For C0021, the threat actors embedded a base64-encoded payload within a LNK file.3
campaign
C0021 C0021
- First seen
- November 2018
- Last seen
- November 2018
- Created
- 15 March 2023
- Last modified
- 31 July 2026
C0021 was a spearphishing campaign conducted in November 2018 that targeted public sector institutions, non-governmental organizations (NGOs), educational institutions, and private-sector corporations in the oil and gas, chemical, and hospitality industries. The majority of targets were located in the US, particularly in and around Washington D.C., with other targets located in Europe, Hong Kong, India, and Canada. C0021's technical artifacts, tactics, techniques, and procedures (TTPs), and targeting overlap with previous suspected APT29 activity.[1][2]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference C0021
During C0021, the threat actors used encoded PowerShell commands.45
During C0021, the threat actors used obfuscated PowerShell to extract an encoded payload from within an .LNK file.67
During C0021, the threat actors used HTTP for some of their C2 communications.8
During C0021, the threat actors used TCP for some C2 communications.9
During C0021, the threat actors downloaded additional tools and files onto victim machines.1011
Standing C0021
Reach is how much of ATT&CK this campaign touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 56 ATT&CK campaigns only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
41st percentile · 59% of 56 ATT&CK campaigns have more Enterprise techniques.
25th percentile · 75% of 56 ATT&CK campaigns have more tactics spanned.
45th percentile · 55% of 56 ATT&CK campaigns have more tools and malware.
55% of the population shares a single value across only 3 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
38th percentile · 62% of 56 ATT&CK campaigns have more detection rules per technique.
Detection coverage C0021
589 distinct rules cover the 15 techniques recorded for this campaign. The 622 technique-to-rule mappings resolve to 589 distinct rules, because one rule can cover several techniques. 433 Sigma · 156 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org