Operation Iron Tiger: Exploring Chinese Cyber-Espionage Attacks on United States Defense Contractors
ID: 120005e1-5c45-4785-a9bf-03f3b91d9578
STIX ID: report--120005e1-5c45-4785-a9bf-03f3b91d9578
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2015-09-16
Last Modified Date: 2015-09-16
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro's 'Operation Iron Tiger' report attributes a multi-year Chinese cyber-espionage campaign (Emissary Panda / TG-3390) that shifted from regional political and government targets in Asia-Pacific (2010) to U.S. technology and defense contractors (2013–2015). The actors used targeted spear-phishing, customized and off-the-shelf malware (PlugX, Ghost variants, dnstunclient/dnstunserver, Exchange backdoor Dllshellexc2010, a Google Cloud Platform Trojan, Mimikatz variants), abused legitimate services (Blogspot, App Engine, BAIGE VPN), and employed sophisticated exfiltration methods to steal large volumes of sensitive data (up to terabytes overall, 58GB from one victim); the report includes technical indicators, sample hashes, infrastructure details, persona linkage (phpxss/exenull/Guo Fei), and mitigation guidance.
