000,
    "loss_amount_note": "Forced the world's largest oil enterprise to manage supply logistics on paper and typewriters, and purchase a substantial portion of the global hard drive market to rebuild operations.",
    "first_seen_at": "2012-08-15T08:00:00Z",
    "last_updated_at": "2026-08-18T10:00:00Z",
    "actor_slug": "oilrig-cutting-sword",
    "defendant_slugs": [],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1485",
        "evidence_excerpt": "The Wiper module contained an embedded EldoS RawDisk driver to bypass Windows operating system write protection, directly overwriting raw sector bytes of the Master Boot Record with image data.",
        "evidence_locator": "CISA Alert TA12-240A: Shamoon Malware",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory TA12-240A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/ta12-240a",
        "technique_name": "Data Destruction",
        "tactic": "Impact"
      },
      {
        "technique_id": "T1021.002",
        "evidence_excerpt": "Shamoon spread across internal subnets by utilizing administrative network shares (ADMIN$) and hardcoded domain credentials harvested from internal engineering servers.",
        "evidence_locator": "Symantec Threat Intelligence Analysis: The Shamoon Attacks",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Symantec Shamoon Intelligence Report",
        "source_url": "https://www.cisa.gov",
        "technique_name": "SMB / Windows Admin Shares",
        "tactic": "Lateral Movement"
      }
    ],
    "events": [
      {
        "event_type": "incident",
        "event_date": "2012-08-15",
        "description": "Shamoon wiper detonates at 8:00 AM on the Laylat al-Qadr Islamic holiday, wiping 35,000 corporate computers in under two hours."
      },
      {
        "event_type": "advisory",
        "event_date": "2012-08-27",
        "description": "US-CERT and CISA issue Alert TA12-240A warning global critical infrastructure operators of Shamoon wiper malware."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Stolen domain administrator credentials used to deploy the Shamoon (Disttrack) wiper across 35,000 corporate workstations during the Islamic holy day of Laylat al-Qadr.",
      "blast_radius": "Overwrote the Master Boot Records (MBR) and system files of 35,000 computers across Saudi Aramco in under two hours, forcing the world's largest oil enterprise to manage supply logistics on paper and purchase a major portion of the global hard drive supply.",
      "kill_chain": [
        {
          "phase": "Initial Foothold",
          "title": "Internal Domain Credential Harvesting",
          "description": "Threat actors acquired privileged network credentials on internal engineering servers, staging the multi-component wiper across internal network repositories.",
          "technical_artifacts": [
            "Hardcoded admin credentials",
            "Internal staging directories"
          ],
          "mitre_technique_id": "T1078"
        },
        {
          "phase": "Automated Subnet Spread",
          "title": "Administrative Share Network Traversal",
          "description": "The wiper iterated through IP addresses across internal subnets, copying itself via administrative network shares (ADMIN$) using stolen domain credentials.",
          "technical_artifacts": [
            "ADMIN$ share writes",
            "net use commands"
          ],
          "mitre_technique_id": "T1021.002"
        },
        {
          "phase": "Raw Disk Destruction",
          "title": "EldoS RawDisk Driver MBR Overwrite",
          "description": "Shamoon deployed a legitimate, digitally signed commercial disk driver (EldoS RawDisk) to bypass operating system sector locks, overwriting disk sectors with an image of a burning American flag.",
          "technical_artifacts": [
            "EldoS RawDisk driver",
            "Disttrack wiper binary",
            "Burning flag image data"
          ],
          "mitre_technique_id": "T1485"
        }
      ],
      "defensive_takeaways": [
        "Block Bring Your Own Vulnerable Driver (BYOVD) attacks using the Microsoft Recommended Driver Blocklist.",
        "Disable ADMIN$ and default administrative file sharing across corporate workstation subnets.",
        "Maintain out-of-band golden image repositories and automated bare-metal workstation provisioning.",
        "Enforce strict behavioral endpoint alerting on raw disk write API calls."
