Icefrog APT

Type: Cyber mercenary

Status: Inactive since 2013

Other Names: Danger Panda/ Dagger Three

Active Since/Discovered: 2011/ 2013

Targets: South Korea, Japan, China, US

Target Sectors: Government, military, maritime, telecommunications, satellite, media, energy, high-tech

Malware:

Preferred Attack Vector:  Social Engineering

TTP:

  • Targeted supply chain
  • Hijacked sensitive documents, company plans, email credentials, etc

Unique:

  • File theft was not automated
    • Attacker picked files one by one