logo

APT21__2013__kaspersky-the-net-traveler-part1-final.pdf

ID: 81ac6d41-902f-4934-a8a4-a89afd3b1a83

STIX ID: report--81ac6d41-902f-4934-a8a4-a89afd3b1a83

Threat Score

80/100

Uploaded: 2026-08-07

Published Date: 2013-06-04

Last Modified Date: 2013-06-04

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
## Executive summary: Kaspersky Lab's public analysis of the NetTraveler (aka Travnet/NetFile) campaign documents a long-running targeted espionage operation that used spear‑phishing and Office exploits (CVE-2010-3333, CVE-2012-0158) to deploy data‑exfiltration backdoors (NetTraveler and additional payloads like Saker/Xbox and Zegost). The report provides full technical breakdowns of malware functionality, persistence, custom compression/encoding, C2 scripts and servers, extensive IOCs (MD5s, domains, IPs, filenames), victim profiling (350+ confirmed victims across ~40 countries with diplomatic, government, research and industry targets), overlap with other campaigns, and mitigation/recommendations.