Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Naikon

Also known as: PLA Unit 78020, OVERRIDE PANDA, Camerashy, BRONZE GENEVA, G0019, Naikon, BRONZE STERLING, G0013, Lotus Panda, APT30, Thrip, Spring Dragon, ST Group, DRAGONFISH, BRONZE ELGIN, ATK1, G0030, Red Salamander, Lotus BLossom, Billbug, Lotus Blossom, sile, tracked as, GreenSky27, APT31, Violet Typhoon, the Wuhan Xiaoruizhi Science, Hellsing, TA558, NAIKON CASTLE, Technology Company

Description

Naikon’s operations are designed to gather strategic intelligence rather than deliver financial damage. The group uses a sophisticated blend of social engineering and technical exploits: initial access is typically achieved through spear‑phishing emails containing malicious Microsoft Office documents that exploit CVE‑2012‑0158 or employ double‑extension tricks (.doc.exe). Once inside, the actor deploys dropper or loader components such as Aria‑body, RainyDay, PlugX and RARSTONE to establish a backdoor for command‑and‑control. Persistence is achieved through multiple Windows persistence mechanisms – Windows Run registry entries, scheduled tasks (T1053/T1047), hijacked DLLs, and masqueraded services that mimic legitimate processes such as taskmgr. For lateral movement, Naikon leverages stolen Domain Administrator accounts and tools like PowerShell‑based WmiExec or remote service utilities (PsExec, NTLM). Discovery is thorough: netbios scans via nbtscan/T1018 expose network shares, netsh output exposes firewall/router settings, and DLL side‑loading into legitimate applications provides stealth. Defense evasion includes modifying registry keys, disabling security tools (T1518), and using legitimate software images to hide malicious code. Throughout its long‑term activity, Naikon has demonstrated a clear preference for targeting state bodies, think‑tanks, NGOs, and international organizations such as the UNDP and ASEAN, focusing on Southeast Asian governments. Despite operating across multiple regions, the group’s approach remains remarkably consistent: use of spear‑phishing with decoy documents, exploitation of Office CVEs, persistent backdoors, and stealthy lateral movement using administrative credentials.

Goals & Targeting

Targeted Sectors

Government
Defense
Telecommunications
Manufacturing
Financial services
Media
Hospitality
Healthcare
Non profit
Energy
Critical infrastructure
Retail

Targeted Countries / Regions

CN
VN
IN
SG

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 2 days ago

Executive Summary

Naikon, a state-sponsored espionage actor attributed to the Chinese PLA’s Chengdu Military Region Second Technical Reconnaissance Bureau (Unit 78020), has been active since at least 2010 and focuses on government, military, telecom, energy, and critical‑infrastructure targets in Southeast Asia, India, Singapore, Vietnam and China. The group relies heavily on spear‑phishing attachments, legitimate program masquerading, DLL side‑loading, and living‑off‑the‑land utilities to establish persistence, move laterally with stolen credentials, and exfiltrate data for intelligence purposes.

Goals & Targeting

Strategically, Naikon seeks to harvest politically sensitive or economically valuable data from governmental, defence and critical‑infrastructure entities across Southeast Asia and parts of South and East Asia for use by the Chinese state. By focusing on high‑value civil and military targets that are often less hardened against social engineering, the actor gains strategic advantage in shaping geopolitical narratives and strengthening China’s regional influence.

Enhanced Description

Key Capabilities

  • Remote system discovery using NetBIOS scanner
  • Spearphishing via attachments with targeted decoy documents
  • Persistence via Windows Run registry entry
  • DLL side‑loading into legitimate executables
  • Masquerading services as legitimate (e.g., taskmgr)
  • Disguising malware as legitimate applications (Chrome, Adobe, VMware)
  • Use of netsh commands to discover firewall and network settings
  • Leveraging administrator credentials for lateral movement
  • Exploitation of Microsoft Word CVE-2012-0158 for initial access and privilege escalation
  • Credential dumping via dedicated tools

MITRE ATT&CK Tactics

Discovery
Initial Access
Execution
Persistence
Defense Evasion
Credential Access
Lateral Movement
Privilege Escalation

ATT&CK Techniques

T1018
T1566.001
T1204
T1547
T1574
T1053
T1036
T1046
T1137
T1518
T1078
T1003
T1105
T1083

Software / Tooling

Aria-body
RainyDay
PlugX
RARSTONE
HDoor
Backspace
Creamsicle
Flashflood
FoundCore
Gemcutter
Nebulae
NetEagle
NewCore RAT
Orangeade
Quarks PwDump
Sloan??
Sandboxie
Spaceship
SslMM
Sys10
TeamViewer?
nbtscan

Campaigns & Victims

Naikon’s campaign pattern exhibits a deliberate, long‑lasting presence (since 2010), with repeated use of the same spear‑phishing vectors and persistence mechanisms across multiple victim countries. The actor primarily targets governmental, defence, telecom, financial‑services, energy sectors, often focusing on organisations linked to policy research or international bodies such as UNDP and ASEAN. Operations are carried out via a mix of custom backdoors (Aria-body/RainyDay) and off‑the‑shelf RATs (PlugX, RARSTONE), with a consistent use of DLL side‑loading and legitimate Windows utilities for stealth. While the group’s activity is intermittent at times, it maintains an operational tempo sufficient to sustain long‑term intelligence gathering without compromising detection by typical security controls.

