Home/Threat Actor/Icefog
Threat Actor

Icefog

icefog · china · active since 2011

Icefog (Dagger Panda / APT-C-13 / G0011) is a suspected China- aligned cyber-espionage cluster active since at least 2011 and one of the foundational publicly-tracked China-aligned clusters in the public record, publicly disclosed in seminal September 25, 2013 Kaspersky GReAT report "The Icefog APT: A Tale of Cloak and Three Daggers", distinguished operationally by the defining hit-and-run tradecraft signature (short-duration intrusions of days-to-weeks, rapid selective exfiltration of specific targeted documents, operator-hands-on-keyboard precision-targeting, and removal of cluster artifacts following collection completion) that contrasts with the sustained-presence-implant pattern of most peer publicly-tracked APT clusters and suggests operational priorities aligned with specific tasking-driven collection rather than sustained-access-and-monitoring missions, defined by the signature IceFog Windows + macOS toolkit (with the report- title's "Three Daggers" referring to the Dagger Pro, Dagger Three, and MacFog variants, the macOS capability comparatively unusual among publicly-tracked clusters during the 2013-2018 period), and by sustained operations against approximately seventy victims including South Korean and Japanese government, military, defense industrial (shipbuilding, aerospace), shipping, telecommunications, satellite, news media, financial services, higher education, and supply-chain vendor targets.

contemporary operational status (post-2019) analytically open with substantially reduced vendor- tracking volume, treat post-2019 Icefog activity as analytically uncertain rather than confidently active.

china confidence: medium 18 aliases

Profile

Icefog (also tracked as Dagger Panda, APT-C-13, and MITRE ATT&CK G0011) is a suspected China-aligned cyber-espionage cluster active since at least 2011 and one of the foundational publicly- tracked China-aligned clusters in the public record. The cluster was publicly disclosed in seminal September 25, 2013 Kaspersky GReAT report "The Icefog APT: A Tale of Cloak and Three Daggers" , one of the most operationally consequential foundational China- aligned cluster reports. Kaspersky's attribution drew on victimology (concentrated targeting of Korean and Japanese government, defense industrial, shipping, telecommunications, aerospace, and media targets in regional adversarial relationships with China), operational hours consistent with Chinese time zones, and Chinese-language code artifacts in IceFog malware.

The specific Chinese government entity (MSS, PLA, or contractor) has not been formally established. No formal government attribution event has been issued. The cluster's most defining operational signature, and the element that most distinguishes Icefog from peer publicly- tracked clusters, is the hit-and-run tradecraft pattern.

Where most publicly-tracked APT clusters rely on sustained-presence implants for months-to-years of ongoing collection from compromised victim environments, Icefog operations were characterized by short-duration intrusions (days to weeks), rapid selective exfiltration of specific targeted documents, operator- hands-on-keyboard precision-targeting rather than broad scattershot collection, and removal of cluster artifacts following collection completion. The hit-and-run pattern was comparatively unusual at the time of 2013 disclosure and remains a distinctive cluster signature. The tradecraft suggests operational priorities aligned with specific tasking-driven collection (collect specific documents, exfil, move on) rather than sustained-access-and- monitoring missions, a meaningful operational-doctrine signal about the cluster's tasking authorities.

Operationally the cluster's signature toolkit is the IceFog malware family with both Windows and macOS variants (the macOS variant tracked as MacFog). The report-title's reference to "Three Daggers" referred to the IceFog Dagger Pro, Dagger Three, and MacFog variants. The macOS capability was comparatively unusual among publicly-tracked clusters during the 2013-2018 period and extended the cluster's reach into macOS-prevalent target environments (notably journalism, media, and selected research-and-academic environments).

Targeting focus was overwhelmingly directed at South Korean and Japanese government, military, defense industrial (shipbuilding, aerospace), shipping, telecommunications, satellite, news media, financial services, higher education, and supply-chain vendor targets. The supply-chain-vendor focus complemented the direct- target operations against government and defense entities and reflected operational interest in collecting intelligence from less-defended supply-chain partners about more-defended primary targets. The Korean Peninsula + Japan focus aligned with sustained Chinese intelligence interest in regional adversarial relationships during the period.

Initial-access tradecraft was predominantly spear-phishing with weaponized Office documents, particularly sustained exploitation of CVE-2012-0158 and CVE-2012-1856 (Microsoft Office RTF and Mscomctl vulnerabilities), CVE-2013-0640 and CVE-2013-0641 (Adobe PDF reader vulnerabilities), and CVE-2014-1761. The cluster did not consistently demonstrate 0day-development capability during the publicly-tracked period and primarily relied on rapid weaponization of disclosed n-day vulnerabilities. A handful of operational notes: First, the September 2013 Kaspersky disclosure was operationally consequential and triggered substantial cluster operational adjustments.

Apparent operational pause was followed by 2015 "Icefog reborn" reporting documenting continued activity under updated tradecraft, and 2018 selective continued reporting. The cluster's contemporary operational status (post-2019) has been analytically open with substantially reduced vendor-tracking volume. Second, the cluster is operationally distinct from peer publicly- tracked China-aligned clusters in the corpus despite some shared victim categories.

