APT12__2016__FireEye_The-Mutter-Backdoor-Operation-Beebus-with-New-Targets_Apr-17-13.pdf
ID: 0bf98761-3025-42a5-815c-91320c678ae8
STIX ID: report--0bf98761-3025-42a5-815c-91320c678ae8
Threat Score
85/100
Uploaded: 2026-08-07
Published Date: 2016-04-11
Last Modified Date: 2016-04-11
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye analysis of the 'Mutter' backdoor describes a targeted espionage campaign (linked to Operation Beebus / the 'Comment Group') that used malicious RTF/XLS/DOC exploits (e.g., CVE-2012-0158, CVE-2010-3333, CVE-2008-3005) to deliver a DLL-based HTTP backdoor against aerospace, defense, telecom and government targets in the US and India; the report details Mutter's command set, proxy-aware C2 communications, evasion techniques (large padded PE, sleep/loop delays), associated C2 domains/IPs, sample hashes, mutexes and a timeline of activity.
