hello guys, im curious knowing the list of main arsenal used by apt28, i would like to know what RATs used by the group and what are its protocol to communicate, if anyone know please let me know.
Most true APTs will have custom C2 or will use Brute Ratel / Cobalt. Generic Threat Actor groups will use the cracked copy of Cobalt. Loaders are all in house, and their true TTPs are emergent.