Hogfish Redleaves Malware Threat Analysis I Accenture
ID: 96b24499-3afa-4a00-92c3-63f8c0ce44d9
STIX ID: report--96b24499-3afa-4a00-92c3-63f8c0ce44d9
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2018-04-20
Last Modified Date: 2018-04-20
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Accenture iDefense report analyzes a targeted espionage campaign by HOGFISH (APT10) using RedLeaves implants against Japanese victims: a malicious Word document drops an obfuscated DLL and a signed binary, performs process hollowing into iexplore.exe, persists via Startup shortcuts, communicates with hardcoded C2 domains over HTTP (encrypted with RC4), and exfiltrates credentials and screenshots; the report provides IoCs (hashes, domains, IPs, mutexes, file paths) and mitigation guidance for SOCs.