      ]
    }
  },
  {
    "id": "case-change-healthcare-blackcat",
    "slug": "change-healthcare-blackcat-ransomware",
    "title": "Change Healthcare Ransomware Outage (ALPHV / BlackCat)",
    "summary": "Nationwide healthcare billing and pharmacy clearinghouse paralyzed by an ALPHV/BlackCat ransomware deployment. Threat actors gained initial access through an unmonitored Citrix portal server lacking multi-factor authentication, exfiltrating 6 terabytes of protected health data and forcing a 350 Bitcoin ($22 million) extortion payout amidst an estimated $3+ billion systemic recovery cost.",
    "case_number": "HHS-OCR-2024-001",
    "court": "U.S. House Energy and Commerce Committee Oversight & HHS OCR",
    "district": "D.D.C.",
    "country": "United States",
    "opened_at": "2024-02-21",
    "status": "convicted",
    "victim_sector": "Healthcare, Financial Services",
    "victim_country": "United States",
    "loss_amount_usd": 3000000000,
    "loss_amount_note": "Over $3 billion in direct incident response, provider loan liquidity, forensic remediation, and $22M Bitcoin ransom payment.",
    "first_seen_at": "2024-02-12T00:00:00Z",
    "last_updated_at": "2026-09-01T00:00:00Z",
    "actor_slug": "alphv-blackcat",
    "defendant_slugs": [],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1078",
        "evidence_excerpt": "Attackers logged into a production Citrix remote access portal using compromised employee credentials that were not protected by multi-factor authentication.",
        "evidence_locator": "Congressional Hearing Testimony of UnitedHealth Group CEO Andrew Witty, May 1, 2024",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "House Energy and Commerce Committee Testimony",
        "source_url": "https://energycommerce.house.gov",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1486",
        "evidence_excerpt": "ALPHV/BlackCat ransomware encrypted core production enterprise databases and virtualization hosts, completely severing real-time pharmacy eligibility checks across the U.S.",
        "evidence_locator": "HHS OCR Formal Breach Notification",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "HHS OCR Cybersecurity Notice",
        "source_url": "https://www.hhs.gov",
        "technique_name": "Data Encrypted for Impact",
        "tactic": "Impact"
      },
      {
        "technique_id": "T1567",
        "evidence_excerpt": "Adversaries exfiltrated approximately 6 terabytes of highly confidential medical claims, patient clinical history, and billing records to cloud storage repositories prior to encryption.",
        "evidence_locator": "UnitedHealth Group 8-K Regulatory Filing",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "SEC Form 8-K UnitedHealth Group",
        "source_url": "https://www.sec.gov",
        "technique_name": "Exfiltration Over Web Service",
        "tactic": "Exfiltration"
      }
    ],
    "events": [
      {
        "event_type": "incident",
        "event_date": "2024-02-12",
        "description": "Attackers gain initial access to Change Healthcare Citrix portal lacking multi-factor authentication."
      },
      {
        "event_type": "incident",
        "event_date": "2024-02-21",
        "description": "ALPHV ransomware payload executes across server farms; medical claims processing goes dark nationwide."
      },
      {
        "event_type": "ransom_payment",
        "event_date": "2024-03-01",
        "description": "UnitedHealth Group authorizes payment of 350 Bitcoin (approx. $22M) to the ALPHV affiliate operator."
      },
      {
        "event_type": "hearing",
        "event_date": "2024-05-01",
        "description": "UnitedHealth CEO testifies before Congress, confirming the root cause was an unauthenticated Citrix portal."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Attackers logged into a remote access Citrix portal utilizing single-factor employee credentials harvested by infostealers. The portal was a legacy environment that lacked multi-factor authentication (MFA) enforcement.",
      "blast_radius": "Crippled billing and claims processing for over 50% of the medical claims in the United States. Pharmacies could not verify prescription insurance coverage, forcing patients to pay out-of-pocket. Over $3 billion in direct response, provider emergency loan liquidity, and forensic reconstruction costs.",
      "kill_chain": [
        {
          "phase": "Initial Access",
          "title": "Unauthenticated Citrix Portal Ingress",
          "description": "ALPHV/BlackCat affiliates logged into a Change Healthcare Citrix application server using stolen credentials that lacked secondary MFA verification.",
          "technical_artifacts": [
            "Citrix NetScaler Gateway",
            "Single-factor employee session",
            "Infostealer credential logs"
          ],
          "mitre_technique_id": "T1078"
        },
        {
          "phase": "Lateral Movement & Recon",
          "title": "Active Directory Discovery and Network Mapping",
          "description": "Adversaries traversed from the Citrix boundary across internal subnets using standard administrative tools and harvested Kerberos tickets to locate production databases.",