Comparison points
  • vs Tonto Team (already covered, tonto_team.yaml): both target Korea/Japan; Tonto Team operates sustained-presence Bisonal tradecraft, while Icefog operates hit-and-run IceFog tradecraft. Different operational doctrines.
  • vs APT10 / Stone Panda (already covered, apt10_stonepanda.yaml): both target Japan; APT10 operates managed-service-provider supply-chain tradecraft (Operation Cloud Hopper), while Icefog operates direct-victim hit-and-run tradecraft.
  • vs APT17 / Aurora Panda (already covered, apt17_aurora_panda.yaml): different victim emphasis and tradecraft. Third, the cluster's contemporary operational status warrants analytical caution. Treat post-2019 Icefog activity as analytically uncertain rather than confidently active. Possible operational fates include: continued operations under modified tradecraft and rebranded naming streams, operational retirement and personnel reassignment to other Chinese-aligned cluster ecosystems, or consolidation into broader contemporary cluster identities. Public reporting has not formally resolved the question. Fourth, the Icefog disclosure is historically consequential beyond the cluster's specific operations, Kaspersky's 2013 report contributed substantially to the broader threat- intelligence community understanding of how state-aligned cyber-espionage operations could employ tradecraft other than the dominant sustained-presence-APT pattern. The hit-and-run doctrine has subsequently been documented in other clusters and represents a meaningful operational-doctrine variant.

Aliases

18
icefogice fogice_fogdagger pandadagger_pandadaggerpandadagger chinadagger_chinaicefog rebornicefog_rebornicefog picefog_papt-c-13apt_c_13aptc13g0011atk 30atk30

Notable Campaigns

7
2019-2025Contemporary Status Open Question (2019-2025)
2015-2018Icefog Reborn, Continued Reporting (2015-2018)
2013-2018macOS IceFog (MacFog) Variant (2013-2018)
2013Kaspersky GReAT: The Icefog APT, A Tale of Cloak and Three Daggers (September 25, 2013)
2011-2018Hit-and-Run Tradecraft Signature (2011-2018)
2011-2018Korean and Japanese Supply Chain Targeting (2011-2018)
2011-2013Pre-Disclosure Korean and Japanese Targeting Operations (2011-2013)

Attribution & Reporting

Attributed by
Kaspersky GReATESETTrend MicroSymantec (Broadcom)Mandiant / FireEyeCrowdStrikeCisco TalosSentinelOneJPCERT/CCLAC Co. Ltd. (Japan)ESTSecurity (Korea)AhnLab (Korea)NSHC / Threat Recon (Korea)Recorded Future Insikt Group360 Threat Intelligence CenterQiAnXin Threat Intelligence CenterGroup-IBCitizen Lab (University of Toronto)
Key reporting
reportKaspersky GReAT: The Icefog APT, A Tale of Cloak and Three Daggers (September 25, 2013), seminal cluster disclosure
reportKaspersky GReAT: The Icefog APT Hits US Targets with Java Backdoor (January 2014)
reportKaspersky GReAT: Icefog Reborn (multiple years)
reportESET: The Icefog Malware Attacking Asian Organizations (September 2013)
reportTrend Micro: Icefog APT Analysis Whitepaper
reportSymantec: Icefog APT Strikes Japanese and Korean Targets (October 2013)
reportJPCERT/CC: Icefog Activity in Japan (Japanese-language reporting)
reportLAC Co. Ltd. (Japan): Icefog Continued Tracking
reportESTSecurity (Korea): Icefog Korean-language Tracking
reportAhnLab (Korea): Icefog Continued Tracking
reportSekoia: Icefog China Historical Tracking (2023-2024)
reportMalpedia Actor Profile: Icefog
reportMITRE ATT&CK Group G0011, Icefog

Operational

State sponsor

Suspected China-aligned cyber-espionage cluster, attributed by seminal Kaspersky GReAT September 25, 2013 disclosure "The Icefog APT: A Tale of Cloak and Three Daggers" to actors operating in alignment with Chinese state intelligence interests. Kaspersky's attribution methodology drew on victimology (concentrated targeting of Korean and Japanese government, defense industrial, shipping, telecommunications, aerospace, and media targets in regional adversarial relationships with China), operational hours consistent with Chinese time zones, Chinese-language code artifacts in IceFog malware, and Chinese-language operational strings. The specific Chinese government entity (Ministry of State Security / MSS, People's Liberation Army / PLA, or contractor entity) has not been formally established. No formal US, UK, EU, Japanese, Korean, or other government attribution event has been issued.

the China-aligned framing rests on Kaspersky research and subsequent vendor consensus and should be treated as suspected rather than formally confirmed. The cluster represents one of the foundational publicly-tracked China-aligned clusters with operations documented since at least 2011 (with Kaspersky retrospective analysis suggesting possible earlier activity). The September 2013 Kaspersky disclosure was operationally consequential and triggered substantial cluster operational adjustments, including apparent operational pause followed by 2015 "Icefog reborn" reporting documenting continued activity under updated tradecraft, and 2018 selective continued reporting. The cluster's contemporary operational status has been analytically open with reduced vendor-tracking volume after approximately 2018.

Motivations
espionage, intelligence_gathering, economic_espionage, intellectual_property_theft, industrial_intelligence, geopolitical_collection, regional_intelligence, korean_peninsula_collection, japan_collection, supply_chain_intelligence
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)59/60 · 98%
Analytics (MITRE CAR)27/60 · 45%
Runtime / container (Falco)8/60 · 13%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)17/60 · 28%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

2 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MAC FOGMACFOGMSHTASELECTIVE DOCUMENT COLLECTIONSHORT DURATION INTRUSION
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin