Antlion__2022__Symantec_Antlion-ChineseAPT-Target-Financial-Taiwan_02-03-2022.pdf
ID: fd9d7908-261f-4c82-8712-aa92b8c3187b
STIX ID: report--fd9d7908-261f-4c82-8712-aa92b8c3187b
Threat Score
88/100
Uploaded: 2026-08-14
Published Date: 2022-02-21
Last Modified Date: 2022-02-21
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Symantec describes an 18+ month Antlion campaign targeting Taiwanese financial and manufacturing organizations using a custom .NET backdoor (xPack), multiple custom loaders and tools, credential dumping (registry and procdump), keylogging, SMB-based file transfers, exploitation (including EternalBlue and CVE-2019-1458), and data staging/exfiltration; the report includes technical analysis, YARA rules and numerous SHA256 IOCs to aid detection and response.