IOC Patterns

  • NetBIOS scan activity
  • Suspicious DNS queries
  • Spearphishing attachment delivery
  • Registry Run key modification persistence
  • DLL side-loading into legitimate processes
  • Masqueraded service names
  • Disguised malware as legitimate executables
  • netsh command usage for firewall discovery
  • Double‑extension executable attachments
  • Exploitation of MS Word CVE-2012-0158
  • Presence of Aria-body and RainyDay backdoors

Recommended Actions

  • Implement robust spear‑phishing detection and email filtering that blocks malicious attachments and double‑extension files
  • Monitor outbound network traffic for NetBIOS/LAN discovery patterns (e.g., nbtscan) and suspicious DNS queries
  • Deploy threat intelligence feeds to detect known domain or IP indicators used by Aria-body and RainyDay backdoors
  • Enforce strict monitoring of the registry Run key and scheduled task creation, with alerts for alterations tied to persistence
  • Apply application whitelisting or DLL integrity checks to detect side‑loading into legitimate processes
  • Detect and block disguised system services that mimic native Windows services (e.g., taskmgr)
  • Audit privileged account usage and disable unused administrator credentials
  • Patching Microsoft Office suite promptly to mitigate CVE‑2012‑0158 and similar vulnerabilities
  • Provide targeted user training on recognising spear‑phishing attachments with decoy content
  • Use endpoint detection and response solutions capable of detecting PlugX, RARSTONE, Aria-body, RainyDay and other RATs

Suggested Tags

Naikon
APT30
Override Panda
China State Sponsored
PLA Unit 78020
SpearPhishingAttachment
DataTheft
TargetedAttacks
GovernmentMilitaryTargets
CivilianOrganizations
SoutheastAsia
UNDP
ASEAN
Backdoor
Aria-body
RainyDay
DLLSideLoading
Persistence
CredentialDumping
LateralMovement

Confidence Assessment

Confidence in Naikon’s attribution to the Chinese PLA Unit 78020 is high, supported by multiple security vendors, academic research, and MITRE ATT&CK entries. The consensus on its core TTPs—including spear‑phishing with Office exploits, persistence via Run registry and scheduled tasks, DLL side‑loading, and administrative credential usage—is firm. However, gaps remain regarding the exact start date of activity, full scope of victim list beyond public incidents, long‐term operational tempo, and definitive linkages between all alias names (e.g., APT30 vs. Naikon). Continued monitoring and intelligence gathering are required to refine those aspects.

ATT&CK Techniques

Defense impairment
1 technique
Stealth
9 techniques

Software / Tooling

Observed Data

No observed data linked yet.

Indicators of Compromise

IPv4 Address 1 Domain 14 Filename 2 URL 3

References

  1. CameraShy — ThreatConnect Inc. and Defense Group Inc. (DGI). (2015, September 23). Project CameraShy: Closing the Aperture on China's Unit 78020. Retrieved December 17, 2015.
  2. Baumgartner Naikon 2015 — Baumgartner, K., Golovkin, M.. (2015, May). The MsnMM Campaigns: The Earliest Naikon APT Campaigns. Retrieved April 10, 2019.
  3. Baumgartner Golovkin Naikon 2015 — Baumgartner, K., Golovkin, M.. (2015, May 14). The Naikon APT. Retrieved January 14, 2015.
  4. www.kaspersky.com — Cited by web research for: TA558
  5. attack.mitre.org — Cited by web research for: T1566
  6. attack.mitre.org — Cited by web research for: T1547
  7. apt.etda.or.th — Cited by web research for: FLASHFLOOD
  8. apt.etda.or.th — Cited by web research for: Energy
  9. businessinsights.bitdefender.com — Cited by web research for: 8.0.12.0
  10. https://attack.mitre.org/techniques/T1018/ — Cited by AI analysis.
  11. https://malpedia.caad.fkie.fraunhofer.de/actor/naikon — Cited by AI analysis.
  12. https://securelist.com/the-chronicles-of-the-hellsing-apt-the-empire-strikes-back/69567/ — Cited by AI analysis.
  13. https://research.checkpoint.com/2020/naikon-apt-cyber-espionage-reloaded/ — Cited by AI analysis.
  14. https://cluster25.io/2022/04/29/lotus-panda-awake-last-strike/ — Cited by AI analysis.
  15. https://exchange.xforce.ibmcloud.com/threat-group/guid:2f1962c4d7c0c994981c5bc363823c44 — Cited by AI analysis.

Intel Summary

31

Techniques

57

Tools

4

Campaigns

162

IOCs

0

Observed Data

8

Tactics

Tags

APT
Critical Infrastructure
Government Targeting
Ransomware
Espionage
Cyberspace
Banking/Financial Sector
Naikon
APT30
Override Panda
China State Sponsored
PLA Unit 78020
SpearPhishingAttachment
DataTheft
TargetedAttacks
GovernmentMilitaryTargets
CivilianOrganizations
SoutheastAsia
UNDP
ASEAN
Backdoor
Aria-body
RainyDay
DLLSideLoading
Persistence
CredentialDumping
LateralMovement

Details

MITRE ID
G0019
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
C
Confidence
90%
Added
May 26, 2026
STIX ID
intrusion-set--2a158b0a-7ef8-43cb-9985-bf34d1e12050
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.