logo

DAGGER_PANDA__2013__icefog.pdf

ID: ad6abdc6-cd70-42ca-a19f-9aff23307953

STIX ID: report--ad6abdc6-cd70-42ca-a19f-9aff23307953

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2013-09-26

Last Modified Date: 2013-09-26

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Kaspersky’s report analyzes the Icefog APT (aka Dagger Three), an espionage-focused campaign active since ~2011 that targets primarily Japan and South Korea. It documents spear‑phishing delivery (Office, Java, HLP, HWP exploits), Windows and macOS backdoors (interactive Icefog/Macfog variants, including Icefog‑NG), lateral movement and credential‑harvesting tools, extensive C2 infrastructure and sinkholed domains, victim profiling (defense, shipbuilding, telecom, media), IoCs (domains, malware MD5s, mutexes, paths) and mitigation guidance.