PerSwaysion is a threat actor known for conducting phishing campaigns targeting high-level executives. They have been active since at least August 2019 and are believed to be based in Vietnam. PerSwaysion has recently updated their techniques, using more direct phishing methods and leveraging Microsoft 365 to steal credentials.
Executive Summary
PerSwaysion is an active threat actor targeting high-level executives via phishing campaigns, particularly focusing on credential theft using Microsoft 365. Originating from Vietnam and active since August 2019, they have evolved their techniques to more direct phishing methods and are suspected to be involved in financial gain or corporate espionage.
Goals & Targeting
PerS waysion's primary objectives likely include financial gain and/or access to sensitive corporate information. They target high-level executives, possibly to gain unauthorized access to corporate networks or sensitive data. The choice of Microsoft 365 as an attack vector suggests a focus on environments where email communication is central and potentially rich in exploitable targets.
Enhanced Description
PerSwaysion is a threat actor known for conducting phishing campaigns that specifically target high-level executives. They were first observed in August 2019 and are believed to be based in Vietnam. The group has recently updated their tactics, employing more direct phishing methods and leveraging Microsoft 365 to steal credentials. PerSwaysion's activities suggest a focus on sectors where sensitive corporate information or financial assets could be accessed through compromised executive accounts. Their operations have been noted in regions such as the Middle East and Europe, indicating a strategic approach to targeting.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
PerSwaysion has demonstrated a focus on executives and corporate environments, suggesting a targeted approach to campaign planning. Their use of Microsoft 365 indicates an interest in email-based attack vectors common in many corporate settings.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Low confidence in some details, such as exact motivation and tools used. Inferred information about their origin and techniques may be subject to change.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics