APT18
Also reported as TG-0416, Wekby, Satin Typhoon, Wisp Team, DYNAMITE PANDA and 24 other names. Linked to China by four sources.
Reports per quarter
Techniques seen in the last two years
- T1027 2 reports reports only
- T1036.005 2 reports reports only
- T1059.001 2 reports reports only
- T1082 2 reports in ATT&CK
- T1132.001 2 reports reports only
- T1140 2 reports reports only
- T1204.002 2 reports reports only
- T1547.001 2 reports in ATT&CK
- T1566.001 2 reports reports only
- T1573.001 2 reports reports only
Show all 38 techniques Show fewer
- T1001.003 1 report reports only
- T1012 1 report reports only
- T1027.009 1 report reports only
- T1036.007 1 report reports only
- T1041 1 report reports only
- T1055 1 report reports only
- T1055.012 1 report reports only
- T1057 1 report reports only
- T1071.001 1 report in ATT&CK
- T1083 1 report in ATT&CK
- T1102 1 report reports only
- T1105 1 report in ATT&CK
- T1106 1 report reports only
- T1129 1 report reports only
- T1189 1 report reports only
- T1218 1 report reports only
- T1218.007 1 report reports only
- T1218.014 1 report reports only
- T1497.001 1 report reports only
- T1553.002 1 report reports only
- T1566.002 1 report reports only
- T1574 1 report reports only
- T1574.001 1 report reports only
- T1583.001 1 report reports only
- T1583.003 1 report reports only
- T1587.001 1 report reports only
- T1608.001 1 report reports only
- T1627.001 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2008-3431 KEV
- CVE-2010-1424
- CVE-2010-2152
- CVE-2010-2883 KEV
- CVE-2010-3915
- CVE-2010-3916
- CVE-2011-1331
- CVE-2011-2462 KEV
- CVE-2011-3544 KEV
- CVE-2012-0158 KEV ransomware
- CVE-2012-0507 KEV ransomware
- CVE-2012-5687
Show all 129 CVEs Show fewer
- CVE-2013-0707
- CVE-2013-1331 KEV
- CVE-2013-3644
- CVE-2013-3893 KEV
- CVE-2013-3900 KEV
- CVE-2013-3918 KEV
- CVE-2013-5947
- CVE-2013-5990
- CVE-2014-0810
- CVE-2014-1225
- CVE-2014-2962
- CVE-2014-3393
- CVE-2014-4019
- CVE-2014-4113 KEV
- CVE-2014-4114 KEV
- CVE-2014-7247
- CVE-2014-8361 KEV
- CVE-2014-9583
- CVE-2015-0554
- CVE-2015-1641 KEV
- CVE-2015-1701 KEV ransomware
- CVE-2015-2545 KEV
- CVE-2015-4852 KEV
- CVE-2015-5119 KEV
- CVE-2015-5122 KEV
- CVE-2015-7248
- CVE-2015-7254
- CVE-2016-5195 KEV
- CVE-2016-7836 KEV
- CVE-2017-0176
- CVE-2017-0199 KEV ransomware
- CVE-2017-0213 KEV ransomware
- CVE-2017-0261 KEV
- CVE-2017-1182
- CVE-2017-11882 KEV ransomware
- CVE-2017-15944 KEV
- CVE-2017-6327 KEV
- CVE-2017-7269 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-1207
- CVE-2018-13379 KEV ransomware
- CVE-2018-4939 KEV
- CVE-2018-6789 KEV ransomware
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-0803 KEV ransomware
- CVE-2019-10149 KEV
- CVE-2019-1040
- CVE-2019-11510 KEV ransomware
- CVE-2019-11580 KEV ransomware
- CVE-2019-16098
- CVE-2019-17100
- CVE-2019-18935 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2019-3369
- CVE-2019-3396 KEV ransomware
- CVE-2019-9489
- CVE-2020-0601 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-0986 KEV
- CVE-2020-10189 KEV
- CVE-2020-1350 KEV
- CVE-2020-1380 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-15505 KEV
- CVE-2020-1664
- CVE-2020-2021 KEV ransomware
- CVE-2020-2555 KEV
- CVE-2020-3118 KEV
- CVE-2020-5135 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2020-8193 KEV
- CVE-2020-8195 KEV
- CVE-2020-8196 KEV
- CVE-2020-8468 KEV
- CVE-2020-8515 KEV
- CVE-2021-1675 KEV ransomware
- CVE-2021-22555 KEV
- CVE-2021-22941 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-31195
- CVE-2021-31196 KEV
- CVE-2021-31206
- CVE-2021-31207 KEV ransomware
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-34527 KEV ransomware
- CVE-2021-4034 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-4104
- CVE-2021-44207 KEV
- CVE-2021-44228 KEV ransomware
- CVE-2021-45046 KEV ransomware
- CVE-2021-45105
- CVE-2022-21587 KEV ransomware
- CVE-2022-24682 KEV ransomware
- CVE-2022-24934
- CVE-2022-27924 KEV ransomware
- CVE-2022-27925 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2022-30333 KEV ransomware
- CVE-2022-37042 KEV ransomware
- CVE-2022-41040 KEV ransomware
- CVE-2022-41082 KEV ransomware
- CVE-2022-41328 KEV
- CVE-2022-42475 KEV ransomware
- CVE-2022-47986 KEV ransomware
- CVE-2022-49475
- CVE-2023-34362 KEV ransomware
- CVE-2024-0012 KEV ransomware
- CVE-2024-24919 KEV ransomware
- CVE-2024-4577 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
APT 4, Maverick Panda, Wisp Team
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor APT 4, Maverick Panda, Wisp Team
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Ghost RAT (Malware Family)
-
The original link failed its last check. Original publisher Detailsfor Council on Foreign Relations
Show all 213 reports Show fewer
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Wirtschaftsspionage gegen Volkwagen: VW-Konzern wurde jahrelang ausge…
The title opens archive.today, not the publisher’s page. Archived copy on ORKL Detailsfor Wirtschaftsspionage gegen Volkwagen: VW-Konzern wurde jahrelang ausge…
-
Staying ahead of threat actors in the age of AI _ Microsoft Security Blog
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Staying ahead of threat actors in the age of AI _ Microsoft Security Blog