          "technical_artifacts": [
            "AdFind.exe",
            "BloodHound / SharpHound",
            "Kerberos ticket extraction"
          ],
          "mitre_technique_id": "T1087"
        },
        {
          "phase": "Data Exfiltration",
          "title": "Cloud Staging of 6 Terabytes of Protected Health Information",
          "description": "Operatives archived patient records, claims histories, and clinical data into encrypted 7zip volumes and exfiltrated them to cloud hosting accounts via Megasync.",
          "technical_artifacts": [
            "7-Zip compressed archives",
            "Megasync cloud client",
            "6 TB health data exfiltrated"
          ],
          "mitre_technique_id": "T1567"
        },
        {
          "phase": "Extortion Detonation",
          "title": "ALPHV Rust-based Ransomware Encryption",
          "description": "Attackers triggered the ALPHV (BlackCat) Rust binary across critical database servers, encrypting virtual machines and appending random extensions, halting claims processing nationwide.",
          "technical_artifacts": [
            "ALPHV Rust executable",
            "Esxi-targeted payload",
            "RECOVER-files.txt ransom notes"
          ],
          "mitre_technique_id": "T1486"
        }
      ],
      "defensive_takeaways": [
        "Mandate phishing-resistant multi-factor authentication across 100% of external remote access gateways without exceptions for legacy portals.",
        "Implement automated cloud data egress monitoring to alert on outbound exfiltration exceeding baseline volumes.",
        "Maintain immutable, logically isolated operational recovery environments for core transactional clearinghouse services.",
        "Segment clinical and pharmacy transactional systems strictly from enterprise administrative domains."
      ]
    }
  },
  {
    "id": "case-snowflake-credential-theft",
    "slug": "snowflake-customer-credential-theft",
    "title": "Snowflake Enterprise Credential Stuffing & Customer Cloud Thefts",
    "summary": "Financially motivated threat actor collective UNC5537 systematically infiltrated over 165 corporate customer tenants hosted on Snowflake (including Ticketmaster, Santander Bank, Advance Auto Parts, and LendingTree). Attackers leveraged infostealer malware logs dating back years against enterprise user accounts that lacked multi-factor authentication and IP network allowlists, exfiltrating billions of consumer records.",
    "case_number": "SEC-2024-8K-SNOW",
    "court": "U.S. Securities and Exchange Commission & FBI Cyber Division",
    "district": "N.D. Cal.",
    "country": "United States",
    "opened_at": "2024-05-23",
    "status": "alleged",
    "victim_sector": "Cloud Services, Entertainment, Financial Services, Retail",
    "victim_country": "United States",
    "loss_amount_usd": 500000000,
    "loss_amount_note": "Extensive corporate data breach notification costs, extortion demands, and regulatory inquiries across 165+ global enterprise organizations.",
    "first_seen_at": "2024-04-14T00:00:00Z",
    "last_updated_at": "2026-09-01T00:00:00Z",
    "actor_slug": "unc5537-scattered-spider",
    "defendant_slugs": [],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1078",
        "evidence_excerpt": "UNC5537 authenticated directly to enterprise customer Snowflake tenants using single-factor credentials previously captured by RedLine, Vidar, and Lumma infostealer Trojans on employee personal devices.",
        "evidence_locator": "Mandiant Threat Intelligence Special Report: UNC5537 Snowflake Campaign",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Mandiant UNC5537 Report",
        "source_url": "https://cloud.google.com/blog/topics/threat-intelligence",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1110",
        "evidence_excerpt": "Adversaries utilized custom automated tooling named FROSTBITE to systematically test credentials across hundreds of customer tenant URLs and generate presigned staging URLs.",
        "evidence_locator": "Snowflake & CrowdStrike Joint Forensic Investigation Statement",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Snowflake Security Advisory",
        "source_url": "https://www.snowflake.com",
        "technique_name": "Brute Force",
        "tactic": "Credential Access"
      },
      {
        "technique_id": "T1567",
        "evidence_excerpt": "Attackers generated time-limited pre-signed Amazon S3 storage URLs using tenant privileges, transferring hundreds of terabytes of relational data directly to adversary-controlled cloud infrastructure.",
        "evidence_locator": "CISA Advisory AA24-165A",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Alert AA24-165A",
        "source_url": "https://www.cisa.gov",
        "technique_name": "Exfiltration Over Web Service",
        "tactic": "Exfiltration"
      }
    ],
    "events": [
      {
        "event_type": "incident",
        "event_date": "2024-04-14",
        "description": "UNC5537 begins querying customer Snowflake tenants with infostealer-harvested credentials."
