TA428__2019__Chinese_APT_Operation_LagTime_IT.pdf
ID: 0ee623fc-7349-43f0-8ffe-f5206252919d
STIX ID: report--0ee623fc-7349-43f0-8ffe-f5206252919d
Threat Score
75/100
Uploaded: 2026-08-19
Published Date: 2019-07-25
Last Modified Date: 2019-07-25
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Proofpoint documents Operation LagTime IT, a Chinese APT campaign (TA428) targeting East Asian government IT agencies with spear-phishing using malicious RTFs that exploit CVE-2018-0798 to install Cotx RAT and Poison Ivy, detailing the malware capabilities, C2 infrastructure, IOCs, and persistent targeting as part of a state-aligned espionage operation.
