Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.
Also known as: Icefog, Dagger Panda, ATK 23, Red Wendigo, IceFog, Trident, RedFoxtrot, PLA Unit 69010, UAT-7290, Red Foxtrot
“Icefog” is an Advanced Persistent Threat that has been active since at least 2011, targeting mostly Japan and South Korea. Known targets include governmental institutions, military contractors, maritime and shipbuilding groups, telecom operators, industrial and high-tech companies and mass media. The name “Icefog” comes from a string used in the command-and-control server name in one of the samples. The command-and-control software is named “Dagger Three”, in the Chinese language. During Icefog attacks, several other malicious tools and backdoors were uploaded to the victims’ machines, for data exfiltration and lateral movement. The later group RedAlpha has infrastructure overlap with Icefog.
No exploited CVEs have been attributed to this threat actor yet.
Browse CVE Database