Naikon
Also reported as Hellsing, PLA Unit 78020, OVERRIDE PANDA, Camerashy, BRONZE GENEVA and 4 other names. Linked to China by three sources.
Reports per quarter
Techniques seen in the last two years
- T1027 2 reports reports only
- T1036.005 2 reports in ATT&CK
- T1059.001 2 reports reports only
- T1082 2 reports reports only
- T1132.001 2 reports reports only
- T1140 2 reports reports only
- T1204.002 2 reports in ATT&CK
- T1547.001 2 reports in ATT&CK
- T1566.001 2 reports in ATT&CK
- T1573.001 2 reports reports only
Show all 38 techniques Show fewer
- T1001.003 1 report reports only
- T1012 1 report reports only
- T1027.009 1 report reports only
- T1036.007 1 report reports only
- T1041 1 report reports only
- T1055 1 report reports only
- T1055.012 1 report reports only
- T1057 1 report reports only
- T1071.001 1 report reports only
- T1083 1 report reports only
- T1102 1 report reports only
- T1105 1 report reports only
- T1106 1 report reports only
- T1129 1 report reports only
- T1189 1 report reports only
- T1218 1 report reports only
- T1218.007 1 report reports only
- T1218.014 1 report reports only
- T1497.001 1 report reports only
- T1553.002 1 report reports only
- T1566.002 1 report reports only
- T1574 1 report reports only
- T1574.001 1 report in ATT&CK
- T1583.001 1 report reports only
- T1583.003 1 report reports only
- T1587.001 1 report reports only
- T1608.001 1 report reports only
- T1627.001 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2008-3431 KEV
- CVE-2010-0232 KEV
- CVE-2010-1424
- CVE-2010-2152
- CVE-2010-3333 KEV
- CVE-2010-3915
- CVE-2010-3916
- CVE-2010-4398 KEV
- CVE-2011-1331
- CVE-2011-2462 KEV
- CVE-2011-3402 KEV
- CVE-2011-3544 KEV
Show all 145 CVEs Show fewer
- CVE-2012-0158 KEV ransomware
- CVE-2012-1856 KEV
- CVE-2012-4792 KEV
- CVE-2012-5687
- CVE-2013-0707
- CVE-2013-3644
- CVE-2013-3893 KEV
- CVE-2013-3900 KEV
- CVE-2013-3918 KEV
- CVE-2013-5947
- CVE-2013-5990
- CVE-2014-0160 KEV
- CVE-2014-0322 KEV
- CVE-2014-0810
- CVE-2014-1225
- CVE-2014-1761 KEV
- CVE-2014-1776 KEV
- CVE-2014-2962
- CVE-2014-4019
- CVE-2014-4113 KEV
- CVE-2014-6271 KEV
- CVE-2014-6277
- CVE-2014-6278 KEV
- CVE-2014-7169 KEV
- CVE-2014-7186
- CVE-2014-7187
- CVE-2014-7247
- CVE-2014-8361 KEV
- CVE-2014-9583
- CVE-2015-0554
- CVE-2015-2360 KEV
- CVE-2015-5119 KEV
- CVE-2015-7248
- CVE-2015-7254
- CVE-2015-7645 KEV ransomware
- CVE-2016-1019 KEV ransomware
- CVE-2016-4117 KEV ransomware
- CVE-2016-5195 KEV
- CVE-2016-7836 KEV
- CVE-2017-0199 KEV ransomware
- CVE-2017-0213 KEV ransomware
- CVE-2017-0261 KEV
- CVE-2017-1182
- CVE-2017-11882 KEV ransomware
- CVE-2017-118822
- CVE-2017-15944 KEV
- CVE-2017-7269 KEV
- CVE-2017-8570 KEV
- CVE-2017-8759 KEV
- CVE-2018-0171 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-1207
- CVE-2018-13379 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2018-8570
- CVE-2018-8641
- CVE-2018-8653 KEV
- CVE-2019-0604 KEV ransomware
- CVE-2019-10149 KEV
