APT15
This threat actor uses phishing techniques to compromise the networks of foreign ministries of European countries for espionage purposes.
APT15 (VIXEN PANDA) is a China-based cyber espionage group primarily targeting government entities in the EU and India.
APT15, also known as VIXEN PANDA, is a China-based nation-state cyber espionage group. It primarily targets government and administration entities in the European Union, India, the United Kingdom, and Germany. Key TTPs include phishing for initial access, lateral movement via SMB/Windows Admin Shares, credential access using Mimikatz and Golden Ticket, and DNS for C2 communication. Defenders should prioritize monitoring for exploitation of external remote services, anomalous DNS traffic, and the presence of malware such as Okrum, MirageFox, or Neoichor.
This threat actor uses phishing techniques to compromise the networks of foreign ministries of European countries for espionage purposes.
Monitor suspicious online activities to acquire tools and block suspicious downloads.
Harden public-facing applications and monitor network traffic to detect exploit attempts.
Monitor service execution and investigate suspicious service creations or modifications.
Restrict access to External Remote Services and monitor for suspicious connections.
Monitor for suspicious file names and locations and deobfuscate encoded files.
Restrict access to the SAM database and monitor for suspicious authentication attempts, detect Golden Ticket usage.
Monitor for suspicious queries that gather system owner/user information and detect local account discovery.
Restrict access to SMB/Windows Admin Shares and monitor for suspicious share access.
Monitor for suspicious activities that perform remote email collection and automated data collection.
Monitor for suspicious DNS queries and tool transfer, detect C2 traffic.
Detect exfiltration over C2 channel and monitor for suspicious network traffic.
APT15 uses SMB/Windows Admin Shares for lateral movement.
APT15 uses Mimikatz and Golden Ticket for credential access.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.