---
title: "Threat Intel Content Update: 11/20/24"
description: "Tidal Cyber's threat intelligence content updates for the week of 11/12/24. 

Threat Highlights
Well-known researcher Florian Roth published a Q4 2024 trends post. Tidal has CTI content related to each of the highlighted trends:

EDR killers: EDRSilencer, EDRSandBlast, & other Software under the Defense Evasion Tools Tag or T1068 Technique.

Binary auxiliary execution: Newly added GrimResource (.msc) & APT29 (.rdp files) Campaigns.

Remote Administration Tool-RMM Tag

Several new Groups & Campaigns added under the Cloud API (T1059.009) Technique.

ADCS: Not really a trend, at least for publicly reported adversary activity, but it's summarized by T1649 and did feature in the recently added Pacific Rim Campaign.

PowerShell copy/paste campaign: PowerShell User Execution Social Engineering Campaign object.

Persistence outside EDR visibility: Could refer to a few things, but most likely (or at least including) recent rootkits (T1014) and edge device activity (IoT Threat_Routers or IoT Threat_Other Tags).

Additional Salt Typhoon Technique relationships following newly-confirmed reports that the Chinese espionage group had accessed high-profile call records from major telecom companies.

New TA455 Iranian Dream Job Campaign, where researchers concluded that Iranian actors (TA455) were either impersonating North Korea’s Lazarus Group, or that North Korean actors had shared tools and TTPs with the former."
---

[Threat Intelligence Content Updates ](https://www.tidalcyber.com/threat-updates)

# [Threat Intel Content Update: 11/20/24](https://www.tidalcyber.com/threat-updates/threat-intel-content-updated-11/20/24)

 Written by [Tidal Cyber](https://www.tidalcyber.com/threat-updates/author/tidal-cyber) | Nov 20, 2024 4:00:00 PM

#### EDR Killers, GrimResource, Remote Administration Tool-RMM, Cloud API, PowerShell copy/paste campaign, Persistence outside EDR visibility

 

**Threat Highlights**

- Well-known researcher Florian Roth published a “[Q4 2024 trends](https://www.linkedin.com/posts/floroth_cybersec-trends-q424-edr-killers-vulnerable-activity-7262741201265520641-1jB3/?utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-9X32zFEiuFzqBgmwWTxHrwn6KZimwnNLx_MPWWqjpDTjXIMlOsyPnyZNktqkrSVjOEIzO5)” post. Tidal has CTI content related to each of the highlighted “trends”:
  
    - "EDR killers": [EDRSilencer](https://app.tidalcyber.com/software/9c62329b-d02e-457a-9add-4df749eb7f54), [EDRSandBlast](https://app.tidalcyber.com/software/fbd2d7b0-0aa8-459f-8bfa-16daae769282), & other Software under the “Defense Evasion Tools” Tag or [T1068 Technique](https://app.tidalcyber.com/technique/9cc715d7-9969-485f-87a2-c9f7ed3cc44c).
    - Binary "auxiliary" execution: Newly added "[GrimResource](https://app.tidalcyber.com/campaigns/c2f9eb70-cc7d-4d68-80d7-2caf77734674)" (.msc) & APT29 (.rdp files) Campaigns.
    - “Remote Administration Tool-RMM” Tag: Example was be used in our [webinar.](https://www.tidalcyber.com/webinars?commid=629007)
    - Several new Groups & Campaigns added under the Cloud API ([T1059.009](https://app.tidalcyber.com/technique/af798e80-2cc5-5452-83e4-9560f08bf2d5)) Technique.
    - ADCS: Summarized by the [T1649](https://app.tidalcyber.com/technique/b8c27b52-3e73-448d-8a7c-3e814c8e3889) Technique, which featured in our recently added “Pacific Rim” Campaign object.
    - PowerShell copy/paste campaign: “[PowerShell User Execution Social Engineering](https://app.tidalcyber.com/campaigns/9864ed5a-0633-4c04-85f1-728d3ff37e82)” Campaign object.
    - Persistence outside EDR visibility: Could refer to a few things, but most likely (or at least including) recent rootkits ([T1014](https://app.tidalcyber.com/technique/cf2b56f6-3ebd-48ec-b9d9-835397acef89)) and edge device activity (“IoT Threat_Routers” or “IoT Threat_Other” Tags).
- Additional [Salt Typhoon](https://app.tidalcyber.com/groups/753c7cd1-ca9f-4632-bbd2-fd55b9e70b10) Technique relationships following [newly-confirmed reports](https://therecord.media/us-agencies-confirm-china-telecom-hack-wiretaps?utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-9X32zFEiuFzqBgmwWTxHrwn6KZimwnNLx_MPWWqjpDTjXIMlOsyPnyZNktqkrSVjOEIzO5) that the Chinese espionage group had accessed high-profile call records from major telecom companies.
- New “[TA455 Iranian Dream Job Campaign](https://app.tidalcyber.com/campaigns/3c5d0cab-7974-4413-9d00-1aa769bb67db)”, where researchers concluded that Iranian actors (TA455) were either impersonating North Korea’s Lazarus Group, or that North Korean actors had shared tools and TTPs with the former.

[View full post](https://www.tidalcyber.com/threat-updates/threat-intel-content-updated-11/20/24)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Tidal Cyber"
  },
  "dateModified" : "2024-11-22T13:42:00.661Z",
  "datePublished" : "2024-11-20T16:00:00Z",
  "headline" : "Threat Intel Content Update: 11/20/24",
  "image" : {
    "@type" : "ImageObject",
    "height" : 500,
    "url" : "https://21164103.fs1.hubspotusercontent-na1.net/hubfs/21164103/Threat%20Intelligence%20Content%20Update%20Social.jpg",
    "width" : 900
  },
  "mainEntityOfPage" : "https://www.tidalcyber.com/threat-updates/threat-intel-content-updated-11/20/24",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60,
      "url" : "/hs/hsstatic/content_shared_assets/static-1.4092/img/default-amp-logo.png",
      "width" : 60
    },
    "name" : "Threat Intelligence Content Updates"
  }
}
```