APT21__2013__kaspersky-the-net-traveler-part1-final.pdf
ID: 81ac6d41-902f-4934-a8a4-a89afd3b1a83
STIX ID: report--81ac6d41-902f-4934-a8a4-a89afd3b1a83
Threat Score
80/100
Uploaded: 2026-08-07
Published Date: 2013-06-04
Last Modified Date: 2013-06-04
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
## Executive summary: Kaspersky Lab's public analysis of the NetTraveler (aka Travnet/NetFile) campaign documents a long-running targeted espionage operation that used spear‑phishing and Office exploits (CVE-2010-3333, CVE-2012-0158) to deploy data‑exfiltration backdoors (NetTraveler and additional payloads like Saker/Xbox and Zegost). The report provides full technical breakdowns of malware functionality, persistence, custom compression/encoding, C2 scripts and servers, extensive IOCs (MD5s, domains, IPs, filenames), victim profiling (350+ confirmed victims across ~40 countries with diplomatic, government, research and industry targets), overlap with other campaigns, and mitigation/recommendations.
