logo

Operation_Wocao__2019__201912_Report_Operation_Wacao.pdf

ID: 12bbc163-f63e-4f78-a248-d0378ffbeab7

STIX ID: report--12bbc163-f63e-4f78-a248-d0378ffbeab7

Threat Score

90/100

Uploaded: 2026-08-19

Published Date: 2019-12-18

Last Modified Date: 2019-12-18

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Operation Wocao is Fox-IT's detailed analysis of a Chinese state-aligned APT (likely APT20) that used JBoss webshells, stolen VPN/Windows credentials (including stolen RSA SecurID soft-tokens), and custom backdoors (XServer, Agent) plus keyloggers and reconnaissance scripts to infiltrate and exfiltrate data from victims across government and multiple industries in at least 10 countries; the report includes tooling hashes, attack walkthroughs, MITRE ATT&CK mappings and defensive recommendations.