LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0005: APT12

APT12 is a threat group that has been attributed to China. The group has targeted a variety of victims including but not limited to media outlets, high-tech companies, and multiple governments.[1]

EnterpriseG0005GroupObject v2.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

APT12 is an ATT&CK-tracked intrusion set, also referenced as IXESHE, DynCalc, Numbered Panda, and DNSCALC, described by MITRE as China-attributed and historically targeting media, high-tech companies, and governments. For defenders, the practical value is not the name alone: the supplied relationships point to a pattern of targeted email-driven access, client-side execution, and command-and-control using DNS/web channels and proxy-aware tooling.

Executive priority

Treat this as a planning reference for targeted-intrusion readiness, especially if the organization has media, technology, government, or adjacent exposure. Leaders should ask whether email security, endpoint visibility, DNS/proxy logging, and incident response playbooks can connect an initial malicious attachment or client exploit to later command-and-control activity. Because MITRE provides no official detection text for the group, coverage should be proven through control validation rather than assumed from threat-name matching.

Technical view

ATT&CK relationships for APT12 include Spearphishing Attachment, Malicious File, Exploitation for Client Execution, Bidirectional Communication, DNS Calculation, and use of RIPTIDE, Ixeshe, and HTRAN. SOC and IR teams should validate visibility across initial access, execution, and C2 rather than relying on a single indicator. The group object itself has no specified platforms or tactics, but related techniques span Linux, macOS, Windows, and ESXi, while related software includes Windows and Linux/Windows tooling.

Likely telemetry

  • Email security logs for attachments, sender metadata, delivery, quarantine, and user interaction
  • Endpoint telemetry for file creation, document/application launches, child processes, exploit-like crashes, and suspicious execution
  • DNS query and response logs, including unusual resolution patterns and calculated or unexpected follow-on connections
  • Web proxy, firewall, and network flow records for outbound web-service communication and proxy-like behavior
  • EDR/AV detections or malware analysis records referencing RIPTIDE, Ixeshe, HTRAN, or related aliases where available

Detection direction

  • Map detections to the related behaviors: malicious attachments, user-opened files, client exploitation, DNS-based C2 calculation, bidirectional web communication, and proxy tooling.
  • Correlate email delivery and attachment execution with endpoint process activity and later DNS/proxy traffic; isolated alerts may miss the intrusion chain.
  • Tune for false positives around legitimate web services, normal DNS variability, and authorized proxy tools, but require investigation when these appear after suspicious attachment or exploit events.
  • Validate whether named malware/tool detections are signature-only or behavior-based; absence of a family name should not be treated as absence of the behavior.
  • Review ATT&CK relationship context during threat hunting, since the group object has no official detection guidance and no directly specified platforms.

Mitigation priorities

  • Prioritize phishing attachment controls, attachment detonation, and user-reporting workflows for targeted email scenarios.
  • Maintain timely patching and exposure management for client applications that process documents, web content, or other user-opened files.
  • Enforce least privilege and endpoint hardening to reduce the impact of malicious file execution or client exploit success.
  • Strengthen DNS, proxy, and egress controls so unusual outbound C2 patterns can be logged, investigated, and constrained.
  • Prepare IR playbooks that join email, endpoint, DNS, and proxy evidence quickly when a suspected targeted intrusion begins with a file or exploit.
Additional notes and limits

This take is based on ATT&CK G0005 version 2.1 and the supplied relationships to software and techniques. The aliases and references are useful for threat intelligence correlation, but defenders should translate them into behavior-based validation rather than relying only on historical names.

MITRE provides no official detection text, no group-level platforms, and no group-level tactics in the supplied object. The relationship descriptions are partially summarized, and local telemetry, control configuration, and risk context are required before making any statement about organizational exposure or detection coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

APT12

APT12 is a threat group that has been attributed to China. The group has targeted a variety of victims including but not limited to media outlets, high-tech companies, and multiple governments.[1]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

5 rows
DomainIDNameRelationship / procedure
EnterpriseT1204.002Malicious FileSub-technique

APT12 has attempted to get victims to open malicious Microsoft Word and PDF attachment sent via spearphishing.[2][3]

EnterpriseT1102.002Bidirectional CommunicationSub-technique

APT12 has used blogs and WordPress for C2 infrastructure.[1]

EnterpriseT1568.003DNS CalculationSub-technique

APT12 has used multiple variants of DNS Calculation including multiplying the first two octets of an IP address and adding the third octet to that value in order to get a resulting command and control port.[1]

