Also known as: IXESHE, DynCalc, Numbered Panda, DNSCALC, TG-2754 (tentative), APT12, BeeBus, Calc Team, Group 22, Crimson Iron, TG-2754, BRONZE GLOBE, Hexagon Typhoon
APT12 is a threat group that has been attributed to China. The group has targeted a variety of victims including but not limited to media outlets, high-tech companies, and multiple governments.(Citation: Meyers Numbered Panda)
NYT Oct 2012
Targeted Sectors
Targeted Countries / Regions
Executive Summary
APT12, a Chinese threat group, has been conducting espionage operations targeting various sectors, including telecommunications, critical infrastructure, and government. Their primary motivation is to gather sensitive information from high-tech companies, media outlets, and governments. APT12's activities have been observed in several countries, with a focus on Taiwan and Japan.
Goals & Targeting
APT12's strategic objectives are focused on gathering sensitive information from their targets, with a particular emphasis on critical infrastructure, telecommunications, and government sectors. The group's targeting profile suggests that they are interested in exploiting vulnerabilities in these sectors to gain access to sensitive information. APT12's typical victims are high-tech companies, media outlets, and governments, which are likely targeted due to their perceived value as sources of sensitive information.
Enhanced Description
APT12's operations have been linked to several campaigns, including the NYT Oct 2012 campaign. The group has also been associated with various software and tools, including Ixeshe, RIPTIDE, attrib, and HTRAN. APT12's use of these tools and techniques suggests that they are a well-resourced and organized threat group, capable of conducting complex and targeted attacks.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
APT12's campaign patterns suggest that they are a well-organized and resourced threat group, capable of conducting complex and targeted attacks. The group's operational tempo is likely to be moderate to high, with a focus on exploiting vulnerabilities in critical infrastructure, telecommunications, and government sectors. APT12's notable past operations include the NYT Oct 2012 campaign, which targeted media outlets and high-tech companies.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in the available data on APT12 is moderate to high, based on multiple sources and reports from reputable organizations. However, there are some information gaps, particularly with regards to the group's exact motivations and targeting profile. Further research and analysis are needed to fully understand APT12's capabilities and intentions.
NYT Oct 2012
No observed data linked yet.
No IOCs linked yet.
5
Techniques
10
Tools
1
Campaigns
0
IOCs
0
Observed Data
3
Tactics