logo

The EPS Awakens - Part 2 « Threat Research | FireEye Inc

ID: 7dc341b5-bd83-4d6d-8af9-c50580f08c18

STIX ID: report--7dc341b5-bd83-4d6d-8af9-c50580f08c18

Threat Score

88/100

Uploaded: 2026-08-07

Published Date: 2015-12-21

Last Modified Date: 2015-12-21

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye observed Nov–Dec 2015 spear-phishing campaigns targeting Japanese and Taiwanese organizations that exploited a Microsoft EPS use-after-free vulnerability and CVE-2015-1701 to install IRONHALO (downloader) and ELMER (HTTP backdoor). Campaigns used localized lures (Japanese and traditional Chinese), delivered weaponized Word documents, and included observable IoCs (MD5s, C2 IPs and domains, HTTP beacon strings). FireEye attributes one December campaign to China-based APT16 and highlights targeting of high-tech, government, media and financial sectors in the context of regional political events.