Lucky_Cat__2020__Chinese_APT_TA413_Resumes_Targeting_of_Tibet_Following_COVID-19_Themed_Economic_Espionage_Campaign_Delivering_Sepulcher_Malware_Targeting_Europe_Proofpoint_US.pdf
ID: 15a104c5-142d-4679-abda-704ba1ff0fd0
STIX ID: report--15a104c5-142d-4679-abda-704ba1ff0fd0
Threat Score
88/100
Uploaded: 2026-08-19
Published Date: 2020-09-07
Last Modified Date: 2020-09-07
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Proofpoint researchers identified TA413 phishing campaigns in 2020 that used COVID-19 and Tibetan-themed decoys to deliver a new RAT family dubbed “Sepulcher.” The attackers exploited a Microsoft Equation Editor/WMF vulnerability via weaponized RTF and delivered PPSX attachments to download and install the RAT, established persistence (scheduled task calling Credential.dll), and used XOR/LZW-based C2 communications to exfiltrate data; the report provides technical analysis and numerous IOCs (hashes, domains, IPs, and sender addresses).
