APT16APT16

Also known as: APT16 · SVCMONDR · G0023

Known aliases
3

Profile

Between November 26, 2015, and December 1, 2015, known and suspected China-based APT groups launched several spear-phishing attacks targeting Japanese and Taiwanese organizations in the high-tech, government services, media and financial services industries. Each campaign delivered a malicious Microsoft Word document exploiting the aforementioned EPS dict copy use-after-free vulnerability, and the local Windows privilege escalation vulnerability CVE-2015-1701. The successful exploitation of both vulnerabilities led to the delivery of either a downloader that we refer to as IRONHALO, or a backdoor that we refer to as ELMER.

Aliases· 3

APT16SVCMONDR
G0023

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
APT15
Actor
APT17
Actor
APT31
Actor
APT27
Actor
APT21
Actor
APT4
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.