logo

APT12__2016__FireEye_The-Mutter-Backdoor-Operation-Beebus-with-New-Targets_Apr-17-13.pdf

ID: 0bf98761-3025-42a5-815c-91320c678ae8

STIX ID: report--0bf98761-3025-42a5-815c-91320c678ae8

Threat Score

85/100

Uploaded: 2026-08-07

Published Date: 2016-04-11

Last Modified Date: 2016-04-11

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye analysis of the 'Mutter' backdoor describes a targeted espionage campaign (linked to Operation Beebus / the 'Comment Group') that used malicious RTF/XLS/DOC exploits (e.g., CVE-2012-0158, CVE-2010-3333, CVE-2008-3005) to deliver a DLL-based HTTP backdoor against aerospace, defense, telecom and government targets in the US and India; the report details Mutter's command set, proxy-aware C2 communications, evasion techniques (large padded PE, sleep/loop delays), associated C2 domains/IPs, sample hashes, mutexes and a timeline of activity.