All actors

APT19

Also reported as Codoso, Sunshop Group, JerseyMikes, Taffeta Typhoon, Checkered Typhoon and 37 other names. Linked to China by four sources.

Reports
821
Last reported
Known CVEs
267
Techniques in ATT&CK
21
Origin
China
ID
G0073
Merge evidence
50 alias matches

Reports per quarter

  1. 2011 Q4: 1 report
  2. 2012 Q1: no reports
  3. 2012 Q2: no reports
  4. 2012 Q3: 1 report
  5. 2012 Q4: no reports
  6. 2013 Q1: 1 report
  7. 2013 Q2: no reports
  8. 2013 Q3: no reports
  9. 2013 Q4: 3 reports
  10. 2014 Q1: 1 report
  11. 2014 Q2: no reports
  12. 2014 Q3: 3 reports
  13. 2014 Q4: no reports
  14. 2015 Q1: 1 report
  15. 2015 Q2: no reports
  16. 2015 Q3: 6 reports
  17. 2015 Q4: 2 reports
  18. 2016 Q1: 7 reports
  19. 2016 Q2: 5 reports
  20. 2016 Q3: 3 reports
  21. 2016 Q4: 1 report
  22. 2017 Q1: 1 report
  23. 2017 Q2: 9 reports
  24. 2017 Q3: 5 reports
  25. 2017 Q4: 2 reports
  26. 2018 Q1: 3 reports
  27. 2018 Q2: 4 reports
  28. 2018 Q3: 4 reports
  29. 2018 Q4: 4 reports
  30. 2019 Q1: 4 reports
  31. 2019 Q2: 11 reports
  32. 2019 Q3: 5 reports
  33. 2019 Q4: 15 reports
  34. 2020 Q1: 20 reports
  35. 2020 Q2: 13 reports
  36. 2020 Q3: 21 reports
  37. 2020 Q4: 42 reports
  38. 2021 Q1: 49 reports
  39. 2021 Q2: 60 reports
  40. 2021 Q3: 70 reports
  41. 2021 Q4: 50 reports
  42. 2022 Q1: 62 reports
  43. 2022 Q2: 73 reports
  44. 2022 Q3: 50 reports
  45. 2022 Q4: 20 reports
  46. 2023 Q1: 22 reports
  47. 2023 Q2: 11 reports
  48. 2023 Q3: 18 reports
  49. 2023 Q4: 16 reports
  50. 2024 Q1: 11 reports
  51. 2024 Q2: 13 reports
  52. 2024 Q3: 21 reports
  53. 2024 Q4: 11 reports
  54. 2025 Q1: 12 reports
  55. 2025 Q2: 7 reports
  56. 2025 Q3: 8 reports
  57. 2025 Q4: 6 reports
  58. 2026 Q1: 6 reports
  59. 2026 Q2: 27 reports
Dated reports, 2011 Q4 to 2026 Q2.

Techniques seen in the last two years

Show all 276 techniques Show fewer

Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.

Also listed by ATT&CK

CVEs named in reports

Show all 267 CVEs Show fewer

KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.

Reports

  1. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

  2. CrowdCasts Monthly: You Have an Adversary Problem

    date ORKL added it fromORKL

  3. Emissary Panda, APT 27, LuckyMouse, Bronze Union

    date ORKL added it fromORKL

Show all 821 reports Show fewer
  1. Poison Ivy (Malware Family)

