The EPS Awakens - Part 2 « Threat Research | FireEye Inc
ID: 7dc341b5-bd83-4d6d-8af9-c50580f08c18
STIX ID: report--7dc341b5-bd83-4d6d-8af9-c50580f08c18
Threat Score
88/100
Uploaded: 2026-08-07
Published Date: 2015-12-21
Last Modified Date: 2015-12-21
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye observed Nov–Dec 2015 spear-phishing campaigns targeting Japanese and Taiwanese organizations that exploited a Microsoft EPS use-after-free vulnerability and CVE-2015-1701 to install IRONHALO (downloader) and ELMER (HTTP backdoor). Campaigns used localized lures (Japanese and traditional Chinese), delivered weaponized Word documents, and included observable IoCs (MD5s, C2 IPs and domains, HTTP beacon strings). FireEye attributes one December campaign to China-based APT16 and highlights targeting of high-tech, government, media and financial sectors in the context of regional political events.
