Increased Events from Threat Activity Group DEV-0867 - 20230118001¶
Overview¶
The WA SOC has observed an increase of events relating to threat activity group DEV-0867.
Delivery¶
The primary delivery method is via email containing a URL.
Detection and Remediation¶
Detection¶
- Identify the presence of the below supplied KQL/ Kusto hunting code
- Identify the presence of the below supplied IOCs
- Inspect activity from the identified devices and/or users
Recommended Remediation Steps¶
- Run a full Antivirus scan on the compromised device
- Reset the affected user's passwords
- Implement MFA if required
Indicators of Compromise (IOCs)¶
Email information¶
KQL Query¶
Please proceed with caution as the following lines have not been defanged.
//Email item status
//URL Clicks