logo

APT15__2014__wp-operation-ke3chang.pdf

ID: 65dfef2f-bf39-45a4-8f41-f8fd12f8c2b4

STIX ID: report--65dfef2f-bf39-45a4-8f41-f8fd12f8c2b4

Threat Score

90/100

Uploaded: 2026-08-07

Published Date: 2014-09-01

Last Modified Date: 2014-09-01

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye's 'Operation Ke3chang' documents a long-running espionage campaign (active since at least 2010) that used spear-phishing, multiple exploits (including CVE-2012-4681, CVE-2010-3333, CVE-2010-2883), and three related backdoor families (BMW, MyWeb, BS2005) to compromise ministries of foreign affairs and other high-value targets in Europe; the report provides malware technical details, C2 infrastructure mapping (dozens of dynamic DNS domains and ~99 CnC servers), observed lateral movement and post-compromise data-collection tooling, indicators of compromise, and circumstantial attribution to operators likely operating from China.