Also known as: Anonchan, a person-to-person attacks, cpyy, APT3, Gothic Panda, UPS Team, TG-0110, DeputyDog, Parastoo, Newscaster, APT28, Pawn Storm, Fancy Bear, Sednit, MiniDionis, Hammertoss, Chinastrats, Patchwork
HikkI‑Chan has surfaced in open‑source threat reports under a profusion of aliases—including Anonchan, Gothaic Panda, APT3, Forked “DeputyDog” operations, and the notorious Fancy Bear moniker—making attribution challenging. The actor publicly claimed responsibility for multiple data exfiltration incidents, the most prominent being the compromise of 390.4 million VKontakte user accounts and the breach of Israel’s Ministry of Welfare that yielded over 457,000 records. Additional reported intrusions involve Strong Current Enterprises and a Florida Office of Financial Regulation, spilling sensitive information across several industries. Technical footprints indicate HikkI‑Chan leverages spear‑phishing via compromised Microsoft Word documents exploiting the EPS dictionary use‑after‑free vulnerability (linked to CVE‑2015‑1701). Delivery mechanisms include the IRONHALO downloader or the ELMER backdoor, which persistently establish remote control capabilities. The actor is also associated with well‑known RAT families such as PlugX and Ghost RAT, and has been linked—though not conclusively—to ransomware families like DarkSide. Operating across a geopolitical landscape that spans the United States, China, Europe, the Middle East, and South Asia, HikkI‑Chan’s methodology reflects a blend of classic social engineering and zero‑day exploitation. The group is believed to maintain staging hosts in cheap or “bulletproof” infrastructure, often using rapidly rotating domain names (e.g., TEMP.*). Their attacks aim largely at intelligence gathering rather than financial gain or destructive sabotage.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
HikkI‑Chan, a pseudonymous actor claiming responsibility for several high‑profile data breaches—most notably over 390 million VKontakte users and Israeli Ministry of Welfare records—appears to target broad government, defense, financial and critical infrastructure sectors worldwide. The group employs spear‑phishing with malicious Word documents to deliver custom RATs such as PlugX and Ghost RAT, coupled with known vulnerabilities (e.g., CVE‑2015‑1701) for privilege escalation. Their activity suggests a focus on espionage rather than destructive motives.
Goals & Targeting
The actor’s primary motivation is espionage, targeting government agencies, defense contractors, financial institutions, and critical infrastructure providers across a diverse array of countries—including the US, CN, GB, IN, JP, DE, IR, KR, IL, RU—and strategic sectors from energy to aerospace. By compromising these high‑profile targets, HikkI‑Chan seeks to harvest intellectual property, policy documents, personnel data, and other sensitive material that could be leveraged for geopolitical advantage or sold on intelligence markets. Typical victims are medium to large organizations with complex IT ecosystems and a mix of internal employee accounts accessible via spear‑phishing campaigns. Key capabilities
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
HikkI‑Chan’s operations exhibit a high degree of sophistication in both social engineering and technical exploitation, with evidence spanning campaigns from at least 2015 through the early 2020s. The group consistently targets large organizations across varied geographies using spear‑phishing vectors that deliver custom backdoors, then moves laterally to key data stores before exfiltration. Their pattern of rapidly rotating domains and use of known vulnerabilities suggests a modular, reusable toolset that enables rapid reassessment and redeployment. IOC patterns
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based largely on archived open‑source reports, third‑party threat intelligence, and a sparse set of documented incidents. There are significant uncertainties regarding the true identity of HikkI‑Chan—many aliases appear to refer to disparate groups—and no recent confirmations of activity beyond legacy incidents. While technical footprints (spear‑phishing, vulnerability exploitation, RAT deployment) are corroborated by multiple sources, attribution remains speculative and may overlap with other APT factions. Consequently, confidence in the specific operational tactics and tools is moderate; gaps include lack of up‑to‑date IOC datasets, unclear lineage between aliases, and limited evidence of current campaign activity.
No campaigns linked yet.
No observed data linked yet.
8
Techniques
46
Tools
0
Campaigns
40
IOCs
0
Observed Data
7
Tactics