NetTraveler APT Targets Russian, European Interests
ID: f7137696-eaa9-4b39-b672-417318612715
STIX ID: report--f7137696-eaa9-4b39-b672-417318612715
Threat Score
88/100
Uploaded: 2026-08-07
Published Date: 2016-07-17
Last Modified Date: 2016-07-17
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Proofpoint reports on a 2016 NetTraveler (TravNet) APT campaign attributed to China that targeted Russian, Mongolian, Belarusian and other European interests via spear-phishing lures (RAR-hosted executables and Word docs exploiting CVE-2012-0158). The report provides technical analysis of NetTraveler (DLL side-loading, config format), builder artifacts (MNKit), detailed infrastructure and IOCs (multiple fake news-like domains, IPs, and SHA256 hashes), and notes links to prior PlugX-related activity.
