PULSE NAME
Multiple Chinese APT Groups Quickly Use Flash Zero-Day
WHITE UPS AlienVault 2015-07-14 Modified: 2017-08-24
7
IOCs
LOW VOLUME
The FireEye as a Service team detected independent phishing campaigns conducted by two Chinese advanced persistent threat (APT) groups that we track, APT3 and APT18. Each threat group quickly took advantage of a zero-day vulnerability (CVE-2015-5119), which was leaked in the disclosure of Hacking Team’s internal data. Adobe released a patch for the vulnerability on July 8, 2015. Before that patch was released, the groups launched phishing campaigns against multiple companies in the aerospace and defense, construction and engineering, education, energy, health and biotechnology, high tech, non-profit, telecommunications, and transportation industries.
Indicators of Compromise (7)
All hostname FileHash-MD5 CVE
TYPEINDICATORDESCRIPTIONCREATED
hostname link.angellroofing.com 2017-08-24
hostname rpt.perrydale.com 2017-08-24
hostname psa.perrydale.com 2017-08-24
hostname vic.perrydale.com 2017-08-24
hostname report.perrydale.com 2017-08-24
FileHash-MD5 079a440bee0f86d8a59ebc5c4b523a07 2017-08-24
CVE CVE-2015-5119 2017-08-24