NSFOCUS Security Labs recently discovered a new attack process based on phishing documents in their daily threat-hunting operations. Delving deeper into this finding through extensive research, they confirmed two new Trojan horse programs and many rare attack techniques and tactics. NSFOCUS Security Labs believes that this new attack process comes from a new APT attacker, who has a high technical level and cautious attack attitude. The phishing attack activity captured this time is part of the attacker’s targeted strike on specific targets and is its main means to achieve in-domain penetration. NSFOCUS Security Labs validated the high-level threat attributes of AtlasCross in terms of development technology and attack strategy through an in-depth analysis of its attack metrics. At this current stage, AtlasCross has a relatively limited scope of activity, primarily focusing on targeted attacks against specific hosts within a network domain. However, the attack processes they employ are highly robust and mature. NSFOCUS Security Labs deduce that this attacker is highly likely to deploy this attack process into larger-scale network attack operations.
Executive Summary
AtlasCross is a suspected advanced persistent threat (APT) group identified by NSFOCUS Security Labs through novel phishing campaigns and sophisticated attack techniques. The actor demonstrates high technical proficiency and cautious operational behavior, targeting specific hosts within restricted network domains. While currently active on a limited scale, AtlasCross poses significant risks due to its robust attack processes and potential for larger-scale operations.
Goals & Targeting
AtlasCross exhibits a strategic focus on achieving long-term network penetration through targeted attacks. Its primary goal appears to be gaining unauthorized access to specific hosts within a network domain, possibly to establish persistence and lateral movement capabilities. The actor's cautious approach suggests it is targeting high-value assets or sensitive information within sectors where limited visibility would provide strategic advantages. The choice of phishing as the initial attack vector indicates an intent to compromise human factors while maintaining operational stealth to avoid detection. While the exact motivation remains unclear, the combination of technical proficiency and targeted tactics aligns with APT behavior typically linked to state-sponsored espionage or financial gain.
Enhanced Description
AtlasCross, emerging from recent threat-hunting efforts by NSFOCUS Security Labs, represents a new APT group leveraging sophisticated phishing tactics and custom malware. The actor was identified through the deployment of two novel Trojan horse programs and highly refined attack methodologies. These techniques highlight a high level of technical expertise and strategic focus on achieving deep network penetration. AtlasCross primarily employs phishing campaigns using macro-laced Office documents as the initial infection vector, indicative of a methodical approach to compromise specific targets. The actor's cautious operational style suggests it aims for persistence within targeted networks rather than immediate disruption, aligning with typical APT behavior. While its scope appears limited at present, the maturity of its attack processes raises concerns about potential future expansion into broader campaigns. NSFOCUS Labs has not observed significant campaign activity from AtlasCross to date, but its high technical threshold and strategic targeting underscore the need for vigilance among potential victims.
Key Capabilities
MITRE ATT&CK Tactics
Software / Tooling
Campaigns & Victims
AtlasCross has demonstrated limited but highly sophisticated campaign activity, focusing on targeted attacks rather than widespread distribution. Its primary method involves phishing campaigns to compromise specific hosts within a network domain, suggesting an interest in long-term access and persistence. NSFOCUS Security Labs has not observed significant expansion of its operations to date; however, the actor's highly refined attack processes indicate potential for more extensive campaigns. The cautious operational style suggests AtlasCross may be preparing for larger-scale or high-value targets, which could pose risks to sectors requiring stringent network security.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in the identification of AtlasCross as a new APT group based on NSFOCUS Security Labs' analysis. Key gaps include limited historical campaign data and an unclear primary motivation or broader targeting strategy. Additional intelligence on associated tools, infrastructure, and specific targets would enhance understanding of its capabilities.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics