APT12
Also reported as Calc Team, Hexagon Typhoon, IXESHE, DynCalc, BeeBus and 16 other names. Linked to China by four sources.
Reports per quarter
Techniques seen in the last two years
- T1190 3 reports reports only
- T1027 2 reports reports only
- T1041 2 reports reports only
- T1071.001 2 reports reports only
- T1071.003 2 reports reports only
- T1091 2 reports reports only
- T1114.002 2 reports reports only
- T1119 2 reports reports only
- T1203 2 reports in ATT&CK
- T1566.001 2 reports in ATT&CK
Show all 112 techniques Show fewer
- T1566.002 2 reports reports only
- T1583.001 2 reports reports only
- T1001.001 1 report reports only
- T1003 1 report reports only
- T1003.001 1 report reports only
- T1003.003 1 report reports only
- T1005 1 report reports only
- T1014 1 report reports only
- T1020 1 report reports only
- T1021.002 1 report reports only
- T1025 1 report reports only
- T1030 1 report reports only
- T1036 1 report reports only
- T1036.005 1 report reports only
- T1037.001 1 report reports only
- T1039 1 report reports only
- T1040 1 report reports only
- T1046 1 report reports only
- T1048.002 1 report reports only
- T1053 1 report reports only
- T1056.001 1 report reports only
- T1056.003 1 report reports only
- T1057 1 report reports only
- T1059 1 report reports only
- T1059.001 1 report reports only
- T1059.003 1 report reports only
- T1068 1 report reports only
- T1070 1 report reports only
- T1070.004 1 report reports only
- T1070.006 1 report reports only
- T1074.001 1 report reports only
- T1074.002 1 report reports only
- T1078 1 report reports only
- T1078.004 1 report reports only
- T1082 1 report reports only
- T1083 1 report reports only
- T1087.003 1 report reports only
- T1090 1 report reports only
- T1090.002 1 report reports only
- T1090.003 1 report reports only
- T1092 1 report reports only
- T1098 1 report reports only
- T1098.002 1 report reports only
- T1102 1 report reports only
- T1102.002 1 report in ATT&CK
- T1105 1 report reports only
- T1110 1 report reports only
- T1110.001 1 report reports only
- T1110.003 1 report reports only
- T1113 1 report reports only
- T1114.003 1 report reports only
- T1120 1 report reports only
- T1132.001 1 report reports only
- T1133 1 report reports only
- T1134.001 1 report reports only
- T1137.002 1 report reports only
- T1140 1 report reports only
- T1187 1 report reports only
- T1189 1 report reports only
- T1195 1 report reports only
- T1199 1 report reports only
- T1204 1 report reports only
- T1204.001 1 report reports only
- T1204.002 1 report in ATT&CK
- T1210 1 report reports only
- T1211 1 report reports only
- T1213 1 report reports only
- T1213.002 1 report reports only
- T1218.011 1 report reports only
- T1221 1 report reports only
- T1498 1 report reports only
- T1505.003 1 report reports only
- T1528 1 report reports only
- T1542.003 1 report reports only
- T1546.015 1 report reports only
- T1547 1 report reports only
- T1547.001 1 report reports only
- T1550.001 1 report reports only
- T1550.002 1 report reports only
- T1556.006 1 report reports only
- T1557 1 report reports only
- T1559.002 1 report reports only
- T1560 1 report reports only
- T1560.001 1 report reports only
- T1564.001 1 report reports only
- T1564.003 1 report reports only
- T1564.004 1 report reports only
- T1566.003 1 report reports only
- T1567 1 report reports only
- T1567.002 1 report reports only
- T1573.001 1 report reports only
- T1583.004 1 report reports only
- T1583.006 1 report reports only
- T1586.002 1 report reports only
- T1587.001 1 report reports only
- T1587.004 1 report reports only
- T1588.002 1 report reports only
- T1589.001 1 report reports only
- T1595.002 1 report reports only
- T1598 1 report reports only
- T1598.003 1 report reports only
- T1659 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2009-0927 KEV
- CVE-2009-09274
- CVE-2009-3129 KEV
- CVE-2009-4324 KEV
- CVE-2009-43243
- CVE-2010-0188 KEV ransomware
- CVE-2010-1297 KEV
- CVE-2010-2883 KEV
- CVE-2010-3333 KEV
- CVE-2011-0609 KEV
- CVE-2011-06095
- CVE-2011-06098
Show all 55 CVEs Show fewer
- CVE-2011-0611 KEV
- CVE-2011-06116
- CVE-2011-2462 KEV
- CVE-2012-0158 KEV ransomware
- CVE-2012-0507 KEV ransomware
- CVE-2012-1856 KEV
- CVE-2012-1889 KEV
- CVE-2012-2543
- CVE-2013-0640 KEV
- CVE-2013-2729 KEV
- CVE-2013-5990
- CVE-2014-0322 KEV
- CVE-2014-1761 KEV
- CVE-2015-0116
- CVE-2015-1701 KEV ransomware
- CVE-2015-2424 KEV
- CVE-2015-2545 KEV
- CVE-2015-2590 KEV
- CVE-2015-3043 KEV
- CVE-2015-5119 KEV
- CVE-2015-5122 KEV
- CVE-2015-6585
- CVE-2015-7645 KEV ransomware
- CVE-2016-0189 KEV ransomware
- CVE-2017-0144 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-0262 KEV
- CVE-2017-11292 KEV
- CVE-2017-11882 KEV ransomware
- CVE-2017-8759 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2020-35730 KEV
- CVE-2021-22941 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2023-20085
- CVE-2023-23397 KEV
- CVE-2023-36884 KEV ransomware
- CVE-2023-38831 KEV ransomware
- CVE-2023-43770 KEV
- CVE-2024-11182 KEV
- CVE-2024-27443 KEV
- CVE-2024-49039 KEV ransomware
- CVE-2024-9680 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
CrowdCasts Monthly: You Have an Adversary Problem
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CrowdCasts Monthly: You Have an Adversary Problem
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Numbered Panda
-
APT 12, Numbered Panda - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor APT 12, Numbered Panda - Threat Group Cards: A Threat Actor Encyclopedia
-
Survival of the Fittest: New York Times Attackers Evolve Quickly
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Survival of the Fittest: New York Times Attackers Evolve Quickly
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation-Blockbuster-Report
Show all 66 reports Show fewer
-
The Rise of Earth Aughisky: Tracking the Campaigns Taidoor Started
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Rise of Earth Aughisky: Tracking the Campaigns Taidoor Started
-
