PoisonVine (also tracked as APT-C-01 and linked in other reporting to GreenSpot) conducted a long-running cyber-espionage campaign against organizations in China, targeting government agencies, military personnel, defense industry entities, research institutes, universities, maritime bodies, and a major shipping company. Reporting says the group has operated since at least 2007 and continued through later campaigns such as Operation Rubia cordifolia, using spear-phishing, watering-hole attacks, spoofed websites, fake recruitment and manuscript-solicitation emails, and malicious attachments to steal credentials and sensitive internal data for political and military intelligence collection.
The operators combined commodity and customized malware, including Poison Ivy, ZxShell/ZXShell, Gh0st, HttpBots, and Kanbox RAT, while repeatedly exploiting older but reliable flaws such as CVE-2012-0158, CVE-2014-4114, CVE-2014-6352, CVE-2017-8759, and CVE-2018-20250. Investigators tied the activity together through shared dynamic DNS infrastructure, Vultr VPS hosting, overlapping phishing frameworks such as LJFrame, CPFrame, and FAPPFrame, and recurring operational patterns including staged loaders, antivirus evasion, cloud-storage exfiltration, and keyword-based collection of military and national-security documents; one case reportedly involved about 3 GB of stolen files.

TTPs, infrastructure, and targeting history in one profile.
18 events from the most recent confirmed update back to the earliest known activity.
QiAnXin stated that Operation Rubia cordifolia was still active as of October 2020.
QiAnXin reported that from August 2020, the LJFrame 2.0 phishing framework adopted variable paths such as /mainX/ to make phishing assets harder to find.
QiAnXin reported that neteaseyhnujm.serveusers.com, resolving to 139.180.202.208, was related to neteasedqwert.serveuser.com in phishing activity during late 2019. The report also identified infrastructure reuse through shared image resources.
QiAnXin said Operation Rubia cordifolia, a phishing and espionage campaign it attributed to PoisonVine, was active at least from 2018. The campaign targeted defense industry, military intelligence, government agencies, and higher-education research institutions.
QiAnXin's timeline states that PoisonVine was first publicly disclosed in 2018.
QiAnXin reported that a customized shellcode loader was discovered in early 2018 in PoisonVine activity. It triggered .hta execution via CVE-2017-8759 and supported drive-by download and execution.
QiAnXin said PoisonVine conducted several spearphishing attacks using CVE-2017-8759 in October 2017. Antiy separately reported GreenSpot using CVE-2017-8759 Office documents in 2017 to download and execute malware including Poison Ivy.
QiAnXin reported that PoisonVine used its customized Kanbox RAT in February 2015.
QiAnXin's report states Microsoft patched CVE-2014-6352 in October 2014 after PoisonVine's use of the exploit.
QiAnXin reported that PoisonVine used the zero-day later tracked as CVE-2014-6352 in September 2014. The report lists a sample creation time of 4 September 2014 and says the exploit bypassed the patch for CVE-2014-4114.
QiAnXin said PoisonVine attacked several military and government targets in 2013 through a compromised website used as a watering hole.
QiAnXin reported that the first ZxShell variant associated with PoisonVine activity was found in 2012.
Antiy said that in 2011–2015 GreenSpot commonly used spearphishing emails with malicious attachments, especially exploit documents abusing CVE-2012-0158 and bundled PE malware. The exploit-document campaigns often used MHT-formatted files to evade antivirus detection.
Antiy assessed that after 2010 the actor improved its ability to adapt 1-day and older vulnerabilities, customize public attack tools, and deploy some self-developed tooling.
QiAnXin reported that PoisonVine targeted universities and military industry organizations in China during 2008 and 2009 as part of its espionage activity.
QiAnXin's report states PoisonVine was first discovered in December 2007. A trojan attributed to the group targeted a large shipping company that year.
Antiy described suspected related intrusion activity from around 2007 using a DIY-style toolset including nc.exe, rar.exe, keyloggers, and HTTP utilities. It said it could not conclusively prove this was GreenSpot, but assessed it came from the same source direction.
Antiy found evidence suggesting GreenSpot used CVE-2014-4114 before October 2014.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 15 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.