APT12

MITRE ATT&CK: G0005 View on attack.mitre.org

Aliases: IXESHE, DynCalc, Numbered Panda, DNSCALC, NUMBERED PANDA, TG-2754, BeeBus, Group 22, Calc Team, DNSCalc, Crimson Iron, BRONZE GLOBE, Hexagon Typhoon, APT12, HYDROGEN, Red Anubis, DNS-Calc, HORDE

First seen
2011-01-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
Espionage
Last IoC activity
2026-06-16 02:00:35
Profile updated
2026-07-07 12:31:27

Targeted industries: media-and-entertainment technology-and-telecommunications government-and-public-sector manufacturing defense-and-aerospace

Targeted regions: country_code:us country_code:tw country_code:kr

Context

APT12 is a threat group that has been attributed to China. The group has targeted a variety of victims including but not limited to media outlets, high-tech companies, and multiple governments.

Detection coverage

  • 2 YARA rules
  • 68 Sigma rules

Malware & tools used

  • Malicious File (attack-pattern)
  • Bidirectional Communication (attack-pattern)
  • DNS Calculation (attack-pattern)
  • Exploitation for Client Execution (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Ixeshe (malware)
  • RIPTIDE (malware)
  • HTRAN (malware)

Reports & references

  • Mandiant — Apt Groups (report)
  • CrowdStrike — Whois Numbered Panda (report)
  • cfr.org — Apt 12 (report)
  • Mandiant — Darwins Favorite Apt Group 2 (report)
  • secureworks.com — Bronze Globe (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • MITRE ATT&CK — G0005 (report)

External references