APT15__2018__New_tools_uncovered_from_hacking_group_APT15.pdf
ID: 26f71f71-c169-4769-b651-6407557f6c57
STIX ID: report--26f71f71-c169-4769-b651-6407557f6c57
Threat Score
85/100
Uploaded: 2026-08-07
Published Date: 2018-03-14
Last Modified Date: 2018-03-14
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
NCC Group uncovered a long-running APT15 intrusion (May 2016–late 2017) against a global company serving the UK government, during which attackers compromised over 30 hosts, stole domain admin credentials with Mimikatz, exfiltrated a VPN certificate for remote access, and deployed three backdoors—previously known BS2005 and two newly documented implants, RoyalCLI (patched cmd.exe to bypass controls) and RoyalDNS (persistent DNS-based C2)—while using CSVDE, BCP and bespoke SharePoint/Exchange tools to extract sensitive data.
