Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors HikkI-Chan

Also known as: Anonchan, a person-to-person attacks, cpyy, APT3, Gothic Panda, UPS Team, TG-0110, DeputyDog, Parastoo, Newscaster, APT28, Pawn Storm, Fancy Bear, Sednit, MiniDionis, Hammertoss, Chinastrats, Patchwork

Description

HikkI‑Chan has surfaced in open‑source threat reports under a profusion of aliases—including Anonchan, Gothaic Panda, APT3, Forked “DeputyDog” operations, and the notorious Fancy Bear moniker—making attribution challenging. The actor publicly claimed responsibility for multiple data exfiltration incidents, the most prominent being the compromise of 390.4 million VKontakte user accounts and the breach of Israel’s Ministry of Welfare that yielded over 457,000 records. Additional reported intrusions involve Strong Current Enterprises and a Florida Office of Financial Regulation, spilling sensitive information across several industries. Technical footprints indicate HikkI‑Chan leverages spear‑phishing via compromised Microsoft Word documents exploiting the EPS dictionary use‑after‑free vulnerability (linked to CVE‑2015‑1701). Delivery mechanisms include the IRONHALO downloader or the ELMER backdoor, which persistently establish remote control capabilities. The actor is also associated with well‑known RAT families such as PlugX and Ghost RAT, and has been linked—though not conclusively—to ransomware families like DarkSide. Operating across a geopolitical landscape that spans the United States, China, Europe, the Middle East, and South Asia, HikkI‑Chan’s methodology reflects a blend of classic social engineering and zero‑day exploitation. The group is believed to maintain staging hosts in cheap or “bulletproof” infrastructure, often using rapidly rotating domain names (e.g., TEMP.*). Their attacks aim largely at intelligence gathering rather than financial gain or destructive sabotage.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Non profit
Telecommunications
Healthcare
Manufacturing
Energy
Aerospace
Media
Maritime
Education
Food agriculture
Information technology
Think tank
Nuclear
Chemical
Mining
Pharmaceutical
Transportation
Construction
Hospitality
Legal services
Entertainment

Targeted Countries / Regions

US
CN
GB
IN
JP
DE
IR
KR
IL
RU
SA
FR
TW
TR
CA
AU
KZ
PK
VN
UA
PL
AE
SY
SG
NL
BR
ES
IQ
BY
AZ
IT
MX
RO
NG
LB
KP
EG

AI Analysis

Grounded in web research
· 21 hours ago

Executive Summary

HikkI‑Chan, a pseudonymous actor claiming responsibility for several high‑profile data breaches—most notably over 390 million VKontakte users and Israeli Ministry of Welfare records—appears to target broad government, defense, financial and critical infrastructure sectors worldwide. The group employs spear‑phishing with malicious Word documents to deliver custom RATs such as PlugX and Ghost RAT, coupled with known vulnerabilities (e.g., CVE‑2015‑1701) for privilege escalation. Their activity suggests a focus on espionage rather than destructive motives.

Goals & Targeting

The actor’s primary motivation is espionage, targeting government agencies, defense contractors, financial institutions, and critical infrastructure providers across a diverse array of countries—including the US, CN, GB, IN, JP, DE, IR, KR, IL, RU—and strategic sectors from energy to aerospace. By compromising these high‑profile targets, HikkI‑Chan seeks to harvest intellectual property, policy documents, personnel data, and other sensitive material that could be leveraged for geopolitical advantage or sold on intelligence markets. Typical victims are medium to large organizations with complex IT ecosystems and a mix of internal employee accounts accessible via spear‑phishing campaigns. Key capabilities

Enhanced Description

Key Capabilities

  • Spear‑phishing using malicious Microsoft Office documents
  • Exploitation of Windows privilege escalation vulnerabilities (e.g., CVE‑2015‑1701)
  • Deployment of custom RATs (PlugX, Ghost RAT, IRONHALO downloader, ELMER backdoor)
  • Persistence via credential harvesting and rootkit installation
  • Data exfiltration over command‑and‑control channels using fast‑flux domains
  • Use of bulletproof hosting for staging infrastructure

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Credential Access
Discovery
Collection
Exfiltration
Command and Control
Defense Evasion

ATT&CK Techniques

T1566.001
T1204
T1059.003
T1068
T1070
T1087
T1041
T1095

Software / Tooling

PlugX
Ghost RAT
IRONHALO
ELMER
DarkSide
Cobalt Strike (possible link)

Campaigns & Victims

HikkI‑Chan’s operations exhibit a high degree of sophistication in both social engineering and technical exploitation, with evidence spanning campaigns from at least 2015 through the early 2020s. The group consistently targets large organizations across varied geographies using spear‑phishing vectors that deliver custom backdoors, then moves laterally to key data stores before exfiltration. Their pattern of rapidly rotating domains and use of known vulnerabilities suggests a modular, reusable toolset that enables rapid reassessment and redeployment. IOC patterns

IOC Patterns

  • Spearfishing via malicious Microsoft Word documents exploiting CVE‑2015‑1701 (EPS dictionary use‑after‑free) leading to IRONHALO/Emerger backdoors
  • Rapidly rotating or random domain names (e.g., TEMP.*, Cyber.Anarchy.Squad) used for command and control
  • Use of bulletproof hosting and fast‑flux DNS techniques

Recommended Actions

  • Patch all Windows systems against CVE‑2015‑1701 and similar privilege escalation exploits
  • Implement robust email filtering and attachment sandboxing to detect malicious Office documents
  • Deploy endpoint detection and response (EDR) solutions capable of detecting PlugX, Ghost RAT signatures
  • Enforce multi‑factor authentication for privileged accounts to limit lateral movement
  • Establish network segmentation between critical infrastructure segments and general corporate networks
  • Regularly audit access logs for anomalous downloads or executables and monitor outbound traffic for unusual connections to unfamiliar domains

Suggested Tags

APT
cyberespionage
data exfiltration
critical infrastructure
government targeting
Russia-linked actors
China-linked actors

Confidence Assessment

The analysis is based largely on archived open‑source reports, third‑party threat intelligence, and a sparse set of documented incidents. There are significant uncertainties regarding the true identity of HikkI‑Chan—many aliases appear to refer to disparate groups—and no recent confirmations of activity beyond legacy incidents. While technical footprints (spear‑phishing, vulnerability exploitation, RAT deployment) are corroborated by multiple sources, attribution remains speculative and may overlap with other APT factions. Consequently, confidence in the specific operational tactics and tools is moderate; gaps include lack of up‑to‑date IOC datasets, unclear lineage between aliases, and limited evidence of current campaign activity.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Intel Summary

8

Techniques

46

Tools

0

Campaigns

40

IOCs

0

Observed Data

7

Tactics

Tags

Data Exfiltration
Government Targeting
APT
Data breach
Espionage
Social media
Government
FinTech
cyberespionage
data exfiltration
critical infrastructure
government targeting
Russia-linked actors
China-linked actors

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.