GENERAL__2017__Operation_Wilted_Tulip_1.pdf
ID: a3612bd9-20eb-48f2-89b3-06d48e3db605
STIX ID: report--a3612bd9-20eb-48f2-89b3-06d48e3db605
Threat Score
82/100
Uploaded: 2026-08-19
Published Date: 2017-07-25
Last Modified Date: 2017-07-25
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This threat intelligence report details CopyKittens (Operation Wilted Tulip), an advanced cyber espionage operation. It catalogs the group's malware toolkit (including TDTESS, Vminst, NetSrv, ZPP, and Matryoshka v1/v2), their delivery methods (watering hole attacks, web-based exploits, malicious documents and macros), and extensive infrastructure such as DNS-based C2 and numerous domains/IPs. The document also covers the actors' methods for persistence, command and control, and data exfiltration, presenting a thorough set of IOCs and indicators across years and multiple targets, underscoring a high-threat, state- or organized-criminal aligned campaign aimed at government and large IT entities.
