← All actors Recent activity

APT12 G0005

12 · apt-c-12 · apt12 · bluemushroom · dnscalc · dyncalc · ixeshe

Indicators
13
Source reports
7
Activity span
not dated
Newest indicator
unknown
Upstream change
2026-01-02
20192020

Overview 13 indicators

APT12 is a threat group that has been attributed to China. The group has targeted a variety of victims including but not limited to media outlets, high-tech companies, and multiple governments.

url10G0005.json
domain2G0005-domain.txt
ipv41G0005.json

Techniques 5 ATT&CK

Open in ATT&CK Navigator → or download the layer (5 techniques, layer 4.5)

Software 3

Principal sources 7 reports

Ranked by how many of this actor's indicators each report brought in.

What the sources have in common — not a claim that these are the same actor. See the whole graph.

Timeline 13 indicators

Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.

  1. 1 ipv4, 6 url6 yrs ago

    bitofhex.com/2020/02/10/sapphire-mushroom-lnk-files · otx.alienvault.com/pulse/5e447f6666b942ff1568cf2a

    ipv4178.128.110.214:8080
    urlhttp://128.199.73.43
    urlhttp://139.59.230.181
    urlhttp://159.65.127.93
    urlhttp://159.65.74.97
    urlhttp://188.226.144.42
    urlhttp://59.73.16.165

  2. 2 url7 yrs ago

    twitter.com/ccxsaber/status/1189017890927726593 · virustotal.com/gui/file/a70d914bf690898d0737692735e99c…

    http://139.59.101.236
    http://139.59.110.217

  3. 1 url7 yrs ago

    twitter.com/ccxsaber/status/1189017890927726593 · virustotal.com/gui/file/a70d914bf690898d0737692735e99c… · bitofhex.com/2020/02/10/sapphire-mushroom-lnk-files · otx.alienvault.com/pulse/5e447f6666b942ff1568cf2a

    http://139.59.226.29

  4. 2 domain, 1 url7 yrs ago

    fireeye.com/blog/threat-research/2014/09/darwins-fa… · github.com/fireeye/iocs/tree/master/APT12 · virustotal.com/gui/ip-address/141.108.2.157/relations

    domainicc.ignorelist.com
    domainvideo.csmcpr.com
    urlhttp://141.108.2.157

Further reading 9