logo

Hogfish Redleaves Malware Threat Analysis I Accenture

ID: 96b24499-3afa-4a00-92c3-63f8c0ce44d9

STIX ID: report--96b24499-3afa-4a00-92c3-63f8c0ce44d9

Threat Score

90/100

Uploaded: 2026-08-07

Published Date: 2018-04-20

Last Modified Date: 2018-04-20

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Accenture iDefense report analyzes a targeted espionage campaign by HOGFISH (APT10) using RedLeaves implants against Japanese victims: a malicious Word document drops an obfuscated DLL and a signed binary, performs process hollowing into iexplore.exe, persists via Startup shortcuts, communicates with hardcoded C2 domains over HTTP (encrypted with RC4), and exfiltrates credentials and screenshots; the report provides IoCs (hashes, domains, IPs, mutexes, file paths) and mitigation guidance for SOCs.