logo

APT30__2015__rpt-apt30.pdf

ID: f693443d-9745-4d04-9598-0251443e09ea

STIX ID: report--f693443d-9745-4d04-9598-0251443e09ea

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2015-04-11

Last Modified Date: 2015-04-11

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye documents APT30, a decade-long, highly organized cyber-espionage operation focused on Southeast Asia and India that reused and iteratively refined a small set of tools (BACKSPACE/Lecna, NETEAGLE, SHIPSHAPE, SPACESHIP, FLASHFLOOD) to steal sensitive government and regional political/military information; the report details two-stage C2 architectures, a Windows-based BACKSPACE controller with operator features (target prioritization, shift/login tracking, versioning, disk-serial gating), social engineering themes tied to ASEAN events, removable-drive malware designed to bridge air-gapped networks, and extensive IOCs and sample metadata.