
Bronze President
PlugXTA428ORatCobalt StrikeRC Session
Bronze President is a likely Chinese government-sponsored threat group that has been active since at least 2012. It is known for conducting cyber-espionage campaigns targeting organizations and individuals in the Asia-Pacific region and beyond.
Indicators of Compromise
mktoon.ftp1.bizSOCRadar2023-02-02
f1news.vzglagtime.netSOCRadar2023-02-02
91ac64d2.netSOCRadar2023-02-02
www1.dotomater.clubSOCRadar2023-02-02
host.microlynconline.comSOCRadar2023-02-02
sherence.ruSOCRadar2023-02-02
intranet.mrpam.gov.mnSOCRadar2023-02-02
help.microlynconline.comSOCRadar2023-02-02
moneybac.ruSOCRadar2023-02-02
lutanedukasi.co.idSOCRadar2023-02-02
tombstone.kozow.comSOCRadar2023-02-02
playdr2.comSOCRadar2023-02-02
mail.playdr2.comSOCRadar2023-02-02
www.zyber-i.comSOCRadar2023-02-02
www.ciphertechsolutions.comSOCRadar2023-02-02
fax.internnetionfax.comSOCRadar2023-02-02
serviechelp.changeip.usSOCRadar2023-02-02
shareddocs.microft.dynssl.comSOCRadar2023-02-02
able.audit.mnSOCRadar2023-02-02
nameserver.datacertsecure.infoSOCRadar2023-02-02
govi-altai.ecustoms-mn.comSOCRadar2023-02-02
lllllllllll.loseyourip.comSOCRadar2023-02-02
9f78281a.orgSOCRadar2023-02-02
b.popmonster.ruSOCRadar2023-02-02
ybcps4.freeddns.orgSOCRadar2023-02-02
fuckeryoumm.nmb.betSOCRadar2023-02-02
www.myanmarnewsonline.orgSOCRadar2023-02-02
check.datacertsecure.infoSOCRadar2023-02-02
9f78281a.netSOCRadar2023-02-02
ve0.popmonster.ruSOCRadar2023-02-02
home.microlynconline.comSOCRadar2023-02-02
www3.vpkimplus.comSOCRadar2023-02-02
gazar.ecustoms-mn.comSOCRadar2023-02-02
kamikirim.my.idSOCRadar2023-02-02
datetime.datetime.nowSOCRadar2023-02-02
ecustoms-mn.comSOCRadar2023-02-02
microsite-manager.comSOCRadar2023-02-02
nubia.tsagagaar.comSOCRadar2023-02-02
oss.chrome-upgrade.comSOCRadar2023-02-02
doc.redstrpela.netSOCRadar2023-02-02
hacktool.win64.agent.hkSOCRadar2023-02-02
installcb.onlineSOCRadar2023-02-02
alex.dnset.comSOCRadar2023-02-02
server.dotomater.clubSOCRadar2023-02-02
mod.mmgpms.comSOCRadar2023-02-02
backdoor.win32.agentb.caSOCRadar2023-02-02
mtanews.vzglagtime.netSOCRadar2023-02-02
oemprint.catSOCRadar2023-02-02
91ac64d2.comSOCRadar2023-02-02
lib.hostareas.comSOCRadar2023-02-02
news.vzglagtime.netSOCRadar2023-02-02
xre.popmonster.ruSOCRadar2023-02-02
backdoor.win32.agentb.ccSOCRadar2023-02-02
toon.mrbasic.comSOCRadar2023-02-02
custom.songuulcomiss.comSOCRadar2023-02-02
able.tog.mnSOCRadar2023-02-02
microft.dynssl.comSOCRadar2023-02-02
kdr.zarkada.ruSOCRadar2023-02-02
6b4s.popmonster.ruSOCRadar2023-02-02
go.vegispaceshop.orgSOCRadar2023-02-02
pop.playdr2.comSOCRadar2023-02-02
elienceso.kozow.comSOCRadar2023-02-02
images.myanmarnewsonline.orgSOCRadar2023-02-02
d802f446.comSOCRadar2023-02-02
48b2137f.comSOCRadar2023-02-02
d802f446.orgSOCRadar2023-02-02
web.microlynconline.comSOCRadar2023-02-02
9356.popmonster.ruSOCRadar2023-02-02
ns2.gamepoer7.comSOCRadar2023-02-02
developer.firefoxapi.comSOCRadar2023-02-02
gamepoer7.comSOCRadar2023-02-02
niigem.olloo-news.comSOCRadar2023-02-02
ksbyz.jelikob.ruSOCRadar2023-02-02
update.flashplayeractivex.infoSOCRadar2023-02-02
nmcustoms.https443.orgSOCRadar2023-02-02
www2.defensysminck.netSOCRadar2023-02-02
mashupdatabase.comSOCRadar2023-02-02
ns9.mcafee-update.comSOCRadar2023-02-02
gogonews.organiccrap.comSOCRadar2023-02-02
flashplayeractivex.infoSOCRadar2023-02-02
lck.gigabitdate.comSOCRadar2023-02-02
www1.nppnavigator.netSOCRadar2023-02-02
rt.ftp1.bizSOCRadar2023-02-02
trojan.win64.dllhijacker.kmSOCRadar2023-02-02
48b2137f.orgSOCRadar2023-02-02
tsagagaar.comSOCRadar2023-02-02
www.atomicmatryoshka.comSOCRadar2023-02-02
news.flashplayeractivex.infoSOCRadar2023-02-02
api.microft.dynssl.comSOCRadar2023-02-02
www2.sdelanasnou.comSOCRadar2023-02-02
48b2137f.netSOCRadar2023-02-02
web.miscrosaft.comSOCRadar2023-02-02
d802f446.netSOCRadar2023-02-02
ftp.microft.dynssl.comSOCRadar2023-02-02
aircraft.tsagagaar.comSOCRadar2023-02-02
findanswer123.tkSOCRadar2023-02-02
www.omgod.orgSOCRadar2023-02-02
upespr.comSOCRadar2023-02-02
download.hilifimyanmar.comSOCRadar2023-02-02
chdsjjkrazomg.dhcp.bizSOCRadar2023-02-02
rootkiter.comSOCRadar2023-02-02
bamo.ocry.comSOCRadar2023-02-02
blogdirve.comSOCRadar2023-02-02
info.ntcprotek.comSOCRadar2023-02-02
update.hilifimyanmar.comSOCRadar2023-02-02
m.watercaltropinfo.comSOCRadar2023-02-02
9f78281a.comSOCRadar2023-02-02
91ac64d2.orgSOCRadar2023-02-02
tech.songuulcomiss.comSOCRadar2023-02-02
video.nicblainfo.netSOCRadar2023-02-02
txt.mm-film.comSOCRadar2023-02-02
olloo-news.comSOCRadar2023-02-02
datacertsecure.infoSOCRadar2023-02-02
www.watercaltropinfo.comSOCRadar2023-02-02
e-office.dbm.mnSOCRadar2023-02-02
vzglagtime.netSOCRadar2023-02-02
APT Groups1
TA428China
Vicious PandaThunderCatsTEMP.HexPKPLUGCamaro DragonEarth PretaPandaStately TaurusHoneyMyteBronze PresidentTA428Bronze DudleyMustang PandaRed Lich
Campaign Guidance
Remediation, mitigation, notes, history and related intelligence
Observed Countries16
AF (33)
AU (204)
BY (942)
CA (906)
GE (37)
HK (538)
IN (92)
JP (410)
MM (702)
MN (686)
NZ (996)
PH (646)
RU (620)
SG (886)
UA (501)
US (194)