CNChinaconfidence: 50G0023

APT16APT16

Also known as: SVCMONDR · G0023 · APT16

Origin
CN
Known aliases
3
Target sectors
1
Attribution
State-sponsored

Profile

Between November 26, 2015, and December 1, 2015, known and suspected China-based APT groups launched several spear-phishing attacks targeting Japanese and Taiwanese organizations in the high-tech, government services, media and financial services industries. Each campaign delivered a malicious Microsoft Word document exploiting the aforementioned EPS dict copy use-after-free vulnerability, and the local Windows privilege escalation vulnerability CVE-2015-1701. The successful exploitation of both vulnerabilities led to the delivery of either a downloader that we refer to as IRONHALO, or a backdoor that we refer to as ELMER.

Aliases· 3

SVCMONDRAPT16
G0023

Target sectors· 1

Private sector

Known victims· 2

  • Japan
  • Taiwan

MITRE ATT&CK Group crosswalk

G0023

References

  1. https://www.fireeye.com/blog/threat-research/2015/12/the_eps_awakens.html
  2. https://www.cfr.org/interactive/cyber-operations/apt-16
  3. https://attack.mitre.org/groups/G0023
  4. https://www.mandiant.com/resources/insights/apt-groups
  5. https://securelist.com/analysis/publications/74828/cve-2015-2545-overview-of-current-threats/

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
APT15
Actor
APT17
Actor
APT31
Actor
APT4
Actor
APT27
Actor
APT18
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.