APT12

G0005

Threat group.View on attack.mitre.org

About this group

APT12 is a threat group that has been attributed to China. The group has targeted a variety of victims including but not limited to media outlets, high-tech companies, and multiple governments.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1102.002
Bidirectional Communication

APT12 has used blogs and WordPress for C2 infrastructure.

T1203
Exploitation for Client Execution

APT12 has exploited multiple vulnerabilities for execution, including Microsoft Office vulnerabilities (CVE-2009-3129, CVE-2012-0158) and vulnerabilities in Adobe Reader and Flash (CVE-2009-4324, CVE-2009-0927, CVE-2011-0609, CVE-2011-0611).

T1204.002
Malicious File

APT12 has attempted to get victims to open malicious Microsoft Word and PDF attachment sent via spearphishing.

T1566.001
Spearphishing Attachment

APT12 has sent emails with malicious Microsoft Office documents and PDFs attached.

T1568.003
DNS Calculation

APT12 has used multiple variants of DNS Calculation including multiplying the first two octets of an IP address and adding the third octet to that value in order to get a resulting command and control port.

Software3

Campaigns0

None recorded.

References1

  1. Meyers Numbered Panda Open source
    Meyers, A. (2013, March 29). Whois Numbered Panda. Retrieved January 14, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.