logo

APT1: technical backstage

ID: ebc0fea3-03d0-4378-9843-86051587f148

STIX ID: report--ebc0fea3-03d0-4378-9843-86051587f148

Threat Score

90/100

Uploaded: 2026-08-07

Published Date: 2013-03-27

Last Modified Date: 2013-03-27

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Malware.lu report documents a hands-on technical investigation of APT1 activity: discovery and scanning of Poison Ivy C2s, brute-forcing/deriving Camellia encryption keys, exploiting Poison Ivy and a custom Terminator RAT to gain access to attacker infrastructure, enumeration of proxy and C2 topology, collection of attacker tools and targets, and development of Metasploit modules, JtR plugins, and shellcode to analyze and exploit their systems. The report contains IoCs (IP ranges, MD5 hashes, filenames), detailed TTPs (proxy forwarding with xPort, RDP use, one-server-per-target model, working hours), and appendices with source code for exploits, brute forcers, and utilities used during the investigation.