logo

APT17__2015__APT17_Report.pdf

ID: 9e78961d-277b-4871-b587-96423e7f479d

STIX ID: report--9e78961d-277b-4871-b587-96423e7f479d

Threat Score

85/100

Uploaded: 2026-08-07

Published Date: 2015-05-14

Last Modified Date: 2015-05-14

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye and Microsoft describe how the China-based APT17 (DeputyDog) used the BLACKCOFFEE backdoor to hide C2 infrastructure by embedding encoded CnC IP addresses in legitimate Microsoft TechNet profile pages and forum threads (a dead-drop resolver technique); the report details BLACKCOFFEE's capabilities, the decoding mechanism, published IOCs, and mitigation actions taken to sinkhole and observe victims.