LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0005: APT12

MITRE ATT&CK G0005: APT12 Group details, with detection guidance, relationships and mapped CVEs.

EnterpriseG0005GroupObject v2.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

APT12 is an ATT&CK-tracked intrusion set, also referenced as IXESHE, DynCalc, Numbered Panda, and DNSCALC, described by MITRE as China-attributed and historically targeting media, high-tech companies, and governments. For defenders, the practical value is not the name alone: the supplied relationships point to a pattern of targeted email-driven access, client-side execution, and command-and-control using DNS/web channels and proxy-aware tooling.

Executive priority

Treat this as a planning reference for targeted-intrusion readiness, especially if the organization has media, technology, government, or adjacent exposure. Leaders should ask whether email security, endpoint visibility, DNS/proxy logging, and incident response playbooks can connect an initial malicious attachment or client exploit to later command-and-control activity. Because MITRE provides no official detection text for the group, coverage should be proven through control validation rather than assumed from threat-name matching.

Technical view

ATT&CK relationships for APT12 include Spearphishing Attachment, Malicious File, Exploitation for Client Execution, Bidirectional Communication, DNS Calculation, and use of RIPTIDE, Ixeshe, and HTRAN. SOC and IR teams should validate visibility across initial access, execution, and C2 rather than relying on a single indicator. The group object itself has no specified platforms or tactics, but related techniques span Linux, macOS, Windows, and ESXi, while related software includes Windows and Linux/Windows tooling.

Likely telemetry

  • Email security logs for attachments, sender metadata, delivery, quarantine, and user interaction
  • Endpoint telemetry for file creation, document/application launches, child processes, exploit-like crashes, and suspicious execution
  • DNS query and response logs, including unusual resolution patterns and calculated or unexpected follow-on connections
  • Web proxy, firewall, and network flow records for outbound web-service communication and proxy-like behavior
  • EDR/AV detections or malware analysis records referencing RIPTIDE, Ixeshe, HTRAN, or related aliases where available

Detection direction

  • Map detections to the related behaviors: malicious attachments, user-opened files, client exploitation, DNS-based C2 calculation, bidirectional web communication, and proxy tooling.
  • Correlate email delivery and attachment execution with endpoint process activity and later DNS/proxy traffic; isolated alerts may miss the intrusion chain.
  • Tune for false positives around legitimate web services, normal DNS variability, and authorized proxy tools, but require investigation when these appear after suspicious attachment or exploit events.
  • Validate whether named malware/tool detections are signature-only or behavior-based; absence of a family name should not be treated as absence of the behavior.
  • Review ATT&CK relationship context during threat hunting, since the group object has no official detection guidance and no directly specified platforms.

Mitigation priorities

  • Prioritize phishing attachment controls, attachment detonation, and user-reporting workflows for targeted email scenarios.
  • Maintain timely patching and exposure management for client applications that process documents, web content, or other user-opened files.
  • Enforce least privilege and endpoint hardening to reduce the impact of malicious file execution or client exploit success.
  • Strengthen DNS, proxy, and egress controls so unusual outbound C2 patterns can be logged, investigated, and constrained.
  • Prepare IR playbooks that join email, endpoint, DNS, and proxy evidence quickly when a suspected targeted intrusion begins with a file or exploit.
Additional notes and limits

This take is based on ATT&CK G0005 version 2.1 and the supplied relationships to software and techniques. The aliases and references are useful for threat intelligence correlation, but defenders should translate them into behavior-based validation rather than relying only on historical names.

MITRE provides no official detection text, no group-level platforms, and no group-level tactics in the supplied object. The relationship descriptions are partially summarized, and local telemetry, control configuration, and risk context are required before making any statement about organizational exposure or detection coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

APT12

No official description is available in the imported ATT&CK source object.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.1
Created
Modified
Raw hash
79013e760380bcf2...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.