      },
      {
        "event_type": "breach_leak",
        "event_date": "2024-05-27",
        "description": "Threat actors post 560 million Ticketmaster customer records for sale on BreachForums for $500,000."
      },
      {
        "event_type": "advisory",
        "event_date": "2024-06-10",
        "description": "CISA, Mandiant, and Snowflake publish joint advisory warning of credential stuffing against accounts lacking MFA."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "UNC5537 threat actors leveraged historical infostealer malware logs (RedLine, Vidar, Lumma) capturing username and password combinations for contractor accounts. Crucially, the target Snowflake customer accounts lacked multi-factor authentication and network IP allowlisting.",
      "blast_radius": "Systematic theft of corporate data spanning 165+ enterprise organizations, including 560 million Ticketmaster customer records, Santander customer databases, and Advance Auto Parts records, leading to widespread consumer fraud and extortion demands on BreachForums.",
      "kill_chain": [
        {
          "phase": "Initial Credential Acquisition",
          "title": "Infostealer Log Ingestion",
          "description": "Adversaries acquired corporate employee credentials harvested by consumer infostealer Trojans that had infected non-managed personal devices between 2020 and 2024.",
          "technical_artifacts": [
            "RedLine stealer logs",
            "Lumma stealer archives",
            "Single-factor username/password pairs"
          ],
          "mitre_technique_id": "T1078"
        },
        {
          "phase": "Automated Reconnaissance",
          "title": "Custom FROSTBITE Enumeration Tooling",
          "description": "UNC5537 utilized custom scripts (dubbed FROSTBITE) to query Snowflake customer tenant URLs, validating credentials and assessing available data schemas without triggering brute-force lockouts.",
          "technical_artifacts": [
            "FROSTBITE Python scripts",
            "Snowflake API requests",
            "Customer tenant URL enumeration"
          ],
          "mitre_technique_id": "T1110"
        },
        {
          "phase": "Cloud Storage Exfiltration",
          "title": "Presigned Amazon S3 URL Staging",
          "description": "Using tenant query privileges, attackers generated short-lived pre-signed Amazon S3 storage URLs and dumped relational tables directly to adversary staging servers.",
          "technical_artifacts": [
            "COPY INTO s3:// stage commands",
            "Presigned AWS S3 URLs",
            "Relational database parquet dumps"
          ],
          "mitre_technique_id": "T1567"
        },
        {
          "phase": "Public Extortion",
          "title": "BreachForums Auction and Ransom Threats",
          "description": "Adversaries posted samples on darknet cybercrime forums, contacting corporate victims directly via email and Telegram demanding cryptocurrency ransoms between $300,000 and $5,000,000.",
          "technical_artifacts": [
            "BreachForums listings",
            "Telegram extortion channels",
            "Sample proof CSV leaks"
          ],
          "mitre_technique_id": "T1041"
        }
      ],
      "defensive_takeaways": [
        "Enforce mandatory multi-factor authentication (MFA) across all SaaS and cloud data warehouse user accounts.",
        "Deploy Network Policy Allowlisting to restrict Snowflake database access strictly to corporate VPN and office IP addresses.",
        "Prohibit session tokens or credentials from non-managed or personal endpoints from accessing enterprise cloud resources.",
        "Audit third-party contractor accounts regularly and terminate inactive access credentials immediately upon contract conclusion."
