Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Campaigns/C0017
MITRE ATT&CK Campaign · 2021–2022

C0017 (C0017)

ShareXLinkedInRedditHN

[C0017](https://attack.mitre.org/campaigns/C0017) was an [APT41](https://attack.mitre.org/groups/G0096) campaign conducted between May 2021 and February 2022 that successfully compromised at least six U.S. state government networks through the exploitation of vulnerable Internet facing web applications. During [C0017](https://attack.mitre.org/campaigns/C0017), [APT41](https://attack.mitre.org/groups/G0096) was quick to adapt and use publicly-disclosed as well as zero-day vulnerabilities for initial access, and in at least two cases re-compromised victims following remediation efforts. The goals of [C0017](https://attack.mitre.org/campaigns/C0017) are unknown, however [APT41](https://attack.mitre.org/groups/G0096) was observed exfiltrating Personal Identifiable Information (PII).(Citation: Mandiant APT41)

▪Attributed groups (1)

G0096APT41

▪Techniques used (29)

T1680Local Storage DiscoveryT1027.002Software PackingT1033System Owner/User DiscoveryT1036.004Masquerade Task or ServiceT1016System Network Configuration DiscoveryT1053.005Scheduled TaskT1190Exploit Public-Facing ApplicationT1505.003Web ShellT1140Deobfuscate/Decode Files or InformationT1003.002Security Account ManagerT1027Obfuscated Files or InformationT1041Exfiltration Over C2 ChannelT1048.003Exfiltration Over Unencrypted Non-C2 ProtocolT1074.001Local Data StagingT1071.001Web ProtocolsT1005Data from Local SystemT1102.001Dead Drop ResolverT1059.007JavaScriptT1574Hijack Execution FlowT1090ProxyT1036.005Match Legitimate Resource Name or LocationT1059.003Windows Command ShellT1001.003Protocol or Service ImpersonationT1134Access Token ManipulationT1567Exfiltration Over Web ServiceT1560.003Archive via Custom MethodT1588.002ToolT1105Ingress Tool TransferT1102Web Service

▪Software used (6)

S0154Cobalt StrikemalwareS1051KEYPLUGmalwareS1052DEADEYEmalwareS0105dsquerytoolS0002MimikatztoolS0097Pingtool
C0017on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.