| Reference | TTP Info |
|---|---|
| https://attack.mitre.org/campaigns/C0029/ | Tampering with OS integrity checker tool |
| https://www.volexity.com/blog/2024/01/10/active-exploitation-of-two-zero-day-vulnerabilities-in-ivanti-connect-secure-vpn/ | Attackers have installed webshells |
| https://www.sygnia.co/blog/china-nexus-threat-group-velvet-ant/ | Threat actors created reverse SSH tunnels for persistent remote access |