logo

IXESHE: An APT Campaign

ID: db38e7ac-0dee-4fe1-a776-6f52b3c04def

STIX ID: report--db38e7ac-0dee-4fe1-a776-6f52b3c04def

Threat Score

88/100

Uploaded: 2026-08-07

Published Date: 2012-07-25

Last Modified Date: 2012-07-25

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro's 2012 research paper analyzes the IXESHE APT campaign (active since 2009) that used targeted spear-phishing with weaponized PDF/XLS exploits—including two zero-days—to deploy remote-control/backdoor malware against East Asian governments, electronics manufacturers, and a telecommunications company; it documents malware behaviors, bespoke C2 formats and custom Base64 alphabets, extensive compromised C&C infrastructure (≈60 servers), campaign tags/IOCs, timelines, and recommended detection/mitigation strategies.