Operation_Wocao__2019__201912_Report_Operation_Wacao.pdf
ID: 12bbc163-f63e-4f78-a248-d0378ffbeab7
STIX ID: report--12bbc163-f63e-4f78-a248-d0378ffbeab7
Threat Score
90/100
Uploaded: 2026-08-19
Published Date: 2019-12-18
Last Modified Date: 2019-12-18
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Operation Wocao is Fox-IT's detailed analysis of a Chinese state-aligned APT (likely APT20) that used JBoss webshells, stolen VPN/Windows credentials (including stolen RSA SecurID soft-tokens), and custom backdoors (XServer, Agent) plus keyloggers and reconnaissance scripts to infiltrate and exfiltrate data from victims across government and multiple industries in at least 10 countries; the report includes tooling hashes, attack walkthroughs, MITRE ATT&CK mappings and defensive recommendations.
