24/7 ONLINE · 09:00–00:00◆Hacettepe Teknokent / Ankara
+90 536 662 38 09[email protected]
DSETDoğanay Siber Emniyet
  • Services
  • Academy
  • Simulator
  • Blog
    BlogArticles · technical write-ups · guidesAnnouncementsLatest DSET news · bulletinsVideo GalleryTraining · demos · cyber security videos
  • About Us
    About UsThe DSET story · vision · teamSimulators and ToolsFree interactive calculators, simulators and diagnosis wizardsSector SolutionsFinance · Healthcare · Public Sector · E-Commerce · 7 industriesReference CasesReal DSET cases · industry outcomesIn the PressDSET in the national pressSite SearchAll content · articles · services · casesFrequently Asked QuestionsCommon questions · quick answersContactPhone · WhatsApp · address · form
  • Tracking System
    Customer LoginAccount dashboard · request trackingForensics RequestDigital evidence · examination requestData Recovery RequestDisk · RAID · recovery requestPrice CalculatorATK 2026 reference · 9 services
KAOS
TREN
DSETCustomer Panel

Sign in to your account

Request tracking, quote approval and your history in one panel.

Loading security verification...
DSET Customer Panel AES 256 GCM encrypted session
DSET AI
//Investment & Holding · 2026
Investment & Holding · Case 2026

Investment holding · Cobalt Strike Malleable C2 · APT41 · undetected for 4 months · USOM coordination

An investment holding's SOC analyst noticed an anomalous jitter pattern in HTTPS traffic: a Cobalt Strike Malleable C2 profile (Amazon mimicking) had been used. Inside for 4 months, 23 endpoints infected. An APT41 TTP match. With 2 weeks of passive observation + USOM coordination + coordinated eradication DSET achieved 24 months of clean operation and national threat intel sharing.

Duration
2 weeks of observation · 30 days of eradication
Scope
23 infected endpoints · CFO+CEO included · APT41
Customer Satisfaction
★★★★★

01 The Challenge

Zeek/Suricata: a C2 beacon polling every 60s ± 10s (Cobalt Strike default). JA3 fingerprint 72a589da586844d7f0818ce684948eea (Cobalt Strike defaults). 23 endpoints infected, including the CFO + CEO + 4 investment analysts. Sensitive investment strategies at risk.

02 DSET's Approach

01

T+0 · Start passive observation

DSET was called in urgently, a 2-week passive observation TTP collection plan. Early movement triggers APT41.

02

T+2 weeks · Full TTP map

The C2 server identity (a Chinese VPN) + the exfil channel + IOCs were fully mapped. USOM coordination, joint work with the authorities of 4 countries.

03

T+15 days · Coordinated eradication

Simultaneous cleanup of 23 endpoints (without the attacker noticing). A joint C2 takedown with USOM (coordination with the Chinese VPN provider).

04

T+18 days · AD reset

krbtgt rotation × 2, DA reset, all credentials reset. The attacker was completely kicked out.

05

T+30 days · Full architecture

DSET ZTNA + EDR + a DNS firewall + Sentinel + a threat intel feed. Multi-layer protection against APT41 was established.

06

T+90 days · USOM partnership

A USOM "critical infrastructure" partnership, national threat intel sharing. Quarterly tabletops with APT scenarios.

07

T+24 months · Continuously clean

DSET 36-month annual audit. 3 years clean, 3 new APT attempts blocked automatically; the holding earned the sector title of "cyber security pioneer."

03 Results in Numbers

23 endpoints
APT41 eradication
2 weeks
Passive observation
Active
USOM coordination
0
Reinfection (3 years)
3
Automatic blocks (new APT)
Cyber security pioneer
Sector title

04 Customer Testimonial

"

Learning that APT41 had been inside for 4 months was terrifying. DSET's strategy of 2 weeks of passive observation + USOM coordination gave us a full TTP map; with coordinated eradication we kicked the attacker out without triggering them.

Holding CISO
Investment Holding · 8M USD AuM
★★★★★

05 Key Takeaways

In APT41 attacks, early eradication = a guaranteed return via a new vector
2 weeks of passive observation + USOM coordination is critical for fighting with national resources
Every holding should have the Cobalt Strike default JA3 fingerprint as a Suricata rule
A threat intel feed + a DNS firewall automatically block new APT attempts

06 Services Used in This Case

KAOS Local Artificial Intelligence

Turkey's cyber guardian · local · independent · on the path to world leadership.

Cyber Security

Cognitive solutions.

Incident Simulator & Threat Heatmap

Not hours of deliberation · but minutes of interactive simulation.

Your case can end just as well.

Free assessment · detailed response within 48 hours.

Call Now Contact form

Other Cases

Automotive Manufacturing

Ransomware on 800 endpoints at an automotive supplier · full recovery in 9 days

View
Public Administration

Detection and cleanup of a 14-month APT intrusion at a metropolitan municipality

View
Finance

A 9-day Red Team engagement at one of Turkey's top 5 banks

View
DSETDoğanay Siber Emniyet

Digital Forensics · Data Recovery · Cyber Security · Information Security · Technical Examination · Expert Opinion · KVKK & GDPR Compliance · Digital Transformation Consulting · advanced training programs offered by DSET Academy.

+90 536 662 38 09[email protected]Hacettepe Teknokent · Üniversiteler Mah. 1596. Cad. 6. AR-GE Blokları C Blok No:6C Z.Kat · Beytepe · Çankaya · ANKARAOur Google Business Profile7/24 Online · 09.00 → 00.00 · Pazartesi · Pazar

Our Services

  • Digital Forensics
  • Data Recovery
  • KAOS Local Artificial Intelligence
  • Cyber Security
  • KVKK-GDPR Consultancy
  • DSET Academy
  • Incident Simulator & Threat Heatmap
  • Website Security
  • Information Security
  • Adli Bilişim Benchmark'ı

Support & Help

  • About Us
  • Press Room
  • Price Calculator
  • Frequently Asked Questions
  • Contact
  • EU AI Act Article 4 Guide
  • Sector Solutions
  • KVKK Disclosure Statement
  • GDPR · EU Data Rights
  • Privacy Policy
  • Cookie Policy
  • Terms of Service

Quick Links

  • Solutions
  • DFB Benchmark
  • Blog
  • Video Gallery
  • DSET Academy
  • Case Simulator
  • Reference Cases
  • Site Search
  • DSET AI Assistant
  • Digital Forensics Request Form
  • Data Recovery Request Form
  • Customer Login

Ecosystem

  • Hacettepe Teknokent
  • Cyber Security Cluster
  • USOM · National Cyber Incident Response
  • KVKK Authority
  • llms.txt
© 2026 dset.com.tr · Doğanay Siber Emniyet Teknolojileri · All rights reserved.
“Kalite asla tesadüf değildir...”
TREN
Home
References
Privacy
KVKK
GDPR
Cookies
Terms