logo

Operation Iron Tiger: Exploring Chinese Cyber-Espionage Attacks on United States Defense Contractors

ID: 120005e1-5c45-4785-a9bf-03f3b91d9578

STIX ID: report--120005e1-5c45-4785-a9bf-03f3b91d9578

Threat Score

90/100

Uploaded: 2026-08-07

Published Date: 2015-09-16

Last Modified Date: 2015-09-16

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro's 'Operation Iron Tiger' report attributes a multi-year Chinese cyber-espionage campaign (Emissary Panda / TG-3390) that shifted from regional political and government targets in Asia-Pacific (2010) to U.S. technology and defense contractors (2013–2015). The actors used targeted spear-phishing, customized and off-the-shelf malware (PlugX, Ghost variants, dnstunclient/dnstunserver, Exchange backdoor Dllshellexc2010, a Google Cloud Platform Trojan, Mimikatz variants), abused legitimate services (Blogspot, App Engine, BAIGE VPN), and employed sophisticated exfiltration methods to steal large volumes of sensitive data (up to terabytes overall, 58GB from one victim); the report includes technical indicators, sample hashes, infrastructure details, persona linkage (phpxss/exenull/Guo Fei), and mitigation guidance.