Also known as: PLA Unit 78020, OVERRIDE PANDA, Camerashy, BRONZE GENEVA, G0019, Naikon, BRONZE STERLING, G0013, Lotus Panda, APT30, Thrip, Spring Dragon, ST Group, DRAGONFISH, BRONZE ELGIN, ATK1, G0030, Red Salamander, Lotus BLossom, Billbug, Lotus Blossom, sile, tracked as, GreenSky27, APT31, Violet Typhoon, the Wuhan Xiaoruizhi Science, Hellsing, TA558, NAIKON CASTLE, Technology Company
Naikon’s operations are designed to gather strategic intelligence rather than deliver financial damage. The group uses a sophisticated blend of social engineering and technical exploits: initial access is typically achieved through spear‑phishing emails containing malicious Microsoft Office documents that exploit CVE‑2012‑0158 or employ double‑extension tricks (.doc.exe). Once inside, the actor deploys dropper or loader components such as Aria‑body, RainyDay, PlugX and RARSTONE to establish a backdoor for command‑and‑control. Persistence is achieved through multiple Windows persistence mechanisms – Windows Run registry entries, scheduled tasks (T1053/T1047), hijacked DLLs, and masqueraded services that mimic legitimate processes such as taskmgr. For lateral movement, Naikon leverages stolen Domain Administrator accounts and tools like PowerShell‑based WmiExec or remote service utilities (PsExec, NTLM). Discovery is thorough: netbios scans via nbtscan/T1018 expose network shares, netsh output exposes firewall/router settings, and DLL side‑loading into legitimate applications provides stealth. Defense evasion includes modifying registry keys, disabling security tools (T1518), and using legitimate software images to hide malicious code. Throughout its long‑term activity, Naikon has demonstrated a clear preference for targeting state bodies, think‑tanks, NGOs, and international organizations such as the UNDP and ASEAN, focusing on Southeast Asian governments. Despite operating across multiple regions, the group’s approach remains remarkably consistent: use of spear‑phishing with decoy documents, exploitation of Office CVEs, persistent backdoors, and stealthy lateral movement using administrative credentials.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Naikon, a state-sponsored espionage actor attributed to the Chinese PLA’s Chengdu Military Region Second Technical Reconnaissance Bureau (Unit 78020), has been active since at least 2010 and focuses on government, military, telecom, energy, and critical‑infrastructure targets in Southeast Asia, India, Singapore, Vietnam and China. The group relies heavily on spear‑phishing attachments, legitimate program masquerading, DLL side‑loading, and living‑off‑the‑land utilities to establish persistence, move laterally with stolen credentials, and exfiltrate data for intelligence purposes.
Goals & Targeting
Strategically, Naikon seeks to harvest politically sensitive or economically valuable data from governmental, defence and critical‑infrastructure entities across Southeast Asia and parts of South and East Asia for use by the Chinese state. By focusing on high‑value civil and military targets that are often less hardened against social engineering, the actor gains strategic advantage in shaping geopolitical narratives and strengthening China’s regional influence.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Naikon’s campaign pattern exhibits a deliberate, long‑lasting presence (since 2010), with repeated use of the same spear‑phishing vectors and persistence mechanisms across multiple victim countries. The actor primarily targets governmental, defence, telecom, financial‑services, energy sectors, often focusing on organisations linked to policy research or international bodies such as UNDP and ASEAN. Operations are carried out via a mix of custom backdoors (Aria-body/RainyDay) and off‑the‑shelf RATs (PlugX, RARSTONE), with a consistent use of DLL side‑loading and legitimate Windows utilities for stealth. While the group’s activity is intermittent at times, it maintains an operational tempo sufficient to sustain long‑term intelligence gathering without compromising detection by typical security controls.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in Naikon’s attribution to the Chinese PLA Unit 78020 is high, supported by multiple security vendors, academic research, and MITRE ATT&CK entries. The consensus on its core TTPs—including spear‑phishing with Office exploits, persistence via Run registry and scheduled tasks, DLL side‑loading, and administrative credential usage—is firm. However, gaps remain regarding the exact start date of activity, full scope of victim list beyond public incidents, long‐term operational tempo, and definitive linkages between all alias names (e.g., APT30 vs. Naikon). Continued monitoring and intelligence gathering are required to refine those aspects.
No observed data linked yet.
31
Techniques
57
Tools
4
Campaigns
162
IOCs
0
Observed Data
8
Tactics