Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: G0039, Suckfly, BRONZE OLIVE, Group 46, tracked as, Destroy RAT, Kaba, Korplug, several other aliases, Turbine Panda, mid-2015, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, APT36, Shadow Brokers, JerseyMikes, TURBINE PANDA, BRONZE EXPRESS, TECHNETIUM, Taffeta Typhoon

Description

**Toolset/Malware:** China Chopper **Notes:** Possible overlap with Beijing Group

Goals & Targeting

Targeted Sectors

Government
Financial services
Defense
Telecommunications
Healthcare
Education
Manufacturing
Media
Non profit
Energy
Critical infrastructure
Pharmaceutical
Aviation
Hospitality
Information technology
Retail
Aerospace
Transportation
Gaming
Think tank
Mining
Chemical
Maritime
Entertainment
Legal services
Nuclear
Oil gas
Construction
Utilities

Targeted Countries / Regions

CN
US
RU
IR
UA
IN
VN
JP
IL
GB
AU
SA
PK
TW
AE
KR
TR
SG
DE
BY
MX
ES
PL
CA
RO
FR
NG
KP
IT
LB
AZ
KZ

AI Analysis

· 1 week ago

Executive Summary

APT22 is a nation-state threat actor primarily involved in espionage activities. The group targets defense and aerospace sectors in the US and NATO countries, using tools like China Chopper for web-based attacks. APT22's operations have been ongoing since at least 2014, with a focus on maintaining persistent access through webshells.

Goals & Targeting

APT22's strategic objectives center around espionage, aiming to acquire sensitive information from the defense sector. The targeting profile reflects a focus on countries that are adversaries of China, including the US and NATO nations, to gain military and technological intelligence.

Enhanced Description

APT22, also known as G0039, Suckfly, and BRONZE OLIVE, is a nation-state-sponsored cyber espionage group. The actor primarily targets defense and aerospace organizations in the US and NATO member states. APT22's modus operandi involves using webshells like China Chopper to gain initial access and maintain persistence in targeted networks. The group exhibits extensive campaign history dating back to at least 2014, with a focus on stealing sensitive data and intellectual property from defense contractors.

Key Capabilities

  • Webshell deployment (China Chopper)
  • Spear-phishing
  • Lateral movement within networks
  • Credential dumping

MITRE ATT&CK Tactics

Reconnaissance
Exfiltration
Defense Evasion

ATT&CK Techniques

T1057.004
T1203
T1566.002

Software / Tooling

China Chopper webshell
Custom malware

Campaigns & Victims

APT22 has been involved in multiple espionage campaigns targeting defense contractors. The group operates with a slow and methodical approach, focusing on maintaining long-term access to networks to steal sensitive data.

IOC Patterns

  • Webshell activity indicative of China Chopper usage
  • Malicious scripts injected into web pages

Recommended Actions

  • Implement strict email filtering to block spear-phishing attempts
  • Monitor for webshell-related network traffic

Suggested Tags

Nation-state
APT
Espionage
Defense sector

Confidence Assessment

High confidence in APT22's nation-state designation and espionage focus, though specific campaign details remain limited.

ATT&CK Techniques

Credential Access
1 technique
Defense impairment
1 technique
Discovery
1 technique
Initial Access
1 technique
Stealth
1 technique
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: Sandworm Team
  2. attack.mitre.org — Cited by web research for: T1059
  3. apt.etda.or.th — Cited by web research for: Custom malware
  4. securelist.com — Cited by web research for: Dark

Intel Summary

7

Techniques

46

Tools

0

Campaigns

12

IOCs

0

Observed Data

7

Tactics

Tags

Nation-state
APT
Espionage
Defense sector

Details

MITRE ID
APT22
Type
Nation-State
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
70%
Added
Jul 21, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.