Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: Group 72, APT17, Tailgater Team, Dogfish (iDefense), Deputy Dog (iDefense), Winnti Umbrella, Aurora Panda, Deputy Dog, Hidden Lynx, Group 8, "Axiom, SportsFans, Operation Cleaver, Sandworm Team, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations

Description

Axiom – also known as Group 72 or APT17 – is widely regarded as a state‑sponsored Chinese threat actor that has been active since at least 2008. The group’s attacks span a broad range of sectors, including aerospace, defense, manufacturing, media and government organizations, with particular attention to high‑profile Fortune 500 companies and intellectual‑property‑rich firms in the United States, Japan, Taiwan and Korea. Tactics are characterized by an engineering‑heavy methodology: Axiom prepares bespoke payloads, distributes them via watering‑hole sites or spear‑phishing for tailored victims, then leverages public‑facing app exploits (CVE‑2014‑0322, CVE‑2012‑4792, CVE‑2012‑1889 and CVE‑2013‑3893) to gain footholds. Once inside, the group deploys modular malware such as PlugX or Olympic Destroyer, captures credentials through LSASS dumping (T1003.001) and persists via RDP hijacking (T1563.002). The intelligence community links Axiom’s operational footprint with that of Winnti – particularly in the use of dynamic DNS for C&C infrastructure – but analysts note sufficient differences in TTPs to treat them as distinct entities. Recent reports highlight a coordinated effort that uncovered 43,000 installations and highlighted Axiom’s capacity for mass exfiltration via compressed archives (T1560) while maintaining low detection through stealthy credential and data‑obfuscation techniques.

Goals & Targeting

Targeted Sectors

Government
Defense
Aerospace & defense
Ngo
Financial services
Telecommunications
Manufacturing
Healthcare
Education
Media
Energy
Aerospace
Critical infrastructure
Non profit
Pharmaceutical
Aviation
Information technology
Transportation
Retail
Chemical
Think tank
Maritime
Mining
Utilities
Oil gas
Legal services
Nuclear
Entertainment
Construction
Hospitality
Gaming

Targeted Countries / Regions

US
CN
RU
JP
TW
IR
PK
VN
IL
GB
AU
SA
AE
UA
PL
SG
KR
IN
DE
MX
BY
TR
ES
KP
CA
RO
FR
NG
IT
LB
AZ
KZ

AI Analysis

Grounded in web research
· 15 hours ago

Executive Summary

Axiom is a long‑standing Chinese cyber‑espionage group that has targeted high‑value aerospace, defense, manufacturing and media organizations since at least 2008. The group deploys sophisticated watering‑hole, spear‑phishing and web‑based attacks, leveraging custom backdoors such as PlugX and Olympic Destroyer to steal intellectual property from primarily U.S., Japan, Taiwan and Korea entities. Axiom’s operations have infected tens of thousands of systems, indicating deep persistence and a focus on long‑term intelligence gathering.

Goals & Targeting

Axiom seeks to acquire classified and proprietary information from entities holding strategic or industrial advantage. By targeting defense contractors, aerospace manufacturers and media outlets that publish sensitive technical details, the group amplifies China’s geopolitical influence while securing a cache of actionable intelligence. Victims are typically well‑protected, high‑profile organizations within key U.S., Japanese, Taiwanese, Korean and other technologically advanced markets. The group’s long tenure reflects an objective to maintain persistent access across multiple campaigns—“SMN” being one notable operation—to map out corporate structures and extract data over prolonged periods. Axiom’s focus on industrial R&D assets suggests a strategic intent to support nation‑state objectives, encompassing intellectual property theft, geopolitical advantage and potential influence operations. Key characteristics include an emphasis on high‑value targets that possess actionable IP, coupled with a technical proficiency that enables the group to adapt swiftly between C&C paradigms, exploit widely distributed software vulnerabilities and obfuscate activity to avoid early detection.

Enhanced Description

Key Capabilities

  • Advanced watering‑hole deployment using compromised vendor sites
  • Sophisticated spear‑phishing campaigns with custom payloads
  • Public‑facing application exploitation (multiple CVEs)
  • Dynamic DNS and virtual private server infrastructure for C&C
  • Credential dumping from LSASS memory and RDP hijacking
  • Use of modular backdoors such as PlugX, Olympic Destroyer, Machete
  • Data exfiltration via compressed archives and encrypted channels
  • Stealthy persistence and defense evasion techniques

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Collection
Exfiltration
Command and Control

ATT&CK Techniques

T1059.003
T1003
T1003.001
T1566
T1189
T1190
T1078
T1021
T1021.001
T1583
T1583.002
T1583.003
T1587.004
T1560
T1203
T1546.008
T1553
T1546

