Chinese APT Group, Used Stolen NSA Hacking Tools Before Shadow Brokers
ID: 5dc9a407-870c-5e68-a931-e6fd8e0b4203
STIX ID: report--5dc9a407-870c-5e68-a931-e6fd8e0b4203
Feed Name: Security Ledger
Symantec reporting indicates Chinese-linked APT 'Buckeye' (APT3/Gothic Panda) deployed a variant of the DoublePulsar backdoor delivered via the Bemstour exploit in March 2016, suggesting the group used or replicated NSA Equation Group tools before those tools were publicly leaked by Shadow Brokers; the article highlights CVE-2017-0143 and a Symantec-discovered zero-day (CVE-2019-0703) in discussing the exploits and warns of the strategic risk when state cyber-weapons are exposed and repurposed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
