CactusPete

  • First known sample

    2013
  • Discovery

    2013
  • Current status

    Active
  • Type

    APT
  • Targeted platforms

    OS X , Windows
  • TOP targeted countries

    Eastern Europe , Japan , South Korea , Taiwan , USA
  • The way of propagation

    Exploits , Phishing emails
  • Purpose/Functions

    Cyberespionage
  • Targets

    Defense industrial base , Diplomatic organizations/embassies , Energy , Financial institutions , Government entities , Military , Telecoms
  • Artefacts/Attribution

    Chinese-speaking

  • Description

    This cyberespionage group has been active since at least 2012 and is known for campaigns against military, diplomatic, and infrastructure targets in Asia and Eastern Europe. They typically distribute their custom backdoor (Bisonal) via spear-phishing emails containing malicious attachments. Their success primarily comes from their effective application of social engineering tactics, rather than their malware’s sophistication.

    Additional information