NetTraveler, APT 21, Hammer Panda

Description

(Kaspersky) Over the last few years, we have been monitoring a cyber-espionage campaign that has successfully compromised more than 350 high profile victims in 40 countries. The main tool used by the threat actors during these attacks is NetTraveler, a malicious program used for covert computer surveillance.

The name NetTraveler comes from an internal string which is present in early versions of the malware: NetTraveler Is Running! This malware is used by APT actors for basic surveillance of their victims. Earliest known samples have a timestamp of 2005, although references exist indicating activity as early as 2004. The largest number of samples we observed were created between 2010 and 2013.

The later group RedAlpha has infrastructure overlap with NetTraveler.

Names

NameName-Giver
NetTravelerKaspersky
APT 21Mandiant
Hammer PandaCrowdStrike
TEMP.ZhenbaoFireEye

Country

Motivation

  • Information theft and espionage

First Seen

2004

Observed Sectors

Observed Countries

Tools

Operations

Information

Other Information

Uuid

8650e8c5-55a5-4441-8903-0f2bf5753ef1

Last Card Change

2020-04-19