logo

APT19__2015__the-black-vine-cyberespionage-group.pdf

ID: aa043fa1-b07b-48e4-b4a2-dd8d5bf14fa3

STIX ID: report--aa043fa1-b07b-48e4-b4a2-dd8d5bf14fa3

Threat Score

90/100

Uploaded: 2026-08-07

Published Date: 2015-07-28

Last Modified Date: 2015-07-28

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Symantec's report outlines Black Vine, a well-resourced cyberespionage actor active since 2012 that used watering‑hole attacks and zero‑day Internet Explorer exploits (linked to the Elderwood framework) to deliver custom backdoors (Hurix, Sakurel, Mivast) against aerospace, energy and healthcare targets — notably the Anthem breach (~80M records). The report includes malware MD5s, malicious domains, details of C2 patterns and certificates, campaign timelines, and an assessment of possible ties to the Beijing security firm Topsec.