Antlion__2022__Antlion_Chinese_APT_Uses_Custom_Backdoor_to_Target_Financial_Institutions_in_Taiwan_Symantec_Blogs.pdf
ID: 70879579-a43e-43a0-80d6-ad221282815c
STIX ID: report--70879579-a43e-43a0-80d6-ad221282815c
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2022-02-10
Last Modified Date: 2022-02-10
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Symantec details an 18+ month espionage campaign attributed to Chinese state-backed APT 'Antlion' targeting Taiwanese financial and manufacturing organizations; attackers used a custom .NET backdoor called xPack (and multiple custom loaders, keyloggers, and tools), performed credential dumping and lateral movement, leveraged exploits and living-off-the-land binaries, staged and exfiltrated sensitive data, and maintained long dwell times. The report includes technical indicators (numerous SHA256 hashes), YARA rules, and mitigation guidance for defenders.
