All actors

APT17

Also reported as Hidden Lynx, Heart Typhoon, Group 8, Tailgater Team, Elderwood and 24 other names. Linked to China by four sources.

Reports
333
Last reported
Known CVEs
220
Techniques in ATT&CK
2
Origin
China
ID
G0025
Merge evidence
35 alias matches

Reports per quarter

  1. 2013 Q1: 1 report
  2. 2013 Q2: no reports
  3. 2013 Q3: 5 reports
  4. 2013 Q4: 1 report
  5. 2014 Q1: 4 reports
  6. 2014 Q2: no reports
  7. 2014 Q3: 2 reports
  8. 2014 Q4: 5 reports
  9. 2015 Q1: 2 reports
  10. 2015 Q2: 5 reports
  11. 2015 Q3: 4 reports
  12. 2015 Q4: 5 reports
  13. 2016 Q1: 3 reports
  14. 2016 Q2: 4 reports
  15. 2016 Q3: 4 reports
  16. 2016 Q4: no reports
  17. 2017 Q1: 1 report
  18. 2017 Q2: 8 reports
  19. 2017 Q3: 10 reports
  20. 2017 Q4: 7 reports
  21. 2018 Q1: 7 reports
  22. 2018 Q2: 5 reports
  23. 2018 Q3: 6 reports
  24. 2018 Q4: 4 reports
  25. 2019 Q1: 1 report
  26. 2019 Q2: 4 reports
  27. 2019 Q3: 12 reports
  28. 2019 Q4: 8 reports
  29. 2020 Q1: 14 reports
  30. 2020 Q2: 7 reports
  31. 2020 Q3: 13 reports
  32. 2020 Q4: 7 reports
  33. 2021 Q1: 9 reports
  34. 2021 Q2: 6 reports
  35. 2021 Q3: 13 reports
  36. 2021 Q4: 7 reports
  37. 2022 Q1: 13 reports
  38. 2022 Q2: 20 reports
  39. 2022 Q3: 10 reports
  40. 2022 Q4: 9 reports
  41. 2023 Q1: 9 reports
  42. 2023 Q2: 4 reports
  43. 2023 Q3: 9 reports
  44. 2023 Q4: 3 reports
  45. 2024 Q1: 8 reports
  46. 2024 Q2: 5 reports
  47. 2024 Q3: 5 reports
  48. 2024 Q4: 1 report
  49. 2025 Q1: 10 reports
  50. 2025 Q2: 2 reports
  51. 2025 Q3: 1 report
  52. 2025 Q4: 3 reports
  53. 2026 Q1: 3 reports
  54. 2026 Q2: 23 reports
  55. 2026 Q3: 1 report
Dated reports, 2013 Q1 to 2026 Q3.

Techniques seen in the last two years

Show all 52 techniques Show fewer

Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.

Also listed by ATT&CK

CVEs named in reports

Show all 220 CVEs Show fewer

KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.

