logo

APT15 is alive and strong: An analysis of RoyalCli and RoyalDNS

ID: 19658e23-b9db-44e0-b6a0-b93ed43d0786

STIX ID: report--19658e23-b9db-44e0-b6a0-b93ed43d0786

Threat Score

90/100

Uploaded: 2026-08-07

Published Date: 2018-08-06

Last Modified Date: 2018-08-06

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
NCC Group details an APT15 compromise of a UK government services provider, identifying new and existing backdoors (RoyalCli, RoyalDNS, BS2005), bespoke tools (spwebmember, Exchange/SharePoint dumpers), use of Mimikatz and Golden Ticket techniques, persistence via stolen VPN certificates and DNS/IE-based C2, recovered attacker commands (>200), and published IOCs (hashes, domains) and detection signatures.