Threat intelligence
- Suspected origin
- China
- First seen
- 2011-01-01 00:00:00
- Motivation
- Information theft and espionage
- Targeted sectors
- Aerospace, Defense, Government, High-Tech, Maritime and Shipbuilding, Media, Telecommunications, Utilities
- TLP
- WHITE
(Kaspersky) “Icefog” is an Advanced Persistent Threat that has been active since at least 2011, targeting mostly Japan and South Korea. Known targets include governmental institutions, military contractors, maritime and shipbuilding groups, telecom operators, industrial and high-tech companies and mass media. The name “Icefog” comes from a string used in the command-and-control server name in one of the samples. The command-and-control software is named “Dagger Three”, in the Chinese language. During Icefog attacks, several other malicious tools and backdoors were uploaded to the victims’ machines, for data exfiltration and lateral movement. The later group RedAlpha has infrastructure overlap with Icefog.
Also known as
ATK 23Dagger PandaIcefogRed Wendigo
Coverage 0
No articles match these filters.
Reset filters