TA428 — APT Profile
TA428 targets Eastern European and Asian government and defense organizations using PortDoor and ShadowPad malware.Also tracked as
Calypso, RedFoxtrot, Operation LagTime IT, BRONZE DUDLEY, Operation StealthyTrident, Colourful Panda, BRONZE MEDLEY, Red Lamassu
Tools & malware
- 8.t Dropper Loader
- CotSam Backdoor
- Cotx RAT RAT
- DNSep Backdoor
- Ladon Tool
- Logtu Backdoor
- nccTrojan Backdoor
- Poison Ivy RAT
- PortDoor Backdoor
- Tmanger RAT
Vendor research
- Chinese APT "Operation LagTime IT" Targets Government Information Technology Agencies in Eastern Asia Proofpoint
- Targeted attack on industrial enterprises and public institutions Kaspersky (Securelist)
- APT attacks on industrial organizations in H2 2022 Kaspersky ICS CERT
- Operation StealthyTrident: corporate software under attack ESET (WeLiveSecurity)
Countries linked to this actor
- Mongolia targets