APT17__2013__hidden_lynx.pdf
ID: 46359528-7f7e-4834-a1a2-a585510d3cb2
STIX ID: report--46359528-7f7e-4834-a1a2-a585510d3cb2
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2013-09-17
Last Modified Date: 2013-09-17
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Symantec outlines the activities of the Hidden Lynx group, a sophisticated, likely China-origin "hackers-for-hire" APT that has run large-scale and targeted campaigns since at least 2009. The report details major operations (VOHO, FINSHO, SCADEF), the Bit9 code-signing certificate breach used to sign malware, extensive use of zero-day browser/Flash/Java exploits, watering-hole and supply-chain distribution, custom Trojans (Moudoor, Naid, HiKit, Vasport, Boda), affected sectors (finance, government, defense, education, healthcare), and provides C2/IP/CVE indicators and mitigation guidance.
