APT17__2015__APT17_Report.pdf
ID: 9e78961d-277b-4871-b587-96423e7f479d
STIX ID: report--9e78961d-277b-4871-b587-96423e7f479d
Threat Score
85/100
Uploaded: 2026-08-07
Published Date: 2015-05-14
Last Modified Date: 2015-05-14
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye and Microsoft describe how the China-based APT17 (DeputyDog) used the BLACKCOFFEE backdoor to hide C2 infrastructure by embedding encoded CnC IP addresses in legitimate Microsoft TechNet profile pages and forum threads (a dead-drop resolver technique); the report details BLACKCOFFEE's capabilities, the decoding mechanism, published IOCs, and mitigation actions taken to sinkhole and observe victims.
