The Anthem Hack: All Roads Lead to China - ThreatConnect | Enterprise Threat Intelligence Platform
ID: 59561fc3-8e30-4ff1-b393-4e3f0bbd7873
STIX ID: report--59561fc3-8e30-4ff1-b393-4e3f0bbd7873
Threat Score
78/100
Uploaded: 2026-08-21
Published Date: 2016-03-03
Last Modified Date: 2016-03-03
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ThreatConnect analyzes the Anthem breach and related activity attributed to Chinese APT groups, detailing signed Derusbi/Sakula and other implants, overlapping malware infrastructure (we11point, prennera, topsec2014), and domain/IP indicators. It links the operation to Southeast University and Beijing Topsec, discusses the role of the MSS and state sponsorship in supporting research ties, and emphasizes the need for collaborative defense and proactive threat intelligence sharing to mitigate such large-scale, sophisticated campaigns.
