Icefog, also known as Fucobha, is a family of interactively controlled espionage backdoors active since at least 2011 and publicly identified in 2013. Its early operations primarily targeted Japan and South Korea, including government institutions, military contractors, maritime and shipbuilding organizations, telecommunications operators, technology companies, research institutions, and media organizations. Operators used a focused, hit-and-run approach: inspecting compromised systems, locating selected documents, archiving and exfiltrating them, and then abandoning the victims rather than maintaining prolonged surveillance.
Icefog supports system reconnaissance, remote command execution, bidirectional file transfers, and deployment of additional malware. Some Windows variants also allow operators to execute SQL commands against accessible Microsoft SQL Server systems. Operators deployed password and hash dumpers and browser and email credential-recovery utilities alongside the backdoor. Windows variants used HTTP, email-based, or custom TCP command-and-control mechanisms, with persistence and DLL search-order hijacking present in some versions. The macOS variant, Macfog, supports system-information collection, command execution, file transfers, and persistence through launch agents.
Delivery methods included spear-phishing attachments and links, malicious Microsoft Office and Hangul Word Processor documents, Java exploits, and WinHelp macro abuse. Confirmed exploited vulnerabilities included CVE-2012-0158, CVE-2012-1856, CVE-2012-1723, and CVE-2013-0422. Macfog was distributed through Chinese forums as a trojanized application. Icefog has also been used by RedFoxtrot and the Operation Redbonus activity cluster; these later associations do not establish a definitive sponsor for its original campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2012-1856 (the “Tran Duy Linh” exploit fixed in Microsoft’s MS12-060 security bulletin). The attachment is a standard “Tran Duy Linh” exploit for CVE-2012-1856. | The “Icefog” backdoor set (also known as “Fucobha”) is an interactive espionage tool that is directly controlled by the attackers.
During our investigation, we identified several types of exploits being used through spear-phishing e-mails against the targets: ... Web links to Oracle Java exploits (CVE-2013-0422 and CVE-2012-1723). | The “Icefog” backdoor set (also known as “Fucobha”) is an interactive espionage tool that is directly controlled by the attackers.
CVE-2012-0158 (the MSCOMCTL.OCX remote code execution vulnerability fixed with Microsoft’s MS12-027 security bulletin). The first two vulnerabilities are exploited through Microsoft Office documents (Word and Excel) that drop and execute the backdoor and show a fake “lure” document to the victim. | The “Icefog” backdoor set (also known as “Fucobha”) is an interactive espionage tool that is directly controlled by the attackers.
During our investigation, we identified several types of exploits being used through spear-phishing e-mails against the targets: ... Web links to Oracle Java exploits (CVE-2013-0422 and CVE-2012-1723). | The “Icefog” backdoor set (also known as “Fucobha”) is an interactive espionage tool that is directly controlled by the attackers.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
During our investigations, we also spotted other backdoors in use, such as Whitebird, IceFog and a customized instance of PCShare.
The “Icefog” backdoor set (also known as “Fucobha”) is an interactive espionage tool that is directly controlled by the attackers.
RedFoxtrot maintains large amounts of operational infrastructure and has likely employed both bespoke and publicly available malware families commonly used by Chinese cyber espionage groups, including Icefog, PlugX, Royal Road, Poison Ivy, ShadowPad, and PCShare.
RedFoxtrot maintains large amounts of operational infrastructure and has likely employed both bespoke and publicly available malware families commonly used by Chinese cyber espionage groups, including Icefog, PlugX, Royal Road, Poison Ivy, ShadowPad, and PCShare.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
145 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor used in attacks in the APAC region, especially Japan and South Korea; described as part of a prior Olympics-themed attack and associated with methodical targeting.
Chinese cyber espionage malware used by RedFoxtrot; historically delivered via Royal Road and used in campaigns targeting Central Asia, Pakistan, and India.
Used as a historical comparison for sophisticated operations targeting platforms beyond Windows, and as a complexity benchmark. No operational relationship to The Mask is established.
A backdoor used by Operation Redbonus alongside ShadowPad and other payloads. The report notes the cluster's interest in Indian targets but does not describe IceFog's capabilities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.