Also known as: Dynamite Panda, TG-0416, APT18, TA428, Colourful Panda, BRONZE DUDLEY, tracked as, IRIDIUM, VOODOO BEAR, BE2, Tech Sectors, Threat Intelligence, Chimaera, Agrius
Wekby is a well‐resourced Chinese threat actor that targets a broad portfolio of sectors—including aerospace and defense, high technology, telecommunications, healthcare, education, transportation, and critical infrastructure—across the United States, Europe, and other regions. The group operates with clear espionage objectives, collecting strategic intelligence by leveraging sophisticated delivery mechanisms such as phishing emails with obfuscated attachments (e.g., Pisloader) and exploiting newly discovered vulnerabilities to gain initial footholds. Operationally, Wekby employs a mix of custom implants—HTTPBrowser, Pigloader, HcdLoader—and third‑party tools like TokenControl to establish persistence. Its malware demonstrates persistence through HKCU\
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Wekby (APT18/Dynamite Panda) is a sophisticated Chinese nation‑state actor focused on espionage against critical infrastructure, technology, and government sectors across the United States and Europe. The group relies heavily on DNS‑based command‑and‑control, phishing with obfuscated implants such as Pisloader, and anti‑analysis techniques like ROP packing to evade detection. Rapid exploitation of zero‑days and persistent execution via Run keys and scheduled tasks enable long‑term presence within target environments.
Enhanced Description
No observed data linked yet.
28
Techniques
49
Tools
3
Campaigns
40
IOCs
0
Observed Data
5
Tactics