APT12__2016__FireEye_Operation-Beebus_Feb-1-13.pdf
ID: 9cbc962e-3404-4716-87c4-455b0b5125b1
STIX ID: report--9cbc962e-3404-4716-87c4-455b0b5125b1
Threat Score
88/100
Uploaded: 2026-08-07
Published Date: 2016-04-11
Last Modified Date: 2016-04-11
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye describes 'Operation Beebus', a targeted APT campaign against aerospace and defense organizations using spearphishing and drive-by downloads with weaponized PDFs/DOCs (multiple CVEs) and DLL search-order hijacking for persistence; the malware encodes/exfiltrates data to C2 servers (modified base64 with character substitutions), with provided IoCs (MD5s, domains, IPs), timelines, and attribution to a China-linked group leveraging HTran and obfuscated HTML comment techniques.
