The document details a sophisticated cyberattack campaign identified by the National Cybersecurity and Communications Integration Center (NCCIC), affecting multiple sectors since May 2016, which utilizes multiple malware implants and stolen administrative credentials. Key findings include the deployment of malware such as Redleaves and PlugX, exploiting weaknesses in IT service providers to gain access to customer environments, and employing various techniques to obscure their activities through the manipulation of legitimate traffic and credential misuse. NCCIC aims to disseminate this information to assist organizations in detecting potential compromises and plans to release further updates as investigations continue.