logo

NetTraveler APT Targets Russian, European Interests

ID: f7137696-eaa9-4b39-b672-417318612715

STIX ID: report--f7137696-eaa9-4b39-b672-417318612715

Threat Score

88/100

Uploaded: 2026-08-07

Published Date: 2016-07-17

Last Modified Date: 2016-07-17

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Proofpoint reports on a 2016 NetTraveler (TravNet) APT campaign attributed to China that targeted Russian, Mongolian, Belarusian and other European interests via spear-phishing lures (RAR-hosted executables and Word docs exploiting CVE-2012-0158). The report provides technical analysis of NetTraveler (DLL side-loading, config format), builder artifacts (MNKit), detailed infrastructure and IOCs (multiple fake news-like domains, IPs, and SHA256 hashes), and notes links to prior PlugX-related activity.