top of page
Mitre
Alias
Operation �seven Pointed Dagger�, Red Pegasus, Apt9, Nightshade Panda, Apt9,, Flowershow, Apt 9, Group 27, Flowerlady
Country
China
Sponsor
Nil
Motivation
Nil
First Seen
2013
Description
APT9 engages in cyber operations where the goal is data theft, usually focusing on the data and projects that make a particular organization competitive within its field. APT9 was historically very active in the pharmaceuticals and biotechnology industry. We have observed this actor use spearphishing, valid accounts, as well as remote services for Initial Access. On at least one occasion, Mandiant observed APT9 at two companies in the biotechnology industry and suspect that APT9 actors may have gained initial access to one of the companies by using a trusted relationship between the two companies. APT9 use a wide range of backdoors, including publicly available backdoors, as well as backdoors that are believed to be custom, but are used by multiple APT groups. (Softpedia) Arbor�s ASERT team is now reporting that, after looking deeper at that particular campaign, and by exposing a new trail in the group�s activities, they managed to identify a new RAT that was undetectable at that time by most antivirus vendors. Named Trochilus, this new RAT was part of Group 27�s malware portfolio that included six other malware strains, all served together or in different combinations, based on the data that needed to be stolen from each victim. This collection of malware, dubbed the Seven Pointed Dagger by ASERT experts, included two different PlugX versions, two different Trochilus RAT versions, one version of the 3012 variant of the 9002 RAT, one EvilGrab RAT version, and one unknown piece of malware, which the team has not entirely decloaked just yet.
Targeted
Industries
Government, Utilities,, Aerospace, Construction, Energy, Defense Industrial Base, Pharmaceuticals, Media, Healthcare, Utilities
Targeted
Countries
Usa, United States, Myanmar, Thailand, United States,
Tools
3102
Evilgrab
Moonwind
Poison
Trochilus
Plugx
9002
TTP
Nil
Operations
Performed
Nil
Counter
Operations
Nil
Information
nil
bottom of page