- CVE-2019-11510 KEV ransomware
- CVE-2019-1367 KEV ransomware
- CVE-2019-1429 KEV
- CVE-2019-16098
- CVE-2019-1652 KEV
- CVE-2019-1653 KEV
- CVE-2019-17100
- CVE-2019-19781 KEV ransomware
- CVE-2019-2215 KEV
- CVE-2019-9489
- CVE-2019-9670 KEV
- CVE-2020-0674 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-0986 KEV
- CVE-2020-10189 KEV
- CVE-2020-1380 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-1664
- CVE-2020-2021 KEV ransomware
- CVE-2020-5135 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2020-8468 KEV
- CVE-2021-1675 KEV ransomware
- CVE-2021-1732 KEV ransomware
- CVE-2021-22555 KEV
- CVE-2021-22893 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-28310 KEV
- CVE-2021-31195
- CVE-2021-31196 KEV
- CVE-2021-31206
- CVE-2021-31207 KEV ransomware
- CVE-2021-31955 KEV
- CVE-2021-31956 KEV
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-34527 KEV ransomware
- CVE-2021-4034 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-4104
- CVE-2021-44207 KEV
- CVE-2021-44228 KEV ransomware
- CVE-2021-45046 KEV ransomware
- CVE-2021-45105
- CVE-2022-1040 KEV
- CVE-2022-21587 KEV ransomware
- CVE-2022-24682 KEV ransomware
- CVE-2022-24934
- CVE-2022-27924 KEV ransomware
- CVE-2022-27925 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2022-30333 KEV ransomware
- CVE-2022-37042 KEV ransomware
- CVE-2022-41040 KEV ransomware
- CVE-2022-41082 KEV ransomware
- CVE-2022-41328 KEV
- CVE-2022-42475 KEV ransomware
- CVE-2022-47986 KEV ransomware
- CVE-2022-49475
- CVE-2024-0012 KEV ransomware
- CVE-2024-24919 KEV ransomware
- CVE-2025-29824 KEV ransomware
- CVE-2025-32433 KEV
- CVE-2025-49704 KEV ransomware
- CVE-2025-49706 KEV ransomware
- CVE-2025-53770 KEV ransomware
- CVE-2025-53771
- CVE-2025-6218 KEV
- CVE-2025-8088 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Naikon, Lotus Panda - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Naikon, Lotus Panda - Threat Group Cards: A Threat Actor Encyclopedia
-
ICIT Brief – China’s Espionage Dynasty: Economic Death by a Thousand Cuts
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor ICIT Brief – China’s Espionage Dynasty: Economic Death by a Thousand Cuts
Show all 223 reports Show fewer
-
Wirtschaftsspionage gegen Volkwagen: VW-Konzern wurde jahrelang ausge…
The title opens archive.today, not the publisher’s page. Archived copy on ORKL Detailsfor Wirtschaftsspionage gegen Volkwagen: VW-Konzern wurde jahrelang ausge…
-
MustangPanda%20-%20Enemy%20at%20the%20gate_final.pdf
The original link failed its last check. Original publisher Detailsfor MustangPanda%20-%20Enemy%20at%20the%20gate_final.pdf
-
Chinese Naikon Group Back with New Espionage Attack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese Naikon Group Back with New Espionage Attack
-
The LOTUS PANDA Is Awake, Again. Analysis Of Its Last Strike.
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The LOTUS PANDA Is Awake, Again. Analysis Of Its Last Strike.
