APT12, also known as Numbered Panda, Calc Team, DynCalc, DNSCalc, IXESHE, Hexagon Typhoon, Horde, Hydrogen, and Red Anubis, is a China-attributed cyber-espionage threat actor active since at least 2009. The group has targeted government entities, media organizations, high-technology companies, telecommunications organizations, and Taiwanese electronics manufacturers, with a particularly strong focus on East Asia and Taiwan. APT12 is known for spearphishing-based initial access using malicious Microsoft Office and PDF attachments, relying on user execution to open weaponized files. The group has also been linked to web-based exploitation campaigns, including activity associated with Internet Explorer exploitation and selective targeting of Taiwanese government networks. In intrusions, APT12 has deployed backdoors and remote access trojans including RIPTIDE and the IXESHE malware family. The actor’s command-and-control tradecraft includes HTTP communications, encrypted payload transport using RC4, and use of blogs and WordPress as command-and-control infrastructure. APT12 is notably associated with DNS Calculation tradecraft, deriving command-and-control parameters from DNS response data to evade straightforward detection and filtering. Reported operations also show use of persistence mechanisms, custom malware, credential theft, and post-compromise collection activity. APT12 has been publicly linked to long-running espionage operations against Western media and other organizations, including compromises involving theft of employee credentials, establishment of multiple backdoors, and targeted collection from journalists and executives. The group is widely assessed as a state-linked Chinese espionage actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
24 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
9 CVEs this actor has used in observed campaigns. 9 of them exploited in the wild.
...vulnerabilities in Adobe Reader and Flash (CVE-2009-4324, CVE-2009-0927, CVE-2011-0609, CVE-2011-0611).
APT12 has exploited multiple vulnerabilities for execution, including Microsoft Office vulnerabilities (CVE-2009-3129, CVE-2012-0158)...
...vulnerabilities in Adobe Reader and Flash (CVE-2009-4324, CVE-2009-0927, CVE-2011-0609, CVE-2011-0611).
...vulnerabilities in Adobe Reader and Flash (CVE-2009-4324, CVE-2009-0927, CVE-2011-0609, CVE-2011-0611).
...has exploited CVE-2011-0611 in Adobe Flash Player to gain execution on a targeted system.
4 more CVEs tied to this actor tracked in Mallory.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as an associated threat actor in detection annotations for Ghostscript exploitation; no specific campaign activity is described in this reference.
Listed as a threat actor associated with the malicious file execution technique detected by this analytic.
Listed in the detection annotations as a threat actor associated with the installation / pre-OS boot persistence technique context for EFI volume mounting activity.
Referenced as a threat actor associated with spearphishing attachment activity involving malicious file execution and potential credential capture via UDL files.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.