logo

Targeted attack on industrial enterprises and public institutions

ID: f7de4880-052e-48d3-880f-2920c1dddcff

STIX ID: report--f7de4880-052e-48d3-880f-2920c1dddcff

Threat Score

78/100

Uploaded: 2026-08-19

Published Date: 2023-01-11

Last Modified Date: 2023-01-11

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Kaspersky ICS CERT documents a targeted campaign against Eastern European defense-industrial entities and public institutions, attributed to a Chinese-speaking TA428 group. The operation deploys multiple malware backdoors (PortDoor, nccTrojan, Cotx/DNSep, Logtu, CotSam) and uses techniques such as phishing with CVE-2017-11882, DLL hijacking and process hollowing, domain controller compromise, and staged CnC servers to exfiltrate data collected from compromised systems; the report also lists victims, infrastructure details, and security recommendations.