Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Natohub

Also known as: tracked as, cpyy, APT3, Gothic Panda, UPS Team, DeputyDog, Parastoo, defense technology, military, diplomacy sectors, APT28, Pawn Storm, Fancy Bear, MiniDionis, Chinastrats, TG-0110, Newscaster, Sednit, Hammertoss, Patchwork

Description

Natohub is an espionage‑oriented threat actor that has been associated with several Chinese APT groups such as Buckeye (APT3), Gothic Panda, DarkHotel, and Chinastrats/Patchwork. Its publicly stated goal is to harvest sensitive information from international diplomatic entities, evidenced by a declared release of 42,000 documents allegedly stolen from the United Nations’ International Civil Aviation Organization. The actor’s technique portfolio mirrors that of its peers: spear‑phishing via malicious Microsoft Word and Flash attachments, exploitation of zero‑day and public vulnerabilities (e.g., CVE‑2015‑1701), delivery of downloader backdoors such as IRONHALO and ELMER, watering‑hole attacks targeting legitimate sites frequented by high‑value targets, and peer‑to‑peer spread to facilitate lateral movement. Once inside a target network, Natohub leverages toolsets that shift to maintain stealthy persistence and execute long‑term intelligence collection. These capabilities place Natohub within the broader ecosystem of Chinese state‑backed actors frequently cited in reports under the labels United Nations “APT3” or “Buckeye.” Its focus on international governance and defense structures aligns with a strategic interest in geopolitical influence and intelligence gathering, mirroring the operational profiles of groups like DarkHotel and Patchwork. The group’s reliance on both zero‑day exploits and well‑known CVEs reflects an adaptable approach that balances speed of compromise with stealth. The threat actor’s impact extends beyond data theft; by exposing personal records of ICAO staff and alleged UN delegates, Natohub seeks to generate reputational pressure or leverage in diplomatic arenas. This high‑profile narrative amplifies its perceived sophistication but also calls for scrutiny given the limited independent verification of the claimed breach. Overall, Natohub exemplifies a sophisticated state‑aligned threat actor that leverages advanced credential phishing, exploitation, and lateral movement techniques to conduct long‑term espionage against critical political and diplomatic targets worldwide.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Non profit
Telecommunications
Aviation
Aerospace
Energy
Media
Education
Information technology
Maritime
Manufacturing
Think tank
Healthcare
Pharmaceutical
Chemical
Mining
Critical infrastructure
Hospitality
Legal services
Nuclear
Entertainment

Targeted Countries / Regions

US
CN
GB
IN
JP
DE
IR
KR
CA
RU
SA
TW
IL
FR
TR
AU
KZ
PK
VN
ES
UA
PL
AE
SG
NL
BR
IQ
BY
IT
SY
MX
RO
EG
AZ

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 2 days ago

Executive Summary

Natohub is a suspected espionage actor linked to Chinese APT collectives that primarily target government and diplomatic organizations worldwide. It employs spear‑phishing malware attachments exploiting known CVEs and watering‑hole sites to deliver backdoors such as IRONHALO and ELMER, followed by peer‑to‑peer lateral movement and rapid data exfiltration. While publicly claiming a large UN leak, the actor’s verifiable track record remains limited.

Goals & Targeting

Natohub’s strategic objective is sustained intelligence harvesting on global governance, defense, and diplomacy sectors. By compromising high‑profile organizations—particularly within the UN system—it aims to gather sensitive personal data and internal communications that can be leveraged for influence operations or as bargaining chips in geopolitical negotiations. The actor prioritizes low‑visibility infiltration and rapid exfiltration, thereby minimizing detection while maximizing intelligence value. Its targeting profile spans numerous countries, including the US, China, UK, India, Japan, Germany, Israel, Russia, and others, with a particular emphasis on entities involved in international security and policy. This widespread scope signals an intent to accumulate a broad knowledge base about global diplomatic priorities and defense postures rather than focusing on a single nation-state. The long‑term nature of its operations—evidenced by repeated use of peer‑to‑peer lateral tools and persistent backdoors—suggests that Natohub does not merely aim for a one‑off data dump but seeks to maintain covert read‑write access across multiple systems over extended periods.

Enhanced Description

Key Capabilities

  • spear‑phishing for initial access
  • cyber espionage against political entities
  • targeted attacks on organizations in Japan and Hong Kong
  • spear‑phishing with malicious Word documents
  • exploitation of zero‑day and known vulnerabilities (e.g., Flash, Windows, Adobe)
  • delivery of downloader or backdoor payloads such as IRONHALO and ELMER
  • local privilege escalation via CVE-2015-1701
  • watering hole attacks on legitimate websites frequented by target organizations
  • peer‑to‑peer spreading tactics for lateral movement
  • rapid break‑in and data exfiltration
  • toolset switching for stealthy persistence
  • long‑term intelligence gathering

MITRE ATT&CK Tactics

Initial Access
Execution
Privilege Escalation
Defense Evasion
Persistence
Exfiltration

ATT&CK Techniques

T1566.001
T1203
T1068
T1189

Software / Tooling

SUNBURST
Lumma Stealer
CHINACHOPPER
Buckeye
IRONHALO
ELMER
MiniDuke
CosmicDuke
OnionDuke
CozyDuke
CloudDuke
SeaDuke
HammerDuke
PinchDuke
GeminiDuke
Crimson
Anchor
Shamoon
Shark
Samurai
DEADEYE
Mythic
Sednit
Turla
Cobalt
Mirage
VICEROY
Matrix
Dark
Nexus
Poseidon
Tsunami
Predator
Buhtrap

