CNChinaconfidence: 50G0023
APT16APT16
Also known as: SVCMONDR · G0023 · APT16
Origin
CN
Known aliases
3
Target sectors
1
Attribution
State-sponsored
Profile
Between November 26, 2015, and December 1, 2015, known and suspected China-based APT groups launched several spear-phishing attacks targeting Japanese and Taiwanese organizations in the high-tech, government services, media and financial services industries. Each campaign delivered a malicious Microsoft Word document exploiting the aforementioned EPS dict copy use-after-free vulnerability, and the local Windows privilege escalation vulnerability CVE-2015-1701. The successful exploitation of both vulnerabilities led to the delivery of either a downloader that we refer to as IRONHALO, or a backdoor that we refer to as ELMER.
Aliases· 3
SVCMONDRAPT16
Target sectors· 1
Private sector
Known victims· 2
- Japan
- Taiwan
MITRE ATT&CK Group crosswalk
References
- https://www.fireeye.com/blog/threat-research/2015/12/the_eps_awakens.html
- https://www.cfr.org/interactive/cyber-operations/apt-16
- https://attack.mitre.org/groups/G0023
- https://www.mandiant.com/resources/insights/apt-groups
- https://securelist.com/analysis/publications/74828/cve-2015-2545-overview-of-current-threats/
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.