During C0017, APT41 frequently configured the URL endpoints of their stealthy passive backdoor LOWKEY.PASSIVE to masquerade as normal web application traffic on an infected server.2
campaign
C0017 C0017
- First seen
- May 2021
- Last seen
- February 2022
- Created
- 1 December 2022
- Last modified
- 31 July 2026
C0017 was an APT41 campaign conducted between May 2021 and February 2022 that successfully compromised at least six U.S. state government networks through the exploitation of vulnerable Internet facing web applications. During C0017, APT41 was quick to adapt and use publicly-disclosed as well as zero-day vulnerabilities for initial access, and in at least two cases re-compromised victims following remediation efforts. The goals of C0017 are unknown, however APT41 was observed exfiltrating Personal Identifiable Information (PII).[1]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference C0017
During C0017, APT41 copied the SAM and SYSTEM Registry hives for credential harvesting.3
During C0017, APT41 collected information related to compromised machines as well as Personal Identifiable Information (PII) from victim networks.4
During C0017, APT41 used cmd.exe /c ping %userdomain% for discovery.5
During C0017, APT41 broke malicious binaries, including DEADEYE and KEYPLUG, into multiple sections on disk to evade detection.6
During C0017, APT41 used VMProtect to slow the reverse engineering of malicious binaries.7
Standing C0017
Reach is how much of ATT&CK this campaign touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 56 ATT&CK campaigns only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
86th percentile · 86% of 56 ATT&CK campaigns have this many Enterprise techniques or fewer.
77th percentile · 77% of 56 ATT&CK campaigns have this many tactics spanned or fewer.
88th percentile · 88% of 56 ATT&CK campaigns have this many tools and malware or fewer.
55% of the population shares a single value across only 3 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
68th percentile · 68% of 56 ATT&CK campaigns have this many detection rules per technique or fewer.
Detection coverage C0017
1010 distinct rules cover the 29 techniques recorded for this campaign. The 1133 technique-to-rule mappings resolve to 1010 distinct rules, because one rule can cover several techniques. 706 Sigma · 304 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org