logo

APT15__2018__New_tools_uncovered_from_hacking_group_APT15.pdf

ID: 26f71f71-c169-4769-b651-6407557f6c57

STIX ID: report--26f71f71-c169-4769-b651-6407557f6c57

Threat Score

85/100

Uploaded: 2026-08-07

Published Date: 2018-03-14

Last Modified Date: 2018-03-14

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
NCC Group uncovered a long-running APT15 intrusion (May 2016–late 2017) against a global company serving the UK government, during which attackers compromised over 30 hosts, stole domain admin credentials with Mimikatz, exfiltrated a VPN certificate for remote access, and deployed three backdoors—previously known BS2005 and two newly documented implants, RoyalCLI (patched cmd.exe to bypass controls) and RoyalDNS (persistent DNS-based C2)—while using CSVDE, BCP and bespoke SharePoint/Exchange tools to extract sensitive data.