Scenario

A multinational technology company has been the target of several cyber attacks in the past few months. The attackers have been successful in stealing sensitive intellectual property and causing disruptions to the company's operations. A threat advisory report about similar attacks has been shared, and as a CTI analyst, your task is to identify the Tactics, Techniques, and Procedures (TTPs) being used by the Threat group and gather as much information as possible about their identity and motive. For this task, you will utilise the OpenCTI platform as well as the MITRE ATT&CK navigator, linked to the details below.

APT X_USBFerry.pdf

Screenshot 2025-07-08 224933.png

Screenshot 2025-07-08 224946.png

https://tryhackme.com/room/trooper


1- What kind of phishing campaign does APT X use as part of their TTPs?

spear-phishing emails

Screenshot 2025-07-09 090854.png

its in the report provided

2- What is the name of the malware used by APT X?

USBferry

Screenshot 2025-07-09 091014.png

same

3- What is the malware's STIX ID?