APT12

πŸ”΄ High
Also known as: APT12, BeeBus, BRONZE GLOBE, Calc Team, Crimson Iron, DNS-Calc, DNSCALC, DNSCalc, DynCalc, Group 22, Hexagon Typhoon, HORDE, HYDROGEN, IXESHE, Numbered Panda, NUMBERED PANDA, Red Anubis, TG-2754, TG-2754 (tentative)

APT12 is a threat group that has been attributed to China. The group has targeted a variety of victims including but not limited to media outlets, high-tech companies, and multiple governments. Meyers Numbered Panda

🌍 Country China
πŸ“… Activity 2012 β€” 2016
⚑ Risk Level High
🎯 Incident Type Espionage
🧭 ATT&CK G0005
Private sector Government
2012
2016

Introduction

APT12 is a threat group that has been attributed to China. The group has targeted a variety of victims including but not limited to media outlets, high-tech companies, and multiple governments. Meyers Numbered Panda

Activities and Tactics

Targeted Sectors: Private sector, Government

Country of Origin: πŸ‡¨πŸ‡³ China

Risk Level: High

First Seen: 2012

Last Activity: 2016

Incident Type: Espionage

Suspected Victims: Taiwan, Japan

Notable Campaigns

  • NYT Oct 2012

Tactics, Techniques, and Procedures (TTPs)

ATT&CK technique IDs (denormalized)

Notable Indicators of Compromise (IOCs)

No atomic indicators are listed in this profile. The APTnotes snapshot indexes 4 public reports that may contain IOCs; see Source Attribution for dataset links.

Malware and Tools

  • China Chopper
  • Etumbot:
  • Riptide:
  • Hightide:
  • ThreeByte:
  • Waterspout:
  • Mswab:
  • Gh0st:
  • ShowNews:
  • 3001:

MITRE ATT&CK Software

Attribution and Evidence

Country of Origin: China Additional attribution information pending cataloguing.

References

[1] mitre-attack [7] Meyers Numbered Panda Meyers, A. (2013, March 29). Whois Numbered Panda. Retrieved January 14, 2016. [8] Moran 2014 Moran, N., Oppenheim, M., Engle, S., & Wartell, R.. (2014, September 3). Darwin’s Favorite APT Group [Blog]. Retrieved November 12, 2014.