Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
Also known as: IXESHE, DynCalc, Numbered Panda, DNSCALC
5
techniques
3
software
3,987
corpus matches
profile
APT12 is a threat group that has been attributed to China. The group has targeted a variety of victims including but not limited to media outlets, high-tech companies, and multiple governments.
techniques
5 attributed · most-instrumented first
software
3 malware & tools attributed
RIPTIDE
S0003
Ixeshe
S0015
HTRAN
S0040
read this carefully
3,987 corpus matches is not attribution
That count is indicators which exhibit techniques APT12 is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
command-and-control
showing 30 of 3,987
known aliases
Vendors name the same group differently. Searching any alias reaches this profile.