APT30__2015__rpt-apt30_9d78ff20.pdf
ID: c2b5786c-f854-44bf-8f4e-4ca50eb86bc0
STIX ID: report--c2b5786c-f854-44bf-8f4e-4ca50eb86bc0
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2015-04-15
Last Modified Date: 2015-04-15
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye describes APT30, a likely state‑sponsored, decade‑long cyber espionage operation focused on Southeast Asia and India that uses a consistent suite of bespoke tools (BACKSPACE/Lecna, NETEAGLE, SHIPSHAPE, SPACESHIP, FLASHFLOOD), two‑stage C2 infrastructure, spear‑phishing with localized decoys, and removable‑drive techniques to exfiltrate sensitive/government data (including air‑gapped networks); the report includes controller GUI analysis, command sets, versioning, targeting patterns around ASEAN events, and numerous IOCs and MD5 hashes.