      ]
    }
  },
  {
    "id": "case-cdk-global-blacksuit",
    "slug": "cdk-global-blacksuit-ransomware",
    "title": "CDK Global BlackSuit Ransomware Incident",
    "summary": "Destructive ransomware incident that incapacitated CDK Global, the premier SaaS dealer management platform for approximately 15,000 car dealerships across North America. Attackers deployed BlackSuit ransomware throughout CDK cloud and on-premises data centers, forcing dealership employees into pen-and-paper workarounds for weeks until an estimated $25 million ransom was transferred.",
    "case_number": "1:24-cv-05231",
    "court": "U.S. District Court for the Northern District of Illinois",
    "district": "N.D. Ill.",
    "country": "United States",
    "opened_at": "2024-06-19",
    "status": "alleged",
    "victim_sector": "Information Technology, Retail, Automotive",
    "victim_country": "United States",
    "loss_amount_usd": 1000000000,
    "loss_amount_note": "Over $1 billion in delayed auto sales, franchise operational disruption, and an estimated $25M (387 BTC) ransom payment.",
    "first_seen_at": "2024-06-18T00:00:00Z",
    "last_updated_at": "2026-09-01T00:00:00Z",
    "actor_slug": "blacksuit-gang",
    "defendant_slugs": [],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1078",
        "evidence_excerpt": "Attackers gained access to CDK enterprise networks using compromised administrator credentials, bypassing secondary verification checks.",
        "evidence_locator": "Class Action Complaint: 1:24-cv-05231 (N.D. Ill.)",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Court Docket: 1:24-cv-05231",
        "source_url": "https://www.courtlistener.com",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1486",
        "evidence_excerpt": "BlackSuit ransomware payloads encrypted virtualized database instances, dealer inventory feeds, and customer relationship management clusters.",
        "evidence_locator": "CISA & FBI Joint Advisory AA24-220A (BlackSuit)",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA24-220A",
        "source_url": "https://www.cisa.gov",
        "technique_name": "Data Encrypted for Impact",
        "tactic": "Impact"
      },
      {
        "technique_id": "T1490",
        "evidence_excerpt": "The ransomware deleted Volume Shadow Copies and backup catalogues, crippling initial automated recovery attempts and forcing a secondary blackout.",
        "evidence_locator": "CISA Advisory AA24-220A Technical Details",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Technical Analysis",
        "source_url": "https://www.cisa.gov",
        "technique_name": "Inhibit System Recovery",
        "tactic": "Impact"
      }
    ],
    "events": [
      {
        "event_type": "incident",
        "event_date": "2024-06-19",
        "description": "CDK Global detects BlackSuit ransomware executing across core servers and shuts down systems."
      },
      {
        "event_type": "incident",
        "event_date": "2024-06-20",
        "description": "A second encryption wave triggers during restoration efforts, shutting down dealership services again."
      },
      {
        "event_type": "ransom_payment",
        "event_date": "2024-06-25",
        "description": "CDK Global transfers 387 Bitcoin (approx. $25M) to a BlackSuit extortion address to obtain decryptor."
      },
      {
        "event_type": "recovery",
        "event_date": "2024-07-04",
        "description": "Core dealer management system services are restored to nearly all 15,000 dealerships."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Adversaries gained initial ingress to CDK Global internal network infrastructure via compromised administrative credentials, subsequently establishing an undetected command foothold.",
      "blast_radius": "Shutdown of CDK dealer management systems utilized by approximately 15,000 car dealerships in the United States and Canada. Dealerships were unable to process new vehicle purchases, register titles, order replacement parts, or service vehicles for nearly two weeks. Industry sales losses estimated in the billions, with an estimated $25M ransom payment.",
      "kill_chain": [
        {
          "phase": "Initial Ingress",
          "title": "Compromised Administrative Credentials",
          "description": "BlackSuit ransomware affiliates authenticated to internal CDK management subnets using valid administrator credentials that lacked second-factor validation.",
          "technical_artifacts": [
            "Compromised administrator accounts",
            "RDP sessions",
            "VPN gateway logs"
          ],
          "mitre_technique_id": "T1078"
        },
        {
          "phase": "Defense Blindfolding",
          "title": "Shadow Copy Deletion and Security Agent Disablement",
          "description": "Attackers executed vssadmin commands to destroy local Volume Shadow Copies and attempted to disable host monitoring agents across hypervisor hosts.",
          "technical_artifacts": [
            "vssadmin.exe delete shadows /all /quiet",
            "bcdedit.exe /set {default} recoveryenabled No"
          ],
          "mitre_technique_id": "T1490"
        },
        {
          "phase": "System-Wide Encryption",
          "title": "BlackSuit VMware ESXi and Windows Encryption",
          "description": "Adversaries unleashed the BlackSuit encryption binary across both Windows server clusters and VMware ESXi hypervisors, encrypting database virtual disks (.vmdk) simultaneously.",
          "technical_artifacts": [
            "BlackSuit ELF/ESXi payload",
            "BlackSuit Windows binary",
            ".blacksuit encrypted file extension"
          ],
          "mitre_technique_id": "T1486"
        },
        {
          "phase": "Secondary Disruption",
          "title": "Re-infection During Premature Restoration",
          "description": "As CDK engineering teams attempted to bring backup systems online, the ransomware detonated a second time across newly exposed environments, forcing an extended blackout.",
          "technical_artifacts": [
            "Persistent registry run keys",
            "Scheduled task triggers",
            "Secondary extortion note drop"
          ],
          "mitre_technique_id": "T1053.005"
        }
      ],
      "defensive_takeaways": [
        "Isolate hypervisor management interfaces (ESXi / vCenter) completely from general corporate Active Directory domains.",
        "Implement automated immutable offline backups that cannot be modified or deleted via network administrator credentials.",
        "Conduct full forensic containment and credential revocation across all environments prior to initiating system restoration.",
        "Establish secondary out-of-band communication workflows and manual fallback protocols for critical SaaS platforms."
