Targeted attack on industrial enterprises and public institutions
ID: f7de4880-052e-48d3-880f-2920c1dddcff
STIX ID: report--f7de4880-052e-48d3-880f-2920c1dddcff
Threat Score
78/100
Uploaded: 2026-08-19
Published Date: 2023-01-11
Last Modified Date: 2023-01-11
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Kaspersky ICS CERT documents a targeted campaign against Eastern European defense-industrial entities and public institutions, attributed to a Chinese-speaking TA428 group. The operation deploys multiple malware backdoors (PortDoor, nccTrojan, Cotx/DNSep, Logtu, CotSam) and uses techniques such as phishing with CVE-2017-11882, DLL hijacking and process hollowing, domain controller compromise, and staged CnC servers to exfiltrate data collected from compromised systems; the report also lists victims, infrastructure details, and security recommendations.
