New activity of The Blue Termite APT - Securelist
ID: a24e9a65-31fd-4af4-b5eb-b145ed7e77ba
STIX ID: report--a24e9a65-31fd-4af4-b5eb-b145ed7e77ba
Threat Score
88/100
Uploaded: 2026-08-14
Published Date: 2015-10-28
Last Modified Date: 2015-10-28
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Kaspersky Lab reports on the Blue Termite APT campaign targeting Japanese organizations since 2013, detailing a shift to drive-by Flash exploits (CVE-2015-5119) and deployment of customized emdivi backdoors (t17/t20). The analysis covers initial infection methods (watering-hole, malicious SWF), payload extraction and execution, extensive backdoor command sets, per-sample encrypted configuration including hardcoded proxy and SID-based decryption keys, sample hashes and C2 indicators, and mitigation detections deployed by Kaspersky.
