APT27__2019__Emissary_Panda_Attacks_Middle_East_Government_Sharepoint_Servers.pdf
ID: 4c59b055-02d7-4cbe-9be2-0f35010387f2
STIX ID: report--4c59b055-02d7-4cbe-9be2-0f35010387f2
Threat Score
78/100
Uploaded: 2026-08-07
Published Date: 2019-05-29
Last Modified Date: 2019-05-29
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
In April 2019 Unit 42 observed Emissary Panda exploiting SharePoint RCE (CVE-2019-0604) to install Antak and China Chopper webshells on government SharePoint servers in the Middle East, uploading tools (Mimikatz, EternalBlue scanners/exploits, HyperBro) to dump credentials, move laterally, and establish persistent C2 (185.12.45.134). The report provides technical analysis of webshells, custom backdoors, DLL sideloading techniques, timelines of uploads, and extensive IoCs for detection and mitigation.
