logo

APT15__2013__fireeye-operation-ke3chang.pdf

ID: 35c5af88-9dca-4f64-b231-81ad959bcf8b

STIX ID: report--35c5af88-9dca-4f64-b231-81ad959bcf8b

Threat Score

85/100

Uploaded: 2026-08-07

Published Date: 2013-12-10

Last Modified Date: 2013-12-10

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye's "Operation Ke3chang" report documents a multi-year APT campaign targeting European ministries of foreign affairs using BS2005/MyWeb/BMW backdoors and spear-phishing lures (notably a Syria-themed "moviestar" campaign). The analysis covers malware internals, C2 infrastructure (dynamic DNS domains and dozens of servers), observed reconnaissance and lateral movement on compromised networks, credential-stealing tools, sample IOCs and hashes, and circumstantial evidence pointing to operators in China.