      ]
    }
  },
  {
    "id": "case-att-telecom-metadata-theft",
    "slug": "att-telecom-metadata-snowflake-breach",
    "title": "AT&T Cloud Telecom Call and Text Metadata Exfiltration",
    "summary": "Illegal exfiltration of call and text interaction metadata spanning six months for approximately 110 million AT&T wireless customers. Intrusion stemmed from an illicit access point to a third-party Snowflake cloud environment, leading to a 5.7 Bitcoin extortion fee paid through an intermediary to obtain verified video evidence of dataset deletion.",
    "case_number": "SEC-2024-8K-ATT",
    "court": "U.S. Securities and Exchange Commission & DOJ National Security Division",
    "district": "N.D. Tex.",
    "country": "United States",
    "opened_at": "2024-07-12",
    "status": "investigation",
    "victim_sector": "Telecommunications",
    "victim_country": "United States",
    "loss_amount_usd": 100000000,
    "loss_amount_note": "Major regulatory investigations, carrier mitigation costs, and $370,000 cryptocurrency deletion proof payment.",
    "first_seen_at": "2024-04-14T00:00:00Z",
    "last_updated_at": "2026-09-01T00:00:00Z",
    "actor_slug": "unc5537-scattered-spider",
    "defendant_slugs": [],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1078",
        "evidence_excerpt": "Attackers logged into AT&T customer Snowflake cloud workspace using compromised access tokens without hardware multi-factor verification.",
        "evidence_locator": "AT&T Form 8-K Current Report to SEC",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "SEC Form 8-K AT&T Inc.",
        "source_url": "https://www.sec.gov",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1567",
        "evidence_excerpt": "The threat actor exfiltrated phone numbers, call durations, and cell tower interaction identifiers covering May 1 to October 31, 2022.",
        "evidence_locator": "FCC Formal Notice of Inquiry into AT&T Cloud Breach",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "FCC Public Notice",
        "source_url": "https://www.fcc.gov",
        "technique_name": "Exfiltration Over Web Service",
        "tactic": "Exfiltration"
      }
    ],
    "events": [
      {
        "event_type": "incident",
        "event_date": "2024-04-19",
        "description": "Attackers download phone call and text records of cellular customers from May to October 2022."
      },
      {
        "event_type": "discovery",
        "event_date": "2024-05-17",
        "description": "AT&T security operations identify unauthorized workspace queries and terminate compromised tokens."
      },
      {
        "event_type": "ransom_payment",
        "event_date": "2024-05-25",
        "description": "Intermediary transfers 5.7 Bitcoin ($370,000) to threat actor for video proof of database deletion."
