Uptime Hamster: 10d 10h 56mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza APT-C-12

APT-C-12

0 incidentes 0 paises 0 sectores apt CN Ultimo: -
Aliases: Blue Mushroom, NuclearCrisis, Sapphire Mushroom, apt-c-12, apt12, bluemushroom, dnscalc, dyncalc, ixeshe
Ver en IntelTracker → APTTrail →
APT-C-12, also known by the aliases Numbered Panda, DynCalc, Blue Mushroom, NuclearCrisis, and Sapphire Mushroom, is a cyber espionage group that has been active since at least 2009. This group is assessed with high confidence to be of Chinese origin. Their primary motivation is the exfiltration of sensitive data, specifically intellectual property, from targeted organizations. The group is notable for its use of custom malware and long-term infiltration strategies directed against high-value assets. Campaigns attributed to this group, such as those linked to Sapphire Mushroom, have utilized specific techniques including LNK files.

Aliases del actor

Blue MushroomNuclearCrisisSapphire Mushroomapt-c-12apt12bluemushroomdnscalcdyncalcixeshe

Actores similares

apt-blueprintactor · 1apt-45actor · 2apt-c-27actor · 2apt-c-01actor · 2apt-18actor · 1apt-1877teamactor · 1apt-27actor · 1apt-30actor · 1apt-38actor · 1apt-c-48actor · 1

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
X/Twitterunknownbitofhex.comapt-c-12 indicators and references
Repositoriounknowngithub.comapt-c-12 indicators and references
DLS / leak siteunknownotx.alienvault.comapt-c-12 indicators and references
X/Twitterunknowntwitter.comapt-c-12 indicators and references
DLS / leak siteunknownwww.fireeye.comapt-c-12 indicators and references
DLS / leak siteunknownwww.virustotal.comapt-c-12 indicators and references
DLS / leak siteunknownwww.virustotal.comapt-c-12 indicators and references
Repositoriounknowngithub.comapt-c-12 indicators and references
DLS / leak siteunknownraw.githubusercontent.comapt-c-12 indicators and references
X/Twitterunknown128.199.73.43APTTrailURLhttpapt-c-12 indicators and references
Malware asociado
win.etumbot, win.rapid_stealer
Tecnicas MITRE
T1204.002, T1568.003, T1204, T1102, T1568, T1059.001
Tipo
apt
Pais origen
CN
Motivacion
-
Impacto
38
Actualizado
Wed, 01 Ju

Sectores objetivo (SOCRadar)

Other Information ServicesMonetary Authorities-Central BankSoftware PublishersManufacturingElectrical Equipment, Appliance, and Component ManufacturingPublic AdministrationEducational ServicesInternet PublishingSpace & DefenseEnergy & Utilities