>_ The Cyber Casebook // AP CYBER · AP NETWORKING · AI
Home / All case studies / The $387M Heist

Key terms

Zero-dayHot walletWeb shellBounty

AP Cybersecurity alignment

  • 2.1.C.4After gaining access during an attack, adversaries establish persistence to maintain access without needing to regain it. They may use a command and control (C2) protocol to send commands to the device and receive output,…Learning objective: Describe the phases of a cyberattack.
  • 2.1.C.6In the taking-action phase of an attack, adversaries act on their objectives by collecting targeted data, exfiltrating it, and disrupting services or destroying data.Learning objective: Describe the phases of a cyberattack.
  • 4.1.C.1Adversaries can develop exploits for known vulnerabilities in software (including operating systems). Devices with unpatched software are vulnerable to these exploits, which could allow an adversary to crash a system, view…Learning objective: Explain how adversaries can exploit common device vulnerabilities to cause loss, damage, disruption, or destruction.

AP Networking alignment

  • 2.5.A.3Data loss, device compromise, or malware infection can result when network devices are not updated or secured. These impacts may occur due to outdated firmware or the connection of untrusted devices with known vulnerabilities.Learning objective: Identify impacts of potential security vulnerabilities in a SOHO network.
  • 4.5.A.3Widespread data compromise, service outages, or loss of administrative control can occur when an adversary or malicious software moves laterally across a network. These impacts are more likely in segmented or large networks…Learning objective: Identify the impacts of common threats and vulnerabilities in a managed network.
  • 4.6.B.2Monitoring and alerting tools help ensure availability by enabling rapid detection of failures or suspicious activity.Learning objective: Identify ways to improve the reliability and availability of networked systems.

Related case studies