APT27__2019__A_Peek_into_BRONZE_UNION_s_Toolbox.pdf
ID: 44f9a717-c826-4734-b4c7-57967cc14e14
STIX ID: report--44f9a717-c826-4734-b4c7-57967cc14e14
Threat Score
85/100
Uploaded: 2026-08-07
Published Date: 2019-03-05
Last Modified Date: 2019-03-05
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Secureworks CTU research tracks BRONZE UNION (Emissary Panda/APT27), a suspected China-aligned espionage group, documenting updated uses of public and custom tooling (ZxShell, modified Gh0st RAT, SysUpdate), delivery methods (malicious documents, SWC, credential reuse), persistence and privilege escalation techniques, C2 protocols and infrastructure, and a comprehensive set of IoCs (hashes, domains, IPs) observed during 2017–2018 campaigns.
