.:: APT 77 INCIDENT REPORT ::.

This evening around 1772828043 the threat actors known as #APT77 aka #FluffyRodent aka #t34md3gu have breached containment.

While APT77 were engaged in their routine evening check of /var/run which is carried out with escalated privileges and outside of their usual jail environment, due to human error, a critical port was left open for egress and ingress in the production environment. Utilising the breached door(8) Agent R and Agent F both escaped containment.

The discovery was quick and incident response was rapid. Fortunately, after lessons learned from the last incident, the bathroom shower tray fascia has been patched, and upgrades to the general tidiness of the upstairs corridor were actioned. This meant that it was much harder for APT77 to establish persistence, although attempts were made to do so, by hiding under a small console table.

In the immediate aftermath Agent R has taken to run in the wheel in their jail environment, and Agent R, sitting on top of /var/log has been issuing kill -SIGALRM commands repeatedly, but has now settled down after the episode.

APT77 have now resumed their evening check of /var/run, albeit, with continued port scanning activity targeted at the previously discovered security holes.

#degucontent

#APT77 INCIDENT REPORT

Today threat actors affiliated with APT77 aka #FluffyRodent aka #T34MD3GU infiltrated critical infrastructure and established persistence in the water system.

By carrying out timing attacks on the owner which suffered from memory flaws due to not having been able to enter ACPI S3 adequately they managed to slip through an open gateway unnoticed.

After the successful jailbreak they forked off and in asynchronous fashion started to move laterally to the child bedroom and to the bathroom.

In the child bedroom Agent F was discovered chewing up some HotWheels tracks in the corner. It seems the loss of track consistency is irrecoverable.

Agent R (pictured) pwned a cavity under the shower tray and was having the time of her life next to the water pipes. Fortunately operatives managed to uncover her activities and with the use of peanuts and her favourite play tube managed to extricate the threat actor from critical infrastructure.

There remains no known mitigation against APT77 activity.

#degucontent

Rosemary enjoying her elevated privileges after jailbreaking #apt77 #t34md3gu #FluffyRodent #degucontent
Now they are at the data exfil stage, pull the cord, PULL THE CORD!!
#apt77 #t34md3gu #FluffyRodent
#degucontent
#APT77 agent stealthily establishing persistence in the production pipeline via a back door #degucontent #FluffyRodent #t34md3gu

Frances enjoying her escalated privileges and escaping a sandbox

#degucontent #apt77 #FluffyRodent #t34md3gu

T34M D3GU has established persistence in /var/log

#degucontent #APT77 #FluffyRodent