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Dark Pink APT unleashes malware for deeper and more sinister intrusions in the Asia-Pacific and Europe _ Group-IB Blog
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Demonstrating_Hustle
-
APT Group Wekby Leveraging Adobe Flash Exploit (CVE-2015-5119) _ Volexity Blog
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT Group Wekby Leveraging Adobe Flash Exploit (CVE-2015-5119) _ Volexity Blog
-
MustangPanda%20-%20Enemy%20at%20the%20gate_final.pdf
The original link failed its last check. Original publisher Detailsfor MustangPanda%20-%20Enemy%20at%20the%20gate_final.pdf
-
Advanced Persistent Threats (APTs)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threats (APTs)
-
yir-cyber-threats-annex-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-annex-download.pdf
-
Advanced Persistent Threats (APTs)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threats (APTs)
-
Mustang Panda PlugX - 45.251.240.55 Pivot
The original link failed its last check. Original publisher Detailsfor Mustang Panda PlugX - 45.251.240.55 Pivot
-
Higaisa or Winnti? APT41 backdoors, old and new
The original link failed its last check. Original publisher Detailsfor Higaisa or Winnti? APT41 backdoors, old and new
-
Is APT 27 Abusing COVID-19 To Attack People !
The original link failed its last check. Detailsfor Is APT 27 Abusing COVID-19 To Attack People !
-
Reviving MuddyC3 Used by MuddyWater (IRAN) APT
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Reviving MuddyC3 Used by MuddyWater (IRAN) APT
-
The original link failed its last check. Original publisher Detailsfor Analytics
-
BLOG SERIES_Huge Fan of Your Work
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor BLOG SERIES_Huge Fan of Your Work
-
APT41: A Dual Espionage and Cyber Crime Operation
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor APT41: A Dual Espionage and Cyber Crime Operation
-
The original link failed its last check. Original publisher Detailsfor Analytics
-
Operation-Taskmasters-2019-eng
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation-Taskmasters-2019-eng
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor report_APT41
-
Into the Fog - The Return of ICEFOG APT
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Into the Fog - The Return of ICEFOG APT
-
Advanced Persistent Threat Groups
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threat Groups
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT18
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A Tale of Two Targets
-
threatconnect-discovers-chinese-apt-activity-in-europe
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor threatconnect-discovers-chinese-apt-activity-in-europe
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor New Wekby Attacks Use DNS Requests As Command and Control Mechanism - Palo Alto Networks BlogPalo Alto Networks Blog
-
The original link failed its last check. Original publisher Detailsfor security_report_20160613.pdf
-
CVE-2015-2545: overview of current threats - Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor CVE-2015-2545: overview of current threats - Securelist
-
CVE-2015-2545: overview of current threats
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor CVE-2015-2545: overview of current threats
-
CVE-2015-2545- overview of current threats
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor CVE-2015-2545- overview of current threats
-
New Wekby Attacks Use DNS Requests As Command and Control Mechanism
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New Wekby Attacks Use DNS Requests As Command and Control Mechanism
-
New Wekby Attacks Use DNS Requests As Command and Control Mechanism
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor New Wekby Attacks Use DNS Requests As Command and Control Mechanism
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor New Poison Ivy RAT Variant Targets Hong Kong Pro-Democracy Activists - Palo Alto Networks BlogPalo Alto Networks Blog
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ghosts in the Endpoint
-
The original link failed its last check. Original publisher Detailsfor rpt-mtrends-2016.pdf
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor HTExploitTelemetry
-
Uncovering the Seven Pointed Dagger
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Uncovering the Seven Pointed Dagger
-
Afghan Government Compromise_ Browser Beware _ Volexity Blog
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Afghan Government Compromise_ Browser Beware _ Volexity Blog
-
The original link failed its last check. Original publisher Detailsfor rpt-m-trends-2015.pdf
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Who is Samurai Panda
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Who is Anchor Panda
-
BKDR_RARSTONE: New RAT to Watch Out For - TrendLabs Security Intelligence Blog
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor BKDR_RARSTONE: New RAT to Watch Out For - TrendLabs Security Intelligence Blog
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Mandiant_APT1_Report
-
HOW CHINA WILL USE CYBER WARFARE TO LEAPFROG IN MILITARY COMPETITIVENESS
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor HOW CHINA WILL USE CYBER WARFARE TO LEAPFROG IN MILITARY COMPETITIVENESS
Newest first. Details opens the report in Explore.