MITRE ATT&CK documents APT42 as a phishing-focused threat actor that steals credentials and MFA tokens through spearphishing links, impersonation, and cloned login pages, including interception of SMS one-time passwords. The group is also associated with masquerading domains, anonymized VPS infrastructure, and command-and-control over HTTPS, including use of NICECURL and Base64-encoded traffic. On compromised systems, APT42 has used PowerShell, scripts, and WMI for discovery, deployed malware for keylogging, screenshots, and browser credential and cookie theft, and collected data from Microsoft 365 environments while using built-in cloud features and public tools to reduce detection.
The mapped tradecraft also shows APT42 maintaining access through Registry changes and scheduled tasks, while removing evidence by clearing Chrome history and deleting mailbox artifacts. Separately, Splunk published a detection for suspicious creation or modification of files in Linux /etc/update-motd.d, a persistence path where login-triggered Message of the Day scripts can be abused to execute malicious code. The analytic, based on endpoint filesystem telemetry such as Sysmon for Linux Event ID 11, is disabled by default and intended to surface intermediate risk events because legitimate administrative changes can also trigger the rule.

Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Splunk updated its "Linux MOTD Script Added" analytic, which detects creation or modification of files in /etc/update-motd.d that attackers can abuse for persistence or execution on Linux systems. The detection is implemented as an anomaly rule in Splunk Enterprise Security and is disabled by default.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.