logo

Lucky_Cat__2020__Chinese_APT_TA413_Resumes_Targeting_of_Tibet_Following_COVID-19_Themed_Economic_Espionage_Campaign_Delivering_Sepulcher_Malware_Targeting_Europe_Proofpoint_US.pdf

ID: 15a104c5-142d-4679-abda-704ba1ff0fd0

STIX ID: report--15a104c5-142d-4679-abda-704ba1ff0fd0

Threat Score

88/100

Uploaded: 2026-08-19

Published Date: 2020-09-07

Last Modified Date: 2020-09-07

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Proofpoint researchers identified TA413 phishing campaigns in 2020 that used COVID-19 and Tibetan-themed decoys to deliver a new RAT family dubbed “Sepulcher.” The attackers exploited a Microsoft Equation Editor/WMF vulnerability via weaponized RTF and delivered PPSX attachments to download and install the RAT, established persistence (scheduled task calling Credential.dll), and used XOR/LZW-based C2 communications to exfiltrate data; the report provides technical analysis and numerous IOCs (hashes, domains, IPs, and sender addresses).