      },
      {
        "event_type": "disclosure",
        "event_date": "2024-07-12",
        "description": "AT&T files Form 8-K with the SEC following two national security disclosure delays by the DOJ."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Threat actors accessed an AT&T corporate workspace hosted on Snowflake using compromised credentials that lacked hardware multi-factor authentication.",
      "blast_radius": "Exfiltration of phone numbers, call records, and text message metadata covering approximately 110 million wireless customers over six months (May to October 2022). Included cell site tower interaction coordinates enabling geographic tracking. AT&T negotiated and paid a 5.7 Bitcoin ($370,000) extortion payment to verify deletion.",
      "kill_chain": [
        {
          "phase": "Workspace Access",
          "title": "Compromised Access Token Authentication",
          "description": "Adversaries authenticated to the AT&T analytical workspace hosted in Snowflake using stolen API access tokens without secondary hardware security key verification.",
          "technical_artifacts": [
            "Snowflake analytical tokens",
            "API query session logs"
          ],
          "mitre_technique_id": "T1078"
        },
        {
          "phase": "Mass Query & Harvesting",
          "title": "Call Detail Record (CDR) Data Extraction",
          "description": "Attackers executed automated queries to pull massive tables containing Call Detail Records (CDRs), phone numbers, interaction counts, and cell tower IDs.",
          "technical_artifacts": [
            "SQL table SELECT queries",
            "CDR database views",
            "Tower identification records"
          ],
          "mitre_technique_id": "T1530"
        },
        {
          "phase": "Data Exfiltration",
          "title": "Cloud-to-Cloud Data Transfer",
          "description": "Extracted records were channeled to external cloud storage buckets controlled by the threat actor group, bypassing perimeter data loss prevention inspection.",
          "technical_artifacts": [
            "External cloud storage bucket",
            "Compressed tar.gz partitions"
          ],
          "mitre_technique_id": "T1567"
        },
        {
          "phase": "Verification & Deletion",
          "title": "Extortion Negotiation and Deletion Proof",
          "description": "Adversaries demanded cryptocurrency extortion to prevent public dissemination, providing video screen recording evidence of database deletion upon receiving 5.7 Bitcoin.",
          "technical_artifacts": [
            "Bitcoin blockchain transaction",
            "Video verification proof",
            "Intermediary forensic escrow"
          ],
          "mitre_technique_id": "T1485"
        }
      ],
      "defensive_takeaways": [
        "Apply zero trust conditional access policies requiring managed device certificates and hardware FIDO2 tokens for all cloud analytical environments.",
        "Implement strict data masking and tokenization on Call Detail Records and customer telephony metadata.",
        "Establish continuous behavioral anomaly detection on bulk database query volumes and off-hours extraction.",
        "Require network IP allowlisting for all third-party cloud data warehouse connections."
      ]
    }
  },
  {
    "id": "case-microsoft-midnight-blizzard",
    "slug": "microsoft-midnight-blizzard-email-breach",
    "title": "Microsoft Corporate Executive Email Intrusion (Midnight Blizzard / SVR)",
    "summary": "Russian Foreign Intelligence Service (SVR / Midnight Blizzard / APT29) compromised Microsoft corporate email systems via a password spray campaign against a legacy non-production test tenant lacking multi-factor authentication. Attackers leveraged the test account's permissions to grant full OAuth app-level access, reading executive emails and exfiltrating source code and customer cryptographic secrets.",
    "case_number": "SEC-2024-8K-MSFT",
    "court": "U.S. Securities and Exchange Commission & CISA Emergency Directive 24-02",
    "district": "W.D. Wash.",
    "country": "United States",
    "opened_at": "2024-01-19",
    "status": "investigation",
    "victim_sector": "Information Technology, Cloud Services",
    "victim_country": "United States",
    "loss_amount_usd": 150000000,
    "loss_amount_note": "System-wide architectural overhaul (Secure Future Initiative), token revocations, and CISA Emergency Directive 24-02 compliance.",
    "first_seen_at": "2023-11-20T00:00:00Z",
    "last_updated_at": "2026-09-01T00:00:00Z",
    "actor_slug": "apt29",
    "defendant_slugs": [],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1110",
        "evidence_excerpt": "Adversaries executed a slow, distributed password spray against a non-production legacy tenant account that did not enforce multi-factor authentication.",
        "evidence_locator": "Microsoft Security Response Center (MSRC) Investigation Update",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "MSRC Blog Post on Midnight Blizzard",
        "source_url": "https://www.microsoft.com/security/blog",
        "technique_name": "Brute Force",
        "tactic": "Credential Access"
      },
      {
        "technique_id": "T1078",
        "evidence_excerpt": "After authenticating to the legacy test tenant, Midnight Blizzard created new OAuth credentials with high-privilege application permissions (full_access_as_app) to query Exchange Web Services.",
        "evidence_locator": "CISA Emergency Directive 24-02: Mitigating SVR Compromise",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Emergency Directive 24-02",
        "source_url": "https://www.cisa.gov/news-events/directives/ed-24-02",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1041",
        "evidence_excerpt": "Adversaries exfiltrated emails and attachments belonging to Microsoft senior executive leadership and cybersecurity personnel over encrypted HTTPS channels.",
        "evidence_locator": "Microsoft SEC Form 8-K Disclosure",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "SEC Form 8-K Microsoft Corp",
        "source_url": "https://www.sec.gov",
        "technique_name": "Exfiltration Over C2 Channel",
        "tactic": "Exfiltration"
      }
    ],
    "events": [
      {
        "event_type": "incident",
        "event_date": "2023-11-20",
        "description": "SVR operators begin distributed password spraying against legacy Microsoft non-production tenants."