EnterpriseT1203Exploitation for Client Execution

APT12 has exploited multiple vulnerabilities for execution, including Microsoft Office vulnerabilities (CVE-2009-3129, CVE-2012-0158) and vulnerabilities in Adobe Reader and Flash (CVE-2009-4324, CVE-2009-0927, CVE-2011-0609, CVE-2011-0611).[2][3]

EnterpriseT1566.001Spearphishing AttachmentSub-technique

APT12 has sent emails with malicious Microsoft Office documents and PDFs attached.[2][3]

Associated objects

Groups, software, and campaigns

MalwareEnterprise

S0015: Ixeshe

Ixeshe is a malware family that has been used since at least 2009 against targets in East Asia. [1]

Windows
ToolEnterprise

S0040: HTRAN

HTRAN is a tool that proxies connections through intermediate hops and aids users in disguising their true geographical location. It can be used by adversaries to hide their location when interacting with the victim networks. [1][2]

LinuxWindows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.1
Created
Modified
Raw hash
79013e760380bcf2...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.12.1Current bundle79013e760380…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Meyers Numbered Panda

    Meyers, A. (2013, March 29). Whois Numbered Panda. Retrieved January 14, 2016.

  2. [2]
    Moran 2014

    Moran, N., Oppenheim, M., Engle, S., & Wartell, R.. (2014, September 3). Darwin’s Favorite APT Group [Blog]. Retrieved November 12, 2014.

    Open source URL
  3. [3]
    Trend Micro IXESHE 2012

    Sancho, D., et al. (2012, May 22). IXESHE An APT Campaign. Retrieved June 7, 2019.

    Open source URL
  4. [4]
    Moran 2013

    Moran, N., & Villeneuve, N. (2013, August 12). Survival of the Fittest: New York Times Attackers Evolve Quickly [Blog]. Retrieved November 17, 2024.

    Open source URL
  5. [5]
    APT12

    (Citation: Meyers Numbered Panda) (Citation: Moran 2014)

  6. [6]
    APT12

    (Citation: Meyers Numbered Panda) (Citation: Moran 2014)

  7. [7]
    APT12

    (Citation: Meyers Numbered Panda) (Citation: Moran 2014)

  8. [8]
    DNSCALC

    (Citation: Moran 2014)

  9. [9]
    DNSCALC

    (Citation: Moran 2014)

  10. [10]
    DNSCALC

    (Citation: Moran 2014)

  11. [11]
    DynCalc

    (Citation: Meyers Numbered Panda) (Citation: Moran 2014)

  12. [12]
    DynCalc

    (Citation: Meyers Numbered Panda) (Citation: Moran 2014)

  13. [13]
    DynCalc

    (Citation: Meyers Numbered Panda) (Citation: Moran 2014)

  14. [14]
    IXESHE

    (Citation: Meyers Numbered Panda) (Citation: Moran 2014)

  15. [15]
    IXESHE

    (Citation: Meyers Numbered Panda) (Citation: Moran 2014)

  16. [16]
    IXESHE

    (Citation: Meyers Numbered Panda) (Citation: Moran 2014)

  17. [17]
    Meyers Numbered Panda

    Meyers, A. (2013, March 29). Whois Numbered Panda. Retrieved January 14, 2016.

  18. [18]
    Meyers Numbered Panda

    Meyers, A. (2013, March 29). Whois Numbered Panda. Retrieved January 14, 2016.

  19. [19]
    Moran 2014

    Moran, N., Oppenheim, M., Engle, S., & Wartell, R.. (2014, September 3). Darwin’s Favorite APT Group [Blog]. Retrieved November 12, 2014.

    Open source URL
  20. [20]
    Moran 2014

    Moran, N., Oppenheim, M., Engle, S., & Wartell, R.. (2014, September 3). Darwin’s Favorite APT Group [Blog]. Retrieved November 12, 2014.

    Open source URL
  21. [21]
    Numbered Panda

    (Citation: Meyers Numbered Panda)

  22. [22]
    Numbered Panda

    (Citation: Meyers Numbered Panda)

  23. [23]
    Numbered Panda

    (Citation: Meyers Numbered Panda)

  24. [24]
    mitre-attackG0005
    Open source URL
  25. [25]
    mitre-attackG0005
    Open source URL
  26. [26]
    mitre-attackG0005
    Open source URL
  27. [27]
    Moran 2014

    Moran, N., Oppenheim, M., Engle, S., & Wartell, R.. (2014, September 3). Darwin’s Favorite APT Group [Blog]. Retrieved November 12, 2014.

