DAGGER_PANDA__2013__icefog.pdf
ID: ad6abdc6-cd70-42ca-a19f-9aff23307953
STIX ID: report--ad6abdc6-cd70-42ca-a19f-9aff23307953
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2013-09-26
Last Modified Date: 2013-09-26
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Kaspersky’s report analyzes the Icefog APT (aka Dagger Three), an espionage-focused campaign active since ~2011 that targets primarily Japan and South Korea. It documents spear‑phishing delivery (Office, Java, HLP, HWP exploits), Windows and macOS backdoors (interactive Icefog/Macfog variants, including Icefog‑NG), lateral movement and credential‑harvesting tools, extensive C2 infrastructure and sinkholed domains, victim profiling (defense, shipbuilding, telecom, media), IoCs (domains, malware MD5s, mutexes, paths) and mitigation guidance.
