Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: IXESHE, DynCalc, Numbered Panda, DNSCALC, TG-2754 (tentative), APT12, BeeBus, Calc Team, Group 22, Crimson Iron, TG-2754, BRONZE GLOBE, Hexagon Typhoon

Description

APT12 is a threat group that has been attributed to China. The group has targeted a variety of victims including but not limited to media outlets, high-tech companies, and multiple governments.(Citation: Meyers Numbered Panda)

TTP Summary

NYT Oct 2012

Goals & Targeting

Targeted Sectors

Telecommunications
Critical infrastructure
Government

Targeted Countries / Regions

TW
JP

AI Analysis

· 2 months ago

Executive Summary

APT12, a Chinese threat group, has been conducting espionage operations targeting various sectors, including telecommunications, critical infrastructure, and government. Their primary motivation is to gather sensitive information from high-tech companies, media outlets, and governments. APT12's activities have been observed in several countries, with a focus on Taiwan and Japan.

Goals & Targeting

APT12's strategic objectives are focused on gathering sensitive information from their targets, with a particular emphasis on critical infrastructure, telecommunications, and government sectors. The group's targeting profile suggests that they are interested in exploiting vulnerabilities in these sectors to gain access to sensitive information. APT12's typical victims are high-tech companies, media outlets, and governments, which are likely targeted due to their perceived value as sources of sensitive information.

Enhanced Description

APT12's operations have been linked to several campaigns, including the NYT Oct 2012 campaign. The group has also been associated with various software and tools, including Ixeshe, RIPTIDE, attrib, and HTRAN. APT12's use of these tools and techniques suggests that they are a well-resourced and organized threat group, capable of conducting complex and targeted attacks.

Key Capabilities

  • Advanced spearphishing techniques
  • DNS calculation and tunneling
  • Exploitation of client applications
  • Bidirectional communication
  • Use of custom malware and tools

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion

ATT&CK Techniques

T1059.003
T1055
T1566.001
T1204.002
T1568.003
T1102.002
T1203

Software / Tooling

Ixeshe
RIPTIDE
attrib
HTRAN
Custom malware and tools

Campaigns & Victims

APT12's campaign patterns suggest that they are a well-organized and resourced threat group, capable of conducting complex and targeted attacks. The group's operational tempo is likely to be moderate to high, with a focus on exploiting vulnerabilities in critical infrastructure, telecommunications, and government sectors. APT12's notable past operations include the NYT Oct 2012 campaign, which targeted media outlets and high-tech companies.

IOC Patterns

  • Spearphishing with macro-laced Office documents
  • C2 over DNS using fast-flux
  • Staging infrastructure on bulletproof hosting
  • Use of custom malware and tools

Recommended Actions

  • Implement robust email filtering and spearphishing detection
  • Use DNS traffic monitoring and anomaly detection
  • Implement least privilege and segregation of duties
  • Conduct regular vulnerability assessments and patching
  • Use endpoint detection and response tools

Suggested Tags

APT
Espionage
China
Critical Infrastructure
Telecommunications
Government

Confidence Assessment

The confidence level in the available data on APT12 is moderate to high, based on multiple sources and reports from reputable organizations. However, there are some information gaps, particularly with regards to the group's exact motivations and targeting profile. Further research and analysis are needed to fully understand APT12's capabilities and intentions.

ATT&CK Techniques

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Meyers Numbered Panda — Meyers, A. (2013, March 29). Whois Numbered Panda. Retrieved January 14, 2016.
  2. Moran 2014 — Moran, N., Oppenheim, M., Engle, S., & Wartell, R.. (2014, September 3). Darwin’s Favorite APT Group [Blog]. Retrieved November 12, 2014.

Intel Summary

5

Techniques

10

Tools

1

Campaigns

0

IOCs

0

Observed Data

3

Tactics

Tags

APT
Critical Infrastructure
Government Targeting
Espionage
China
Telecommunications
Government

Details

MITRE ID
G0005
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--c47f937f-1022-4f42-8525-e7a4779a14cb
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.