Roaming_Tiger__2014__sophos-rotten-tomato-campaign.pdf
ID: 8c68b416-a2b1-4e36-ae2c-789fa76d87f2
STIX ID: report--8c68b416-a2b1-4e36-ae2c-789fa76d87f2
Threat Score
75/100
Uploaded: 2026-08-19
Published Date: 2014-10-21
Last Modified Date: 2014-10-21
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
SophosLabs' analysis of the “Rotten Tomato” campaign details how multiple attacker groups reused and combined RTF exploit templates leveraging CVE-2012-0158 and CVE-2014-1761 to deliver varied payloads (Plugx, Zbot, Goldsun, Appat). The report catalogs technical workflows, failed and successful integration attempts, sample hashes, dropped file paths, persistence methods, and numerous C2 domains, highlighting both APT-like and commodity crimeware behaviors and providing concrete IoCs and TTP observations.