Campaigns & Victims

Natohub’s known or suspected campaigns exhibit a pattern of initiating attacks through spear‑phishing with malicious Microsoft Word documents that exploit well‑known CVEs, followed by drive‑by watering hole compromise of legitimate sites frequented by targeted sectors. The actor consistently deploys downloader backdoors such as IRONHALO and more advanced persistence tools like ELMER and the Duo‑Duke family. Once inside the network, Natohub often elevates privileges using local exploits (e.g., CVE-2015‑1701) and spreads laterally via peer‑to‑peer mechanisms. Operational tempo appears sustained, with evidence of both rapid break‑in scenarios and long‑term covert presence. Victim types are primarily government, defense, diplomatic, and international organization entities across a broad geographical footprint (US, China, UK, India, Japan, Germany, Israel, Russia). Notable past operations include the claimed UN ICAO data leak and similar spear‑phishing campaigns attributed to Buckeye/APT3 and DarkHotel targeting high‑value diplomatic targets. The actor’s toolset shows close alignment with other state‑aligned Chinese APTs (e.g., Chinastrats, Patchwork), suggesting either a single unified group or converging operational templates. While many specific attacks remain unverified publicly, the documented patterns and tool signatures indicate that Natohub operates as part of a larger adversarial ecosystem focused on geopolitical espionage. IOC_patterns: - Vulnerability exploitation (CVE identifiers) - Watering hole compromised domain names

IOC Patterns

  • Vulnerability exploitation (CVE identifiers)
  • Watering hole compromised domain names

Recommended Actions

  • Patch Windows, Adobe Flash, and Office products to close known CVEs such as CVE-2015-1701
  • Implement strong email attachment filtering and conduct user awareness training against suspicious Word documents
  • Monitor web traffic for anomalous activity on legitimate sites frequented by target sectors
  • Deploy endpoint detection & response solutions to detect downloader and backdoor behaviors
  • Enforce application whitelisting and least privilege principles

Suggested Tags

APT3
Buckeye
China-based APT
Political Targeting
Spearphishing
Gothic Panda
DarkHotel
Zero-day exploit
Spear phishing attachment
Watering hole
Privilege escalation
Japan
Taiwan
APT28
The Dukes
Ghostware
Dropping Elephant
Chinastrats
Patchwork
Government Targets
Think Tanks
NATO

Confidence Assessment

The available data is derived largely from publicly claimed leaks and attribution statements that have not been independently corroborated. While the operational techniques, tool signatures, and sector focus align with known Chinese APT families, direct evidence linking Natohub to the specific ICAO breach remains sparse. Consequently confidence in the actor’s capabilities and exact targeting profile is moderate, but gaps persist regarding the veracity of claimed data dumps, concrete attribution markers, and precise timelines.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. misp-galaxy.org — Cited by web research for: cpyy
  2. https://malpedia.caad.fkie.fraunhofer.de/actors — Cited by AI analysis.
  3. https://malpedia.caad.fkie.fraunhofer.de/details/win.sunburst — Cited by AI analysis.
  4. https://techcrunch.com/2025/01/08/un-aviation-agency-co — Cited by AI analysis.
  5. https://etheses.bham.ac.uk/id/eprint/12297/1/McKenna2022PhD.pdf — Cited by AI analysis.
  6. https://malpedia.caad.fkie.fraunhofer.de/details/win.lumma — Cited by AI analysis.
  7. https://malpedia.caad.fkie.fraunhofer.de/details/win.chinachopper — Cited by AI analysis.
  8. https://securelist.com/analysis/publications/74828/cve-2015-2545-overview-of-current-threats/ — Cited by AI analysis.
  9. https://web.archive.org/web/20130924130243/https://www.fireeye.com/blog/technical/cyber-exploits/2013/09/operation-deputydog-zero-day-cve-2013-3893-attack-against-japanese-targets.html — Cited by AI analysis.
  10. https://blog.trendmicro.com/trendlabs-security-intelligence/more-than-a-dozen-obfuscated-apt33-botnets-used-for-extreme-narrow-targeting/ — Cited by AI analysis.
  11. https://aptnotes.malwareconfig.com/web/viewer.html?file=../APTnotes/2014/apt28.pdf — Cited by AI analysis.
  12. https://www.bleepingcomputer.com/news/security/microsoft-disrupts-apt28-hacking-campaign-aimed-at-us-midterm-elections/ — Cited by AI analysis.
  13. https://www.accenture.com/t20190213T141124Z__w__/us-en/_acnmedia/PDF-94/Accenture-SNAKEMACKEREL-Threat-Campaign-Likely-Targeting-NATO-Members-Defense-and-Military-Outlets.pdf — Cited by AI analysis.
  14. https://quointelligence.eu/2020/09/apt28-zebrocy-malware-campaign-nato-theme/ — Cited by AI analysis.
  15. https://www.microsoft.com/en-us/security/blog/2023/10/18/multiple-north-korean-threat-actors-exploiting-the-teamcity-cve-2023-42793-vulnerability/ — Cited by AI analysis.
  16. https://www.volexity.com/blog/2018/06/07/patchwork-apt-group-targets-us-think-tanks/ — Cited by AI analysis.

Intel Summary

4

Techniques

53

Tools

0

Campaigns

15

IOCs

0

Observed Data

3

Tactics

Tags

Government Targeting
APT3
Buckeye
China-based APT
Political Targeting
Spearphishing
Gothic Panda
DarkHotel
Zero-day exploit
Spear phishing attachment
Watering hole
Privilege escalation
Japan
Taiwan
APT28
The Dukes
Ghostware
Dropping Elephant
Chinastrats
Patchwork
Government Targets
Think Tanks
NATO

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.