APT12
Also known as: IXESHE · DynCalc · Numbered Panda · DNSCALC
Overview
APT12 is a threat group that has been attributed to China. The group has targeted a variety of victims including but not limited to media outlets, high-tech companies, and multiple governments.
Naming & attribution
APT12 is tracked under 5 names across the industry. It uses 5 documented ATT&CK techniques — more than 13% of the 174 groups tracked here.
| Name | First reported by |
|---|---|
| IXESHE | Meyers, A |
| DynCalc | Meyers, A |
| Numbered Panda | Meyers, A |
| DNSCALC | Moran, N., Oppenheim, M., Engle, S., & Wartell, R. |
| APT12 | Meyers, A |
Distinctive techniques
Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.
-
T1568.003DNS Calculation — used by 1 of 174 groups
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- TA459 China — 3 shared techniques (43% overlap)
- The White Company — 3 shared techniques (33% overlap)
- Elderwood China — 3 shared techniques (27% overlap)
- admin@338 China — 3 shared techniques (21% overlap)
- Andariel North Korea — 3 shared techniques (21% overlap)
- BlackTech China — 3 shared techniques (19% overlap)
Targets
Government · Private sector
Regions
Japan · Taiwan
Capabilities
- Exploitation of public-facing / client applications — ATT&CK T1203
TTPs — 5 techniques across 3 tactics
Initial Access
-
T1566.001Spearphishing Attachment
Execution
-
T1203Exploitation for Client Execution -
T1204.002Malicious File
Command and Control
-
T1102.002Bidirectional Communication -
T1568.003DNS Calculation
Tools & malware (3)
Ixeshe · RIPTIDE · HTRAN
Reporting (2)
- Darwin’s Favorite APT Group [Blog] — Moran, N., Oppenheim, M., Engle, S., & Wartell, R.
- Whois Numbered Panda — Meyers, A