Proofpoint reported that the espionage group Leviathan conducted sustained spearphishing campaigns against defense contractors, government agencies, universities with military ties, legal organizations, and maritime-related entities, particularly those connected to the United States, Western Europe, and South China Sea issues. The actor used malicious attachments and URLs, including exploits for CVE-2017-0199 and CVE-2017-8759, macro-enabled Office documents, and socially engineered Publisher files, while also relying on lookalike domains, stolen branding, and occasional lateral movement through compromised email accounts and servers.
A key malware family in the campaigns was NanHaiShu, a custom JavaScript-based tool also documented by MITRE ATT&CK. NanHaiShu used DNS for command-and-control, established persistence through Registry Run Keys or Startup-folder shortcuts, executed additional VBScript and JScript, downloaded payloads from remote URLs, and abused mshta.exe to proxy execution. The malware also gathered host details such as computer name, serial number, proxy settings, and username, reduced Internet Explorer security warnings, deleted decoy files to remove evidence, and encoded files with Base64 as part of the intrusion workflow.

TTPs, infrastructure, and targeting history in one profile.
7 events from the most recent confirmed update back to the earliest known activity.
MITRE ATT&CK published a software entry for NanHaiShu, documenting its observed behaviors and mapping them to ATT&CK techniques. The entry describes capabilities including DNS command-and-control, persistence via Startup or Run keys, script execution, file download, discovery, and Internet Explorer setting changes.
Proofpoint published a report describing the long-running Leviathan espionage actor targeting defense, government, maritime, and military-linked organizations. The report linked the campaigns through recurring use of custom malware including NanHaiShu and Orz, along with consistent targeting and tradecraft.
On September 15 and 19, 2017, Proofpoint detected spearphishing emails targeting a US shipbuilding company and a US university research center with military ties. The lures included the subject line “Apply for internship position” and attachments such as “resume.rtf” and “ARLUAS_FieldLog_2017-08-21.doc.”
The September 2017 attachments exploited CVE-2017-8759 only five days after the vulnerability was publicly documented. In the “resume.rtf” chain, the malware retrieved a malicious SOAP WSDL definition and then downloaded a VBScript file, later establishing persistence with a Startup shortcut and downloading Cobalt Strike.
Between August 2 and 4, 2017, the actor sent spearphishing emails with malicious URLs to multiple defense contractors. Some lures abused the branding of a major military shipbuilder, and some documents exploited CVE-2017-0199 while others used Microsoft Publisher files requiring user interaction.
From February to October 2015, campaigns attributed to the actor targeted South China Sea interests including the Philippines Department of Justice, APEC organizers, and an international law firm. These campaigns used Microsoft Excel and Word documents with macros.
Proofpoint observed the espionage actor persistently targeting US universities with military interests, especially Navy-related institutions, using malicious macro-enabled Excel documents. The actor also used macro-enabled Word documents against US research and development organizations with military and intelligence ties during this period.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 16 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.