Spear-phishing via highly tailored social engineering
Exploitation of Zero-day vulnerabilities (notably in Microsoft Outlook and Office)
Credential harvesting through sophisticated phishing landing pages
Living-off-the-Land (LotL) using legitimate system tools to evade detection
Exploitation of edge devices (VPNs, routers, and firewalls)
Use of legitimate cloud services (Google Drive, OneDrive) for malware delivery and C2
NTLM relay attacks
Deployment of custom backdoors (e.g., X-Agent, Zebrocy, Sednit)