logo

APT27__2019__Emissary_Panda_Attacks_Middle_East_Government_Sharepoint_Servers.pdf

ID: 4c59b055-02d7-4cbe-9be2-0f35010387f2

STIX ID: report--4c59b055-02d7-4cbe-9be2-0f35010387f2

Threat Score

78/100

Uploaded: 2026-08-07

Published Date: 2019-05-29

Last Modified Date: 2019-05-29

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
In April 2019 Unit 42 observed Emissary Panda exploiting SharePoint RCE (CVE-2019-0604) to install Antak and China Chopper webshells on government SharePoint servers in the Middle East, uploading tools (Mimikatz, EternalBlue scanners/exploits, HyperBro) to dump credentials, move laterally, and establish persistent C2 (185.12.45.134). The report provides technical analysis of webshells, custom backdoors, DLL sideloading techniques, timelines of uploads, and extensive IoCs for detection and mitigation.