APT30__2015__rpt-apt30.pdf
ID: f693443d-9745-4d04-9598-0251443e09ea
STIX ID: report--f693443d-9745-4d04-9598-0251443e09ea
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2015-04-11
Last Modified Date: 2015-04-11
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye documents APT30, a decade-long, highly organized cyber-espionage operation focused on Southeast Asia and India that reused and iteratively refined a small set of tools (BACKSPACE/Lecna, NETEAGLE, SHIPSHAPE, SPACESHIP, FLASHFLOOD) to steal sensitive government and regional political/military information; the report details two-stage C2 architectures, a Windows-based BACKSPACE controller with operator features (target prioritization, shift/login tracking, versioning, disk-serial gating), social engineering themes tied to ASEAN events, removable-drive malware designed to bridge air-gapped networks, and extensive IOCs and sample metadata.
