logo

APT12__2016__FireEye_Operation-Beebus_Feb-1-13.pdf

ID: 9cbc962e-3404-4716-87c4-455b0b5125b1

STIX ID: report--9cbc962e-3404-4716-87c4-455b0b5125b1

Threat Score

88/100

Uploaded: 2026-08-07

Published Date: 2016-04-11

Last Modified Date: 2016-04-11

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye describes 'Operation Beebus', a targeted APT campaign against aerospace and defense organizations using spearphishing and drive-by downloads with weaponized PDFs/DOCs (multiple CVEs) and DLL search-order hijacking for persistence; the malware encodes/exfiltrates data to C2 servers (modified base64 with character substitutions), with provided IoCs (MD5s, domains, IPs), timelines, and attribution to a China-linked group leveraging HTran and obfuscated HTML comment techniques.