CNChinaconfidence: 50G0005

APT12APT12

Also known as: NUMBERED PANDA · TG-2754 · BeeBus · Group 22 · DynCalc · Calc Team · DNSCalc · Crimson Iron · IXESHE · BRONZE GLOBE · Hexagon Typhoon · APT12

Origin
CN
Known aliases
12
Target sectors
2
Attribution
State-sponsored

Profile

APT12 is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as NUMBERED PANDA, TG-2754, BeeBus (and 8 more). Operational targeting focuses on the Private sector and Government sectors. Documented victim organisations include Taiwan, Japan. Original record: A group of China-based attackers, who conducted a number of spear phishing attacks in 2013.

Aliases· 12

NUMBERED PANDATG-2754BeeBusGroup 22DynCalcCalc TeamDNSCalcCrimson IronIXESHEBRONZE GLOBEHexagon TyphoonAPT12

Target sectors· 2

Private sectorGovernment

Known victims· 2

  • Taiwan
  • Japan

MITRE ATT&CK Group crosswalk

G0005

References

  1. http://www.crowdstrike.com/blog/whois-numbered-panda/
  2. https://www.cfr.org/interactive/cyber-operations/apt-12
  3. https://www.fireeye.com/blog/threat-research/2014/09/darwins-favorite-apt-group-2.html
  4. https://www.secureworks.com/research/threat-profiles/bronze-globe
  5. https://www.mandiant.com/resources/insights/apt-groups

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
APT21
Actor
APT4
Actor
APT24
Actor
APT-C-12
Actor
APT26
Actor
APT15
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.