    date ORKL added it fromORKL

  2. Nightshade Panda, APT 9, Group 27

    date ORKL added it fromORKL

  3. APT 19, Deep Panda, C0d0so0

    date ORKL added it fromORKL

  4. Cobalt Strike (Malware Family)

    date ORKL added it fromORKL

  5. Ready for Summer: The Sunshop Campaign

    date ORKL added it fromORKL

  6. Emissary Panda, APT 27, LuckyMouse, Bronze Union

    date ORKL added it fromORKL

  7. BlackSuit Ransomware

    publisher's date The DFIR Report fromORKLDFIR Report

  8. Modern Asia APT groups TTPs

    file creation date Kaspersky fromORKL

  9. BumbleBee: Round Two

    publisher's date The DFIR Report fromORKLDFIR Report

  10. RedSense

    Malpedia library date fromORKL

  11. Advanced Persistent Threats (APTs)

    date in the title fromORKL

  12. RedSense

    Malpedia library date fromORKL

  13. Continued cyber activity in Eastern Europe observed by TAG

    date in the title fromORKL

  14. CERT-UA

    Malpedia library date fromORKL

  15. CERT-UA

    Malpedia library date fromORKL

  16. RedSense

    Malpedia library date fromORKL

  17. yir-cyber-threats-annex-download.pdf

    Malpedia library date fromORKL

  18. Quantum Ransomware

    publisher's date The DFIR Report fromORKLDFIR Report

  19. RedSense

    Malpedia library date fromORKL

  20. CERT-UA

    Malpedia library date fromORKL

  21. 2021 Year In Review

    publisher's date The DFIR Report fromORKLDFIR Report

  22. 2021trends.pdf

    Malpedia library date fromORKL

  23. RedSense

    Malpedia library date fromORKL

  24. Patchwork_Patchwork-APT-caught-in-its-own-web_MalwarebytesLabs

    date in the CCS '25 data Malwarebytes fromORKLCCS '25 data

  25. From Zero to Domain Admin

    publisher's date The DFIR Report fromORKLDFIR Report

  26. RedSense

    Malpedia library date fromORKL

  27. Advanced Persistent Threats (APTs)

    date in the title fromORKL

  28. IISerpent- Malware‑driven SEO fraud as a service

    date in the title fromORKL

  29. report-old-dogs-new-tricks.pdf

    Malpedia library date fromORKL

  30. Ryuk Ransomware Now Targeting Webservers

    Malpedia library date fromORKL

  31. Mustang Panda PlugX - 45.251.240.55 Pivot

    Malpedia library date fromORKL

  32. Conti Ransomware

    publisher's date The DFIR Report fromORKLDFIR Report

  33. CTIR_casestudy_2.pdf

    file creation date fromORKL

  34. CTIR_casestudy_1.pdf

    file creation date fromORKL

  35. the-operations-of-winnti-group.pdf

    Malpedia library date fromORKL

  36. mtrends-2021

    file creation date fromORKL

  37. report-bb-2021-threat-report.pdf

    Malpedia library date fromORKL

  38. Technical Analysis of Operation Diànxùn

    Malpedia library date fromORKL

  39. Bazar Drops the Anchor

    publisher's date The DFIR Report fromORKLDFIR Report

  40. Bazar, No Ryuk?

    publisher's date The DFIR Report fromORKLDFIR Report

  41. Analyzing APT19 malware using a step-by-step method

    date in the title fromORKL

  42. PowerPoint Presentation

    file creation date Ganesan, Brittany (OS/ASA) (CTR) fromORKL

  43. Ryuk in 5 Hours

    publisher's date The DFIR Report fromORKLDFIR Report

  44. Chimera, APT19 under the radar -

    date in the title fromORKL

  45. Ryuk's Return

    publisher's date The DFIR Report fromORKLDFIR Report

  46. SCYTHE Library: #ThreatThursday - Buhtrap

    Malpedia library date fromORKL

  47. Ursnif via LOLbins

    publisher's date The DFIR Report fromORKLDFIR Report

  48. Catching APT41 exploiting a zero-day vulnerability

    date in the CCS '25 data Darktrace fromCCS '25 data

  49. Is APT 27 Abusing COVID-19 To Attack People !

    date in the CCS '25 data Yoroi fromCCS '25 data

  50. mtrends-2020

    file creation date fromORKL

  51. Reviving MuddyC3 Used by MuddyWater (IRAN) APT

    date in the CCS '25 data Shells.Systems fromORKLCCS '25 data

  52. Aarhus_miniseminar_291118.pdf

    Malpedia library date fromORKL

  53. Analytics

    Malpedia library date Positive Technologies fromORKLCCS '25 data

  54. BLOG SERIES_Huge Fan of Your Work

    date in the CCS '25 data Crowdstrike fromORKLCCS '25 data

  55. APT41: A Dual Espionage and Cyber Crime Operation

    file creation date FireEye fromORKL

  56. report_APT41

    file creation date fromORKL

  57. Hunting and detecting Cobalt Strike

    date in the title fromORKL

  58. Into the Fog - The Return of ICEFOG APT

    date in the title fromORKL

  59. Into the Fog - The Return of ICEFOG APT

    Malpedia library date fromORKL

  60. mpressioncss_ta_report_2019.pdf

    Malpedia library date fromORKL

  61. BSides IR in Heterogeneous Environment

    Malpedia library date fromORKL

  62. Advanced Persistent Threat Groups

    date in the title fromORKL

  63. Privileges and Credentials: Phished at the Request of Counsel

    date in the CCS '25 data FireEye fromORKLCCS '25 data

  64. KingSlayer A Supply chain attack

    date in the CCS '25 data RSA fromORKLCCS '25 data

  65. ICIT-Brief-China-Espionage-Dynasty

    date in the CCS '25 data Debra Obyrne fromORKLCCS '25 data

  66. security_report_20160613.pdf

    Malpedia library date fromORKL

  67. Turbo Twist: Two 64-bit Derusbi Strains Converge

    date in the CCS '25 data Fidelis fromORKLCCS '25 data

  68. rpt-mtrends-2016.pdf

    file creation date fromORKL

  69. New Attacks Linked to C0d0so0 Group

    date in the title fromORKL

  70. Без названия

    file creation date fromORKL

  71. Uncovering the Seven Pointed Dagger

    Malpedia library date Arbor Networks fromORKLCCS '25 data

  72. Hammertoss: Stealthy Tactics Define A Russian Cyber Threat Group

    date in the CCS '25 data FireEye fromORKLCCS '25 data

  73. rpt-apt29-hammertoss.pdf

    Malpedia library date fromORKL

  74. Microsoft Word - 2015-02-XX -Scanbox II - TLPWHITE.docx

    date in the CCS '25 data PWC fromORKLCCS '25 data

  75. Aided Frame, Aided Direction (Because it’s a redirect) | FireEye Blog

    date in the CCS '25 data FireEye fromORKLCCS '25 data

  76. Supply Chain Analysis: From Quartermaster To Sunshopfireeye

    file creation date FireEye fromORKL

  77. The Chinese Malware Complexes: The Maudi Surveillance Operation

    Malpedia library date Norman fromORKL

  78. CrowdCasts Monthly- You Have an Adversary Problem

    date in the title fromORKL

  79. CrowdCasts Monthly: You Have an Adversary Problem

    Malpedia library date fromORKL

  80. Iexpl0Re Rat

    file creation date Citizen Lab fromORKL

  81. Alleged Apt Intrusion Set: 1.Php Group

    file creation date Zscaler, ThreatLabz fromORKL

Newest first. Details opens the report in Explore.