Introduction
Naikon is assessed to be a state-sponsored cyber espionage group attributed to the Chinese Peopleβs Liberation Armyβs (PLA) Chengdu Military Region Second Technical Reconnaissance Bureau (Military Unit Cover Designator 78020). CameraShy Active since at least 2010, Naikon has primarily conducted operations against government, military, and civil organizations in Southeast Asia, as well as against international bodies such as the United Nations Development Programme (UNDP) and the Association of Southeast Asian Nations (ASEAN). CameraShy Baumgartner Naikon 2015 While Naikon shares some characteristics with APT30, the two groups do not appear to be exact matches. Baumgartner Golovkin Naikon 2015
Activities and Tactics
Targeted Sectors: Government, Private sector
Country of Origin: π¨π³ China
Risk Level: High
First Seen: 2015
Last Activity: 2015
Incident Type: Espionage
Suspected Victims: India, Saudi Arabia, Vietnam, Myanmar, Singapore, Thailand, Malaysia, Cambodia, China, Philippinesβ¦
Notable Campaigns
- MsnMM
- Naikon
- Camera Shy
Tactics, Techniques, and Procedures (TTPs)
- T1078.002 Domain Accounts
- T1018 Remote System Discovery
- T1547.001 Registry Run Keys / Startup Folder
- T1518.001 Security Software Discovery
- T1046 Network Service Discovery
- T1047 Windows Management Instrumentation
- T1137.006 Add-ins
- T1016 System Network Configuration Discovery
- T1036.005 Match Legitimate Resource Name or Location
- T1566.001 Spearphishing Attachment
- T1036.004 Masquerade Task or Service
- T1053.005 Scheduled Task
- T1204.002 Malicious File
- T1574.001 DLL
ATT&CK technique IDs (denormalized)
- T1016
- T1018
- T1036.004
- T1036.005
- T1046
- T1047
- T1053.005
- T1078.002
- T1137.006
- T1204.002
- T1518.001
- T1547.001
- T1566.001
- T1574.001
Notable Indicators of Compromise (IOCs)
No atomic indicators are listed in this profile. The APTnotes snapshot indexes 1 public reports that may contain IOCs; see Source Attribution for dataset links.
Malware and Tools
- RARSTONE:
- BACKSPACe:
- NETEAGLE:
- XSControl:
MITRE ATT&CK Software
- ftp (S0095) β tool
- Net (S0039) β tool
- Ping (S0097) β tool
- netsh (S0108) β tool
- WinMM (S0059) β malware
- Systeminfo (S0096) β tool
- RainyDay (S0629) β malware
- Nebulae (S0630) β malware
- RARSTONE (S0055) β malware
- HDoor (S0061) β malware
- Sys10 (S0060) β malware
- SslMM (S0058) β malware
- PsExec (S0029) β tool
- Tasklist (S0057) β tool
- Aria-body (S0456) β malware
Attribution and Evidence
Country of Origin: China Additional attribution information pending cataloguing.
References
[1] mitre-attack [3] CameraShy ThreatConnect Inc. and Defense Group Inc. (DGI). (2015, September 23). Project CameraShy: Closing the Aperture on Chinaβs Unit 78020. Retrieved December 17, 2015. [4] Baumgartner Naikon 2015 Baumgartner, K., Golovkin, M.. (2015, May). The MsnMM Campaigns: The Earliest Naikon APT Campaigns. Retrieved April 10, 2019. [5] Baumgartner Golovkin Naikon 2015 Baumgartner, K., Golovkin, M.. (2015, May 14). The Naikon APT. Retrieved January 14, 2015.