Software / Tooling

PlugX
Olympic Destroyer
Machete
Akira
GHC0ST RAT

Campaigns & Victims

Axiom’s most prominent campaign, “SMN,” operated from 2008 to 2014 against Fortune 500 firms, journalists, NGOs and defense contractors. Intelligence agencies reported more than 43 000 infected endpoints, with 180 key implants removed during a private‐sector interdiction exercise. The group leveraged watering holes, spear‑phishing, exploit kits targeting CVE‑based vulnerabilities, and custom backdoors to maintain long‑term persistence. Axiom demonstrates an operational tempo that allows rapid lateral movement and data aggregation across multiple organizations before exfiltration. The pattern of activity suggests a deliberate strategy of building knowledge pools around target industries rather than immediate data extraction. Recent disclosures indicate continued use of dynamic DNS, which further complicates C&C takedown efforts.

IOC Patterns

  • Watering‑hole compromise via vendor or third‑party websites
  • Dynamic DNS hosting for command and control servers
  • Exploit‑based initial access using publicly disclosed CVEs
  • Spear‑phishing with malicious attachments or links
  • Custom backdoor implants such as PlugX or Olympic Destroyer
  • Data exfiltration via compressed archives over HTTPS or FTP

Recommended Actions

  • Deploy EDR solutions capable of detecting LSASS memory dumps and credential dumping activity
  • Patch all software to remediate CVE‑2014‑0322, CVE‑2012‑4792, CVE‑2012‑1889, CVE‑2013‑3893 promptly
  • Implement DNS filtering or blocklists for known dynamic DNS domains tied to Axiom activities
  • Use web filtering and sandboxing to detect watering‑hole attacks Maintain robust email security controls (MFA, anti‑phishing campaigns) to mitigate spear‑phishing vectors
  • Adopt network segmentation and least‑privilege principles to limit lateral movement after compromise
  • Integrate threat intel feeds that provide real‑time indicator updates for known Axiom infrastructure

Suggested Tags

APT
Espionage
Chinese state-sponsored
Aerospace
Defense
Manufacturing
Media
Intellectual Property Theft
Watering Hole
Spear-Phishing
Dynamic DNS

Confidence Assessment

The core characteristics of Axiom are supported by multiple public intelligence sources, including the APT17 Malpedia profile and Novetta’s executive summary. Information regarding specific tools is inferred from linked ATT&CK TTPs and associated malware families; however, direct evidence linking each tool to observed incidents remains limited in the source material. The oldest confirmed activity dates back to 2008–2014, so recent activity levels are uncertain. Overall confidence for the overarching threat profile is high, while detailed tactical specifics (e.g., exact CVEs exploited in current campaigns) have lower confidence due to dated references.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

Observed Data

No observed data linked yet.

References

  1. Cisco Group 72 — Esler, J., Lee, M., and Williams, C. (2014, October 14). Threat Spotlight: Group 72. Retrieved January 14, 2016.
  2. Kaspersky Winnti April 2013 — Kaspersky Lab's Global Research and Analysis Team. (2013, April 11). Winnti. More than just a game. Retrieved February 8, 2017.
  3. Novetta Winnti April 2015 — Novetta Threat Research Group. (2015, April 7). Winnti Analysis. Retrieved February 8, 2017.
  4. Novetta-Axiom — Novetta. (n.d.). Operation SMN: Axiom Threat Actor Group Report. Retrieved November 12, 2014.
  5. Kaspersky Winnti June 2015 — Tarakanov, D. (2015, June 22). Games are over: Winnti is now targeting pharmaceutical companies. Retrieved January 14, 2016.
  6. attack.mitre.org — Cited by web research for: OilRig
  7. attack.mitre.org — Cited by web research for: MailFetch.py
  8. https://apt.etda.or.th/cgi-bin/showcard.cgi?g=Axiom%2C+Group+72 — Cited by AI analysis.
  9. https://malpedia.caad.fkie.fraunhofer.de/actor/apt17 — Cited by AI analysis.
  10. http://www.novetta.com/wp-content/uploads/2014/11/Executive_Summary-Final_1.pdf — Cited by AI analysis.

Intel Summary

30

Techniques

52

Tools

2

Campaigns

25

IOCs

0

Observed Data

10

Tactics

Tags

APT
Government Targeting
espionage
government
defense
aerospace
NGO
Espionage
Chinese state-sponsored
Aerospace
Defense
Manufacturing
Media
Intellectual Property Theft
Watering Hole
Spear-Phishing
Dynamic DNS

Details

MITRE ID
G0001
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
90%
Added
May 26, 2026
STIX ID
intrusion-set--a0cb9370-e39b-44d5-9f50-ef78e412b973
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.