logo

APT30__2015__rpt-apt30_9d78ff20.pdf

ID: c2b5786c-f854-44bf-8f4e-4ca50eb86bc0

STIX ID: report--c2b5786c-f854-44bf-8f4e-4ca50eb86bc0

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2015-04-15

Last Modified Date: 2015-04-15

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye describes APT30, a likely state‑sponsored, decade‑long cyber espionage operation focused on Southeast Asia and India that uses a consistent suite of bespoke tools (BACKSPACE/Lecna, NETEAGLE, SHIPSHAPE, SPACESHIP, FLASHFLOOD), two‑stage C2 infrastructure, spear‑phishing with localized decoys, and removable‑drive techniques to exfiltrate sensitive/government data (including air‑gapped networks); the report includes controller GUI analysis, command sets, versioning, targeting patterns around ASEAN events, and numerous IOCs and MD5 hashes.