摩诃草组织
ID: 6b274e39-3ffb-4fe2-996e-8c3ad2c97438
STIX ID: report--6b274e39-3ffb-4fe2-996e-8c3ad2c97438
Threat Score
78/100
Uploaded: 2026-08-21
Published Date: 2016-08-04
Last Modified Date: 2016-08-04
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report documents the Mahorao (Patchwork/HangOver) APT group, detailing four campaigns from 2012–2016 that targeted China and other regions with spear-phishing, watering holes, instant messaging, social networks, and phishing sites, leveraging both known and zero-day CVEs and a diverse set of malware families (HangOver, OSX.Kumar, Smackdown, AutoIT RAT). It analyzes C2 infrastructure, attribution clues, and the broader threat landscape, arguing the attacker operates with substantial resources and state-backed backing and highlighting the need for capacity-based defense.
