APT15__2013__fireeye-operation-ke3chang.pdf
ID: 35c5af88-9dca-4f64-b231-81ad959bcf8b
STIX ID: report--35c5af88-9dca-4f64-b231-81ad959bcf8b
Threat Score
85/100
Uploaded: 2026-08-07
Published Date: 2013-12-10
Last Modified Date: 2013-12-10
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye's "Operation Ke3chang" report documents a multi-year APT campaign targeting European ministries of foreign affairs using BS2005/MyWeb/BMW backdoors and spear-phishing lures (notably a Syria-themed "moviestar" campaign). The analysis covers malware internals, C2 infrastructure (dynamic DNS domains and dozens of servers), observed reconnaissance and lateral movement on compromised networks, credential-stealing tools, sample IOCs and hashes, and circumstantial evidence pointing to operators in China.
