news.mlab.sh
Threat intelligence
Threat actor

Icefog

Profile from actors.mlab.sh, coverage from our own index.

Suspected origin
China
First seen
2011-01-01 00:00:00
Motivation
Information theft and espionage
Targeted sectors
Aerospace, Defense, Government, High-Tech, Maritime and Shipbuilding, Media, Telecommunications, Utilities
TLP
WHITE

(Kaspersky) “Icefog” is an Advanced Persistent Threat that has been active since at least 2011, targeting mostly Japan and South Korea. Known targets include governmental institutions, military contractors, maritime and shipbuilding groups, telecom operators, industrial and high-tech companies and mass media. The name “Icefog” comes from a string used in the command-and-control server name in one of the samples. The command-and-control software is named “Dagger Three”, in the Chinese language. During Icefog attacks, several other malicious tools and backdoors were uploaded to the victims’ machines, for data exfiltration and lateral movement. The later group RedAlpha has infrastructure overlap with Icefog.

Also known as

ATK 23Dagger PandaIcefogRed Wendigo

Coverage 0

No articles match these filters.

Reset filters