APT19__2015__the-black-vine-cyberespionage-group.pdf
ID: aa043fa1-b07b-48e4-b4a2-dd8d5bf14fa3
STIX ID: report--aa043fa1-b07b-48e4-b4a2-dd8d5bf14fa3
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2015-07-28
Last Modified Date: 2015-07-28
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Symantec's report outlines Black Vine, a well-resourced cyberespionage actor active since 2012 that used watering‑hole attacks and zero‑day Internet Explorer exploits (linked to the Elderwood framework) to deliver custom backdoors (Hurix, Sakurel, Mivast) against aerospace, energy and healthcare targets — notably the Anthem breach (~80M records). The report includes malware MD5s, malicious domains, details of C2 patterns and certificates, campaign timelines, and an assessment of possible ties to the Beijing security firm Topsec.
