logo

DAGGER_PANDA__2021__securelist.com-The_Icefog_APT_Hits_US_Targets_With_Java_Backdoor.pdf

ID: 3d37ad82-6f6f-4663-ba96-3578378de064

STIX ID: report--3d37ad82-6f6f-4663-ba96-3578378de064

Threat Score

80/100

Uploaded: 2026-08-14

Published Date: 2021-01-07

Last Modified Date: 2021-01-07

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report analyzes 'Javafog', a Java-based backdoor used by the Icefog (aka Dagger Panda) APT: it includes JAR/sample analysis, persistence via registry autorun, C2 communication patterns with lingdona.com (HTTP POSTs, Java User-Agent), supported remote commands (file upload, remote execution, C2 migration), example PCAP content and process listings, IoCs (domains, IPs, MD5), and observed US-based victims including a large oil & gas company; the authors sinkholed the C2 and note low detection rates on VirusTotal.