Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: Dynamite Panda, TG-0416, APT18, TA428, Colourful Panda, BRONZE DUDLEY, tracked as, IRIDIUM, VOODOO BEAR, BE2, Tech Sectors, Threat Intelligence, Chimaera, Agrius

Description

Wekby is a well‐resourced Chinese threat actor that targets a broad portfolio of sectors—including aerospace and defense, high technology, telecommunications, healthcare, education, transportation, and critical infrastructure—across the United States, Europe, and other regions. The group operates with clear espionage objectives, collecting strategic intelligence by leveraging sophisticated delivery mechanisms such as phishing emails with obfuscated attachments (e.g., Pisloader) and exploiting newly discovered vulnerabilities to gain initial footholds. Operationally, Wekby employs a mix of custom implants—HTTPBrowser, Pigloader, HcdLoader—and third‑party tools like TokenControl to establish persistence. Its malware demonstrates persistence through HKCU\

Goals & Targeting

Targeted Sectors

Defense
Healthcare
Technology
Telecommunications
Aerospace & defense
Education
Transportation
Government
Financial services
Non profit
Aerospace
Energy
Pharmaceutical
Critical infrastructure
Manufacturing
Media
Maritime
Think tank
Information technology
Construction
Retail
Utilities
Oil gas

Targeted Countries / Regions

US
CN
UA
RU
KR
IN
SA
PL
TW
KP
IL
MX
VN
IR
JP
CA
AZ
BY
PK
GB
europe

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 6 hours ago

Executive Summary

Wekby (APT18/Dynamite Panda) is a sophisticated Chinese nation‑state actor focused on espionage against critical infrastructure, technology, and government sectors across the United States and Europe. The group relies heavily on DNS‑based command‑and‑control, phishing with obfuscated implants such as Pisloader, and anti‑analysis techniques like ROP packing to evade detection. Rapid exploitation of zero‑days and persistent execution via Run keys and scheduled tasks enable long‑term presence within target environments.

Enhanced Description

ATT&CK Techniques

Software / Tooling

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: Tech Sectors
  2. attack.mitre.org — Cited by web research for: T1059
  3. unit42.paloaltonetworks.com — Cited by web research for: Clayslide
  4. learn.microsoft.com — Cited by web research for: Tsunami
  5. unit42.paloaltonetworks.com — Cited by web research for: WildFire
  6. apt.etda.or.th — Cited by web research for: Telecommunications

Intel Summary

28

Techniques

49

Tools

3

Campaigns

40

IOCs

0

Observed Data

5

Tactics

Tags

APT
Healthcare Targeting
Government Targeting
espionage
nation-state
defense
technology
telecommunications

Details

MITRE ID
APT18
Type
Nation-State
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
70%
Added
Jul 15, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.