logo

Roaming_Tiger__2014__sophos-rotten-tomato-campaign.pdf

ID: 8c68b416-a2b1-4e36-ae2c-789fa76d87f2

STIX ID: report--8c68b416-a2b1-4e36-ae2c-789fa76d87f2

Threat Score

75/100

Uploaded: 2026-08-19

Published Date: 2014-10-21

Last Modified Date: 2014-10-21

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
SophosLabs' analysis of the “Rotten Tomato” campaign details how multiple attacker groups reused and combined RTF exploit templates leveraging CVE-2012-0158 and CVE-2014-1761 to deliver varied payloads (Plugx, Zbot, Goldsun, Appat). The report catalogs technical workflows, failed and successful integration attempts, sample hashes, dropped file paths, persistence methods, and numerous C2 domains, highlighting both APT-like and commodity crimeware behaviors and providing concrete IoCs and TTP observations.