Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Ice Fog

Also known as: Dagger Panda, IceFog, ICEFOG, Fucobha, Trident, RedFoxtrot, Red Wendigo, PLA Unit 69010, UAT-7290, Red Foxtrot

Description

**Targets:** This threat actor targets government institutions, military contractors, maritime and shipbuilding groups, telecommunications operators, and others, primarily in US, Taiwan, Japan and South Korea. **Toolset/Malware:** Dagger Three (C2 software), Fucobha Backdoor **Overlaps with:** Links to Onion Dog

Goals & Targeting

Targeted Sectors

Government
Telecommunications
Defense

Targeted Countries / Regions

TW
KR
JP

AI Analysis

· 1 week ago

Executive Summary

Ice Fog, also known as Dagger Panda or Red Foxtrot, is a nation-state threat actor primarily involved in espionage activities targeting government, telecommunications, and defense sectors in countries such as Taiwan, South Korea, Japan, and the United States. The group is known for its sophisticated tools like Dagger Three C2 software and Fucobha Backdoor, and has demonstrated persistent activity across multiple industries to gather sensitive intelligence.

Goals & Targeting

Ice Fog's strategic objectives appear to center around espionage, likely to support national security or military interests. The group's focus on government and defense sectors suggests an intent to gather sensitive military, political, and technological information from these targets. Despite being linked to multiple aliases and potential state affiliations, the exact goals beyond espionage remain unclear. Their targeting of countries like Taiwan, Japan, and South Korea may indicate regional strategic priorities or conflicts.

Enhanced Description

Ice Fog is a high-sophistication threat actor linked to nation-state activities, primarily focusing on espionage. The group targets government institutions, military contractors, maritime groups, and telecommunications operators in the US, Taiwan, South Korea, and Japan. Their operations are characterized by persistence and technical proficiency, employing tools such as Dagger Three C2 software and Fucobha Backdoor for command and control, as well as data exfiltration. The group's activities suggest a strong focus on intelligence gathering, possibly linked to geopolitical interests. While no specific campaigns or timestamps are provided, their targeting patterns indicate sustained and targeted operations over time.

Key Capabilities

  • Development of custom C2 software (Dagger Three)
  • Deployment of Fucobha Backdoor for persistent access
  • Sophisticated malware development capabilities
  • Advanced persistence techniques

Software / Tooling

Dagger Three C2 software
Fucobha Backdoor

Campaigns & Victims

Ice Fog's campaign patterns are not well-documented, but their operations suggest a focus on long-term access and data collection. The group likely operates with a slower, more deliberate pace to avoid detection while maintaining persistence across multiple targets. While specific campaigns remain unclear, the sustained targeting of defense and government sectors points to organized, strategic activity.

IOC Patterns

  • Use of Dagger Three C2 software
  • Deployment of Fucobha Backdoor in targeted networks

Recommended Actions

  • Implement rigorous email filtering and phishing detection mechanisms
  • Monitor network traffic for signs of persistent backdoor activities
  • Conduct regular vulnerability assessments and apply patches promptly
  • Enhance user training to identify spear-phishing attempts
  • Use endpoint detection and response (EDR) tools to detect anomalies

Suggested Tags

APT
espionage
government
telecommunications

Confidence Assessment

Confidence in the data is medium due to limited public information on Ice Fog's activities, timelines, and specific attack patterns. While aliases and toolset indicate a likely nation-state actor, the exact nature of operations, including detailed TTPs and campaign history, remain unclear.

ATT&CK Techniques

No techniques linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

2

Tools

0

Campaigns

1

IOCs

0

Observed Data

0

Tactics

Tags

APT
Backdoor / C2
Government Targeting
espionage
government
telecommunications

Details

Type
Nation-State
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
70%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.