    Open source URL
  28. [28]
    Moran 2014

    Moran, N., Oppenheim, M., Engle, S., & Wartell, R.. (2014, September 3). Darwin’s Favorite APT Group [Blog]. Retrieved November 12, 2014.

    Open source URL
  29. [29]
    Trend Micro IXESHE 2012

    Sancho, D., et al. (2012, May 22). IXESHE An APT Campaign. Retrieved June 7, 2019.

    Open source URL
  30. [30]
    Meyers Numbered Panda

    Meyers, A. (2013, March 29). Whois Numbered Panda. Retrieved January 14, 2016.

  31. [31]
    Meyers Numbered Panda

    Meyers, A. (2013, March 29). Whois Numbered Panda. Retrieved January 14, 2016.

  32. [32]
    Meyers Numbered Panda

    Meyers, A. (2013, March 29). Whois Numbered Panda. Retrieved January 14, 2016.

  33. [33]
    Meyers Numbered Panda

    Meyers, A. (2013, March 29). Whois Numbered Panda. Retrieved January 14, 2016.

  34. [34]
    Moran 2014

    Moran, N., Oppenheim, M., Engle, S., & Wartell, R.. (2014, September 3). Darwin’s Favorite APT Group [Blog]. Retrieved November 12, 2014.

    Open source URL
  35. [35]
    Moran 2014

    Moran, N., Oppenheim, M., Engle, S., & Wartell, R.. (2014, September 3). Darwin’s Favorite APT Group [Blog]. Retrieved November 12, 2014.

    Open source URL
  36. [36]
    Trend Micro IXESHE 2012

    Sancho, D., et al. (2012, May 22). IXESHE An APT Campaign. Retrieved June 7, 2019.

    Open source URL
  37. [37]
    Trend Micro IXESHE 2012

    Sancho, D., et al. (2012, May 22). IXESHE An APT Campaign. Retrieved June 7, 2019.

    Open source URL
  38. [38]
    Moran 2013

    Moran, N., & Villeneuve, N. (2013, August 12). Survival of the Fittest: New York Times Attackers Evolve Quickly [Blog]. Retrieved November 17, 2024.

    Open source URL
  39. [39]
    Moran 2014

    Moran, N., Oppenheim, M., Engle, S., & Wartell, R.. (2014, September 3). Darwin’s Favorite APT Group [Blog]. Retrieved November 12, 2014.

    Open source URL
  40. [40]
    Moran 2014

    Moran, N., Oppenheim, M., Engle, S., & Wartell, R.. (2014, September 3). Darwin’s Favorite APT Group [Blog]. Retrieved November 12, 2014.

    Open source URL
  41. [41]
    Moran 2014

    Moran, N., Oppenheim, M., Engle, S., & Wartell, R.. (2014, September 3). Darwin’s Favorite APT Group [Blog]. Retrieved November 12, 2014.

    Open source URL
  42. [42]
    Moran 2014

    Moran, N., Oppenheim, M., Engle, S., & Wartell, R.. (2014, September 3). Darwin’s Favorite APT Group [Blog]. Retrieved November 12, 2014.

    Open source URL
  43. [43]
    Trend Micro IXESHE 2012

    Sancho, D., et al. (2012, May 22). IXESHE An APT Campaign. Retrieved June 7, 2019.

    Open source URL
  44. [44]
    Trend Micro IXESHE 2012

    Sancho, D., et al. (2012, May 22). IXESHE An APT Campaign. Retrieved June 7, 2019.

    Open source URL
  45. [45]
    Moran 2014

    Moran, N., Oppenheim, M., Engle, S., & Wartell, R.. (2014, September 3). Darwin’s Favorite APT Group [Blog]. Retrieved November 12, 2014.

    Open source URL
  46. [46]
    Moran 2014

    Moran, N., Oppenheim, M., Engle, S., & Wartell, R.. (2014, September 3). Darwin’s Favorite APT Group [Blog]. Retrieved November 12, 2014.

    Open source URL
  47. [47]
    Trend Micro IXESHE 2012

    Sancho, D., et al. (2012, May 22). IXESHE An APT Campaign. Retrieved June 7, 2019.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.