APT12
A group of China-based attackers, who conducted a number of spear phishing attacks in 2013.
APT12 is a China-based cyberespionage group targeting government and private sector entities in Taiwan and Japan.
APT12, also known as NUMBERED PANDA, is a China-based nation-state cyber espionage group. It primarily targets private sector and government organizations in Taiwan and Japan. Key TTPs include Spearphishing Attachment for initial access, DNS Calculation for C2, and usage of malware like IXESHE and RIPTIDE along with the HTRAN tool. Defenders should focus on scrutinizing email attachments for phishing, monitoring for anomalous DNS traffic, and strengthening controls against these specific execution and C2 techniques.
A group of China-based attackers, who conducted a number of spear phishing attacks in 2013.
Monitor email attachments for suspicious content and educate users about spearphishing tactics.
Monitor for exploitation attempts against client applications and ensure that files executed on the system are benign.
Monitor network traffic for unusual bidirectional communication patterns and analyze DNS queries for potential C2 communication encoded within DNS calculations.
APT12 uses Spearphishing Attachment for initial access.
APT12 primarily targets private sector and government organizations in Taiwan and Japan.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.