Analysis on APT-to-be Attack That Focusing on China's Government Agency
ID: 10b6432e-4c8a-4d51-921e-09582ab060d3
STIX ID: report--10b6432e-4c8a-4d51-921e-09582ab060d3
Threat Score
78/100
Uploaded: 2026-08-19
Published Date: 2015-05-28
Last Modified Date: 2015-05-28
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ANTiY Labs reports on an APT operation named APT-TOCS targeting a Chinese government agency, using a Cobalt Strike Beacon-based framework and PowerShell-driven, multi-stage shellcode to download and execute encrypted modules in memory. The analysis covers leading files, sample data, modules, and data packets, and notes the use of a commercial attack platform to enable covert, persistent access with periodic heartbeats and C2 communications.