      },
      {
        "event_type": "discovery",
        "event_date": "2024-01-12",
        "description": "Microsoft internal security discovers unauthorized nation-state access to corporate mailboxes."
      },
      {
        "event_type": "disclosure",
        "event_date": "2024-01-19",
        "description": "Microsoft publicly discloses the intrusion via an SEC Form 8-K filing."
      },
      {
        "event_type": "directive",
        "event_date": "2024-04-02",
        "description": "CISA issues Emergency Directive 24-02 ordering federal agencies to remediate exposed credentials."
      }
    ],
    "attack_anatomy": {
      "ground_zero": "Russian Foreign Intelligence Service (SVR / Midnight Blizzard) conducted a password spray attack against a legacy, non-production test tenant account that lacked multi-factor authentication.",
      "blast_radius": "Adversaries gained unauthorized access to corporate email accounts of Microsoft senior leadership, cybersecurity teams, and legal counsel. Operatives exfiltrated source code repositories, communication secrets, and customer authentication secrets shared in emails, prompting CISA Emergency Directive 24-02 for all federal civilian agencies.",
      "kill_chain": [
        {
          "phase": "Initial Access",
          "title": "Distributed Password Spraying Against Legacy Tenant",
          "description": "SVR operators launched a slow, distributed password spray across multiple residential IP proxies against a non-production test tenant that lacked MFA.",
          "technical_artifacts": [
            "Distributed residential proxy network",
            "Single-factor test tenant account"
          ],
          "mitre_technique_id": "T1110"
        },
        {
          "phase": "Privilege Escalation",
          "title": "OAuth Application Creation and Role Assignment",
          "description": "After compromising the test account, Midnight Blizzard leveraged its permissions to create high-privilege OAuth applications and assign the full_access_as_app role for Exchange Web Services.",
          "technical_artifacts": [
            "Malicious OAuth enterprise application",
            "AppRoleAssignment to Exchange",
            "full_access_as_app permission"
          ],
          "mitre_technique_id": "T1098"
        },
        {
          "phase": "Persistent Access",
          "title": "Exchange Web Services (EWS) API Ingress",
          "description": "Attackers authenticated via the newly minted OAuth applications to query the Microsoft corporate Exchange environment, querying mailboxes silently without user interaction.",
          "technical_artifacts": [
            "Exchange Web Services (EWS) API calls",
            "OAuth bearer tokens"
          ],
          "mitre_technique_id": "T1078"
        },
        {
          "phase": "Targeted Exfiltration",
          "title": "Executive Mailbox and Source Code Theft",
          "description": "Adversaries searched for and exfiltrated emails containing cybersecurity threat research, source code snippets, and customer credentials shared with Microsoft support teams.",
          "technical_artifacts": [
            "Corporate executive email threads",
            "Source code repository secrets",
            "Encrypted HTTPS exfiltration"
          ],
          "mitre_technique_id": "T1041"
        }
      ],
      "defensive_takeaways": [
        "Enforce 100% multi-factor authentication across all non-production, test, development, and legacy cloud tenants without exception.",
        "Strictly audit and restrict application-level OAuth permissions (such as full_access_as_app) that grant broad mailbox access.",
        "Segregate non-production directory tenants completely from production identity providers and corporate directories.",
        "Deploy continuous threat intelligence monitoring to identify suspicious credential creation within OAuth applications."
      ]
    }
  }
]