Also known as: Group 72, APT17, Tailgater Team, Dogfish (iDefense), Deputy Dog (iDefense), Winnti Umbrella, Aurora Panda, Deputy Dog, Hidden Lynx, Group 8, "Axiom, SportsFans, Operation Cleaver, Sandworm Team, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations
Axiom – also known as Group 72 or APT17 – is widely regarded as a state‑sponsored Chinese threat actor that has been active since at least 2008. The group’s attacks span a broad range of sectors, including aerospace, defense, manufacturing, media and government organizations, with particular attention to high‑profile Fortune 500 companies and intellectual‑property‑rich firms in the United States, Japan, Taiwan and Korea. Tactics are characterized by an engineering‑heavy methodology: Axiom prepares bespoke payloads, distributes them via watering‑hole sites or spear‑phishing for tailored victims, then leverages public‑facing app exploits (CVE‑2014‑0322, CVE‑2012‑4792, CVE‑2012‑1889 and CVE‑2013‑3893) to gain footholds. Once inside, the group deploys modular malware such as PlugX or Olympic Destroyer, captures credentials through LSASS dumping (T1003.001) and persists via RDP hijacking (T1563.002). The intelligence community links Axiom’s operational footprint with that of Winnti – particularly in the use of dynamic DNS for C&C infrastructure – but analysts note sufficient differences in TTPs to treat them as distinct entities. Recent reports highlight a coordinated effort that uncovered 43,000 installations and highlighted Axiom’s capacity for mass exfiltration via compressed archives (T1560) while maintaining low detection through stealthy credential and data‑obfuscation techniques.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Axiom is a long‑standing Chinese cyber‑espionage group that has targeted high‑value aerospace, defense, manufacturing and media organizations since at least 2008. The group deploys sophisticated watering‑hole, spear‑phishing and web‑based attacks, leveraging custom backdoors such as PlugX and Olympic Destroyer to steal intellectual property from primarily U.S., Japan, Taiwan and Korea entities. Axiom’s operations have infected tens of thousands of systems, indicating deep persistence and a focus on long‑term intelligence gathering.
Goals & Targeting
Axiom seeks to acquire classified and proprietary information from entities holding strategic or industrial advantage. By targeting defense contractors, aerospace manufacturers and media outlets that publish sensitive technical details, the group amplifies China’s geopolitical influence while securing a cache of actionable intelligence. Victims are typically well‑protected, high‑profile organizations within key U.S., Japanese, Taiwanese, Korean and other technologically advanced markets. The group’s long tenure reflects an objective to maintain persistent access across multiple campaigns—“SMN” being one notable operation—to map out corporate structures and extract data over prolonged periods. Axiom’s focus on industrial R&D assets suggests a strategic intent to support nation‑state objectives, encompassing intellectual property theft, geopolitical advantage and potential influence operations. Key characteristics include an emphasis on high‑value targets that possess actionable IP, coupled with a technical proficiency that enables the group to adapt swiftly between C&C paradigms, exploit widely distributed software vulnerabilities and obfuscate activity to avoid early detection.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Axiom’s most prominent campaign, “SMN,” operated from 2008 to 2014 against Fortune 500 firms, journalists, NGOs and defense contractors. Intelligence agencies reported more than 43 000 infected endpoints, with 180 key implants removed during a private‐sector interdiction exercise. The group leveraged watering holes, spear‑phishing, exploit kits targeting CVE‑based vulnerabilities, and custom backdoors to maintain long‑term persistence. Axiom demonstrates an operational tempo that allows rapid lateral movement and data aggregation across multiple organizations before exfiltration. The pattern of activity suggests a deliberate strategy of building knowledge pools around target industries rather than immediate data extraction. Recent disclosures indicate continued use of dynamic DNS, which further complicates C&C takedown efforts.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The core characteristics of Axiom are supported by multiple public intelligence sources, including the APT17 Malpedia profile and Novetta’s executive summary. Information regarding specific tools is inferred from linked ATT&CK TTPs and associated malware families; however, direct evidence linking each tool to observed incidents remains limited in the source material. The oldest confirmed activity dates back to 2008–2014, so recent activity levels are uncertain. Overall confidence for the overarching threat profile is high, while detailed tactical specifics (e.g., exact CVEs exploited in current campaigns) have lower confidence due to dated references.
Ephemeral Hydra
SMN
No observed data linked yet.
30
Techniques
52
Tools
2
Campaigns
25
IOCs
0
Observed Data
10
Tactics