Reports

  1. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

  2. APT 17, Deputy Dog, Elderwood, Sneaky Panda

    date ORKL added it fromORKL

Show all 333 reports Show fewer
  1. Council on Foreign Relations

    date ORKL added it fromORKL

  2. Operation Aurora

    date ORKL added it fromORKL

  3. ZXShell (Malware Family)

    date ORKL added it fromORKL

  4. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

  5. Security Response - Black Vine Cyberespionage Group.pdf

    date ORKL added it fromORKL

  6. Ruxcon%202015%20-%20McCormack.pdf

    date ORKL added it fromORKL

  7. yir-cyber-threats-annex-download.pdf

    Malpedia library date fromORKL

  8. Unmasking China’s State Hackers

    date in the title fromORKL

  9. A Realistic Analysis of the Stuxnet Cyber-attack.pdf

    file creation date fromORKL

  10. The many tentacles of Magecart Group 8

    date in the title fromORKL

  11. Презентация PowerPoint

    Malpedia library date fromORKL

  12. Prevailion Blog

    Malpedia library date fromORKL

  13. Mustang Panda PlugX - 45.251.240.55 Pivot

    Malpedia library date fromORKL

  14. the-operations-of-winnti-group.pdf

    Malpedia library date fromORKL

  15. winnti-2020-rus.pdf

    file creation date fromORKL

  16. Is APT 27 Abusing COVID-19 To Attack People !

    date in the CCS '25 data Yoroi fromCCS '25 data

  17. Analytics

    Malpedia library date Positive Technologies fromORKLCCS '25 data

  18. HELO Winnti_ Attack or Scan

    file creation date fromORKL

  19. HELO Winnti- Attack or Scan-

    date in the title fromORKL

  20. APT41: A Dual Espionage and Cyber Crime Operation

    file creation date FireEye fromORKL

  21. report_APT41

    file creation date fromORKL

  22. TLP-WHITE-CERT-EU-MEMO-190725-1.pdf

    file creation date fromORKL

  23. Into the Fog - The Return of ICEFOG APT

    Malpedia library date fromORKL

  24. Chinese Cyberespionage Originating From Tsinghua University Infrastructure

    date in the CCS '25 data Recorded Future fromORKLCCS '25 data

  25. Burning Umbrella

    date in the CCS '25 data 401TRG fromORKLCCS '25 data

  26. ukatemicrysys_territorialdispute

    Malpedia library date fromORKL

  27. Aurora_Operation_CCleaner_II

    date in the CCS '25 data Intezer fromORKLCCS '25 data

  28. Avast Threat Labs analysis of CCleaner incident

    date in the title fromORKL

  29. Aurora_Operation_CCleaner

    date in the CCS '25 data Cisco fromORKLCCS '25 data

  30. Winnti Evolution - Going Open Source

    date in the CCS '25 data ProtectWise fromORKLCCS '25 data

  31. APT17

    date in the title fromORKL

  32. Operation Cloud Hopper

    file creation date fromORKL

  33. cloud-hopper-report-final-upda_72977

    file creation date fromORKL

  34. Operation Cloud Hopper

    date in the CCS '25 data PWC fromORKLCCS '25 data

  35. ICIT-Brief-China-Espionage-Dynasty

    date in the CCS '25 data Debra Obyrne fromORKLCCS '25 data

  36. Please Read

    date in the CCS '25 data FireEye and Microsoft fromORKLCCS '25 data

  37. security_report_20160613.pdf

    Malpedia library date fromORKL

  38. Newcomers in the Derusbi family

    Malpedia library date fromORKL

  39. Revealing the Attack Operations Targeting Japan

    date in the CCS '25 data JPCERT fromORKLCCS '25 data

  40. VB2015_Catching_the_silent_whisper

    Malpedia library date mpun@fortinet.com, ericleung@fortinet.com, ntan@fortinet.com fromORKL

  41. Uncovering the Seven Pointed Dagger

    Malpedia library date Arbor Networks fromORKLCCS '25 data

  42. The Black Vine Cyberespionage Group

    date in the CCS '25 data Symantec fromORKLCCS '25 data

  43. TT Malware Log

    date in the title fromORKL

  44. APT17_Report.pdf

    Malpedia library date fromORKL

  45. WINNTI Analysis

    Malpedia library date Novetta fromORKL

  46. Global Threat Intel Report

    Malpedia library date Crowdstrike fromORKL

  47. Threat Spotlight: Group 72

    date in the CCS '25 data Cisco fromORKLCCS '25 data

  48. Security vendors take action against Hidden Lynx malware

    date in the title fromORKL

  49. targeted_attacks_against_the_energy_sector

    date in the CCS '25 data Symantec fromORKLCCS '25 data

  50. CrowdCasts Monthly: You Have an Adversary Problem

    Malpedia library date fromORKL

  51. Hidden Lynx – Professional Hackers for Hire

    date in the title fromORKL

  52. Hidden Lynx – Professional Hackers for Hire

    Malpedia library date fromORKL

  53. Hidden Lynx: Professional Hackers For Hire

    Malpedia library date Symantec fromORKL

Newest first. Details opens the report in Explore.