-
yir-cyber-threats-annex-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-annex-download.pdf
-
APT_trends_report_Q2_2021_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q2_2021_Securelist
-
DeadRinger_ Exposing Chinese Threat Actors Targeting Major Telcos
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor DeadRinger_ Exposing Chinese Threat Actors Targeting Major Telcos
-
DeadRinger- Exposing Chinese Threat Actors Targeting Major Telcos
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor DeadRinger- Exposing Chinese Threat Actors Targeting Major Telcos
-
Mustang Panda PlugX - 45.251.240.55 Pivot
The original link failed its last check. Original publisher Detailsfor Mustang Panda PlugX - 45.251.240.55 Pivot
-
Chinese Cyberspies Target Military Organizations in Asia With New Malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese Cyberspies Target Military Organizations in Asia With New Malware
-
Cyberspies target military organizations with new Nebulae backdoor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cyberspies target military organizations with new Nebulae backdoor
-
Bitdefender-PR-Whitepaper-NAIKON-creat5397-en-EN
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Bitdefender-PR-Whitepaper-NAIKON-creat5397-en-EN
-
Higaisa or Winnti? APT41 backdoors, old and new
The original link failed its last check. Original publisher Detailsfor Higaisa or Winnti? APT41 backdoors, old and new
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor nao-sec.org-Royal Road ReDive
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Royal Road! Re-Dive
-
Group-IB_Hi-Tech_Crime_Trends_2020-2021_en
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2020-2021_en
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor IT threat evolution Q2 2020
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Suspected Naikon DGA Domains
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Naikon’s Aria
-
Naikon APT_ Cyber Espionage Reloaded - Check Point Research
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Naikon APT_ Cyber Espionage Reloaded - Check Point Research
-
Naikon APT- Cyber Espionage Reloaded
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Naikon APT- Cyber Espionage Reloaded
-
Is APT 27 Abusing COVID-19 To Attack People !
The original link failed its last check. Detailsfor Is APT 27 Abusing COVID-19 To Attack People !
-
cds19-executive-s08-achievement-unlocked.pdf
The original link failed its last check. Original publisher Detailsfor cds19-executive-s08-achievement-unlocked.pdf
-
The original link failed its last check. Original publisher Detailsfor Analytics
-
Into the Fog - The Return of ICEFOG APT
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Into the Fog - The Return of ICEFOG APT
-
The original link failed its last check. Original publisher Detailsfor Accenture Strategy Templates
-
LuckyMouse hits national data center to organize country-level waterholing campaign - Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor LuckyMouse hits national data center to organize country-level waterholing campaign - Securelist
-
JadeRAT mobile surveillanceware spikes in espionage activity
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor JadeRAT mobile surveillanceware spikes in espionage activity
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Naikon Targeted Attacks
-
ICIT-Brief-China-Espionage-Dynasty
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ICIT-Brief-China-Espionage-Dynasty
-
The original link failed its last check. Original publisher Detailsfor security_report_20160613.pdf
-
The Anthem Hack_ All Roads Lead to China - ThreatConnect _ Enterprise Threat Intelligence Platform
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Anthem Hack_ All Roads Lead to China - ThreatConnect _ Enterprise Threat Intelligence Platform
-
Know Your Enemies 2.0: A Primer on Advanced Persistent Threat Groups
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Know Your Enemies 2.0: A Primer on Advanced Persistent Threat Groups
-
Project_CAMERASHY_ThreatConnect_Copyright_2015
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Project_CAMERASHY_ThreatConnect_Copyright_2015
-
Uncovering the Seven Pointed Dagger
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Uncovering the Seven Pointed Dagger
-
The Msnmm Campaigns: The Earliest Naikon APT Campaigns
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Msnmm Campaigns: The Earliest Naikon APT Campaigns
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Naikon APT
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Naikon APT
-
2015-05-29 -The MsnMM Campaigns - The Earliest Naikon APT Campaigns
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2015-05-29 -The MsnMM Campaigns - The Earliest Naikon APT Campaigns
-
The Chronicles Of The Hellsing APT: The Empire Strikes Back
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Chronicles Of The Hellsing APT: The Empire Strikes Back
-
The Chronicles of the Hellsing APT- the Empire Strikes Back
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Chronicles of the Hellsing APT- the Empire Strikes Back
-
Hellsing Indicators Of Compromise
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Hellsing Indicators Of Compromise
-
The Chronicles of the Hellsing APT_the Empire Strikes Back
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Chronicles of the Hellsing APT_the Empire Strikes Back
-
Elite cyber crime group strikes back after attack by rival APT gang
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Elite cyber crime group strikes back after attack by rival APT gang
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Global Threat Intel Report
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Spear Phishing the News Cycle- APT Actors Leverage Interest in the Disappearance of Malaysian Flight MH 370
-
BKDR_RARSTONE: New RAT to Watch Out For - TrendLabs Security Intelligence Blog
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor BKDR_RARSTONE: New RAT to Watch Out For - TrendLabs Security Intelligence Blog
Newest first. Details opens the report in Explore.