APT12, 3 Minute Profile
APT12,, currently inactive used spear phishing to deliver malware containing Etumbot, RIPTIDE, Mswab, Gh0st, ShowNews and other components.
fireeyeflare
seen from Croatia
seen from Russia
seen from China

seen from United States

seen from France
seen from China
seen from Australia

seen from United Kingdom
seen from United States

seen from Malaysia

seen from Germany
seen from Germany

seen from United Kingdom

seen from Italy

seen from United Kingdom

seen from Germany
seen from China
seen from United States
seen from France
seen from United States
APT12, 3 Minute Profile
APT12,, currently inactive used spear phishing to deliver malware containing Etumbot, RIPTIDE, Mswab, Gh0st, ShowNews and other components.
fireeyeflare
Gothic Panda
Type: Nation-State-SponsoredAPT3 Status: Believed ActiveAPT3 Other Names: Gothic Panda/ UPS/ Pirpi/ Operation Clandestine Fox/ TG-0110/ BuckEye/ Group 6/ Operation Double Tap/ Operation Clandestine Wolf APT3 Target Sectors: energy sector, financial sector, technology industries, NGO/ International arena, aerospace and defense organizations, telecommunication companies, construction, high-tech, and transportation organizations Malware: Pirpi capable of gathering network adapter information, downloading files to memory, deleting files, listing directories, uploading files to the C2, executing processes, and other functionalities PlugX Kaba PluginDetect SHOTPUT backdoor (Backdoor APT CookieCutter) SportsLoader
apt3fireeye
Gothic Panda
Type: Nation-State-SponsoredAPT3 Status: Believed ActiveAPT3 Other Names: Gothic Panda/ UPS/ Pirpi/ Operation Clandestine Fox/ TG-0110/ BuckEye/ Group 6/ Operation Double Tap/ Operation Clandestine Wolf APT3 Target Sectors: energy sector, financial sector, technology industries, NGO/ International arena, aerospace and defense organizations, telecommunication companies, construction, high-tech, and transportation organizations Malware: Pirpi capable of gathering network adapter information, downloading files to memory, deleting files, listing directories, uploading files to the C2, executing processes, and other functionalities PlugX Kaba PluginDetect SHOTPUT backdoor (Backdoor APT CookieCutter) SportsLoader
operationclandestinefox
APT12, 3 Minute Profile
APT12,, currently inactive used spear phishing to deliver malware containing Etumbot, RIPTIDE, Mswab, Gh0st, ShowNews and other components.