IceFog is a backdoor associated with Chinese cyber espionage activity and first publicly identified in 2013. It has been used in operations targeting organizations in the Asia-Pacific region, particularly in Japan and South Korea, and has also been linked to broader espionage activity against government, defense, telecommunications, mining, and research entities across Central and South Asia. IceFog has been observed in document-based intrusion chains in which a malicious lure leads to the installation of the backdoor on victim systems.
The malware is notably associated with the threat cluster RedFoxtrot, a suspected Chinese state-sponsored espionage group linked by public reporting to PLA Unit 69010. RedFoxtrot has employed IceFog alongside other tooling commonly seen in China-nexus operations, including PlugX, Poison Ivy, Royal Road, PCShare, and likely ShadowPad. Reporting indicates that RedFoxtrot’s use of IceFog declined over time as the group increasingly favored other malware families.
IceFog is used to provide covert remote access to compromised systems, fitting its role as an espionage backdoor. It has been referenced in campaigns using themed lure documents, including a prior Olympics-themed attack in which a malicious document dropped the IceFog backdoor. High-confidence reporting supports its use on Windows systems in targeted intrusions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Icefog leveraged CVE-2012-0158—an older vulnerability in Windows common controls—relying on the fact that many system administrators ... often find patching cumbersome. | Once the user opened the document, the sample called and dropped a backdoor component, called Icefog. First discovered in 2013, the Icefog backdoor was used to attack sectors in the APAC region, with a focus on Japan and South Korea.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
RedFoxtrot maintains large amounts of operational infrastructure and has likely employed both bespoke and publicly available malware families commonly used by Chinese cyber espionage groups, including Icefog, PlugX, Royal Road, Poison Ivy, ShadowPad, and PCShare.
RedFoxtrot maintains large amounts of operational infrastructure and has likely employed both bespoke and publicly available malware families commonly used by Chinese cyber espionage groups, including Icefog, PlugX, Royal Road, Poison Ivy, ShadowPad, and PCShare.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor used in attacks in the APAC region, especially Japan and South Korea; described as part of a prior Olympics-themed attack and associated with methodical targeting.
Chinese cyber espionage malware used by RedFoxtrot; historically delivered via Royal Road and used in campaigns targeting Central Asia, Pakistan, and India.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.