Port 22

SAS 2021: Learning to ChaCha with APT41

John Southworth gives insights about APT41 and the malware used by the threat actor the Motnug loader and its descendant, the ChaCha loader; also, shares some thoughts on the actors attribution and the payload, including the infamous CobaltStrike.