APT15__2014__wp-operation-ke3chang.pdf
ID: 65dfef2f-bf39-45a4-8f41-f8fd12f8c2b4
STIX ID: report--65dfef2f-bf39-45a4-8f41-f8fd12f8c2b4
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2014-09-01
Last Modified Date: 2014-09-01
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye's 'Operation Ke3chang' documents a long-running espionage campaign (active since at least 2010) that used spear-phishing, multiple exploits (including CVE-2012-4681, CVE-2010-3333, CVE-2010-2883), and three related backdoor families (BMW, MyWeb, BS2005) to compromise ministries of foreign affairs and other high-value targets in Europe; the report provides malware technical details, C2 infrastructure mapping (dozens of dynamic DNS domains and ~99 CnC servers), observed lateral movement and post-compromise data-collection tooling, indicators of compromise, and circumstantial attribution to operators likely operating from China.