Advanced Persistent Threats (APTs)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threats (APTs)
-
Advanced Persistent Threats (APTs)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threats (APTs)
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese State-Sponsored Activity Group TAG-22 Targets Nepal, the Philippines, and Taiwan Using Winnti and Other Tooling
-
Advanced Persistent Threat Groups
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threat Groups
-
Cisco's Talos Intelligence Group Blog: KONNI: A Malware Under The Radar For Years
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Cisco's Talos Intelligence Group Blog: KONNI: A Malware Under The Radar For Years
-
CNACOM - Open Source Exploitation via Strategic Web Compromise
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor CNACOM - Open Source Exploitation via Strategic Web Compromise
-
ICIT-Brief-China-Espionage-Dynasty
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ICIT-Brief-China-Espionage-Dynasty
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Please Read
-
In The Wild- Mobile Malware Implements New Features
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor In The Wild- Mobile Malware Implements New Features
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor TrendLabs Security Intelligence BlogIXESHE Derivative IHEATE Targets Users in America - TrendLabs Security Intelligence Blog
-
IXESHE Derivative IHEATE Targets Users in America
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor IXESHE Derivative IHEATE Targets Users in America
-
Cisco Talos Blog: Research Spotlight: Needles in a Haystack
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Cisco Talos Blog: Research Spotlight: Needles in a Haystack
-
The Mutter Backdoor: Operation Beebus with New Targets
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor The Mutter Backdoor: Operation Beebus with New Targets
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Operation Beebus
-
RESEARCH SPOTLIGHT: NEEDLES IN A HAYSTACK
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor RESEARCH SPOTLIGHT: NEEDLES IN A HAYSTACK
-
Taiwan Presidential Election: A Case Study on Thematic Targeting - Cyber security updates
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Taiwan Presidential Election: A Case Study on Thematic Targeting - Cyber security updates
-
Taiwan Presidential Election: A Case Study on Thematic Targeting
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Taiwan Presidential Election: A Case Study on Thematic Targeting
-
Operation-Blockbuster-Loaders-Installers-and-Uninstallers-Report
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation-Blockbuster-Loaders-Installers-and-Uninstallers-Report
-
Operation-Blockbuster-Tools-Report
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation-Blockbuster-Tools-Report
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Operation Blockbuster
-
Operation-Blockbuster-Destructive-Malware-Report
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation-Blockbuster-Destructive-Malware-Report
-
Operation-Blockbuster-RAT-and-Staging-Report
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation-Blockbuster-RAT-and-Staging-Report
-
Dissecting the Malware Involved in the INOCNATION Campaign
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Dissecting the Malware Involved in the INOCNATION Campaign
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor HTExploitTelemetry
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Darwin’s Favorite APT Group
-
Darwin’s Favorite APT Group | FireEye Blog
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Darwin’s Favorite APT Group | FireEye Blog
-
WORLD WAR C : Understanding Nation-State Motives Behind Today’s Advanced Cyber Attacks
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor WORLD WAR C : Understanding Nation-State Motives Behind Today’s Advanced Cyber Attacks
-
Survival of the Fittest: New York Times Attackers Evolve Quickly | FireEye Blog
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Survival of the Fittest: New York Times Attackers Evolve Quickly | FireEye Blog
-
Targeted Threat Index: Characterizing And Quantifying Politically-Motivated Targeted Malware
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Targeted Threat Index: Characterizing And Quantifying Politically-Motivated Targeted Malware
-
Microsoft Word - ASERT Threat Intelligence Brief 2014-07 Illuminating Etumbot APT.docx
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft Word - ASERT Threat Intelligence Brief 2014-07 Illuminating Etumbot APT.docx
-
Iran and Russia blamed for state-sponsored espionage
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iran and Russia blamed for state-sponsored espionage
-
Iran and Russia blamed for statesponsored espionage
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Iran and Russia blamed for statesponsored espionage
-
Iran and Russia blamed for state-sponsored espionage
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Iran and Russia blamed for state-sponsored espionage
-
World War C: Understanding Nation-State Motives Behind Today's Advanced Cyber Attacks
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor World War C: Understanding Nation-State Motives Behind Today's Advanced Cyber Attacks
-
CrowdCasts Monthly- You Have an Adversary Problem
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor CrowdCasts Monthly- You Have an Adversary Problem
-
CrowdCasts Monthly: You Have an Adversary Problem
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CrowdCasts Monthly: You Have an Adversary Problem
-
2Q Report on Targeted Attack Campaigns
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2Q Report on Targeted Attack Campaigns
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Who is Samurai Panda
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Who is Clever Kitten
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Whois Numbered Panda
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor IXESHE: An APT Campaign
Newest first. Details opens the report in Explore.