APT15 is alive and strong: An analysis of RoyalCli and RoyalDNS
ID: 19658e23-b9db-44e0-b6a0-b93ed43d0786
STIX ID: report--19658e23-b9db-44e0-b6a0-b93ed43d0786
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2018-08-06
Last Modified Date: 2018-08-06
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
NCC Group details an APT15 compromise of a UK government services provider, identifying new and existing backdoors (RoyalCli, RoyalDNS, BS2005), bespoke tools (spwebmember, Exchange/SharePoint dumpers), use of Mimikatz and Golden Ticket techniques, persistence via stolen VPN certificates and DNS/IE-based C2, recovered attacker commands (>200), and published IOCs (hashes, domains) and detection signatures.
