Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: TG-0416, Dynamite Panda, Threat Group-0416, SCANDIUM, PLA Navy, Wekby, G0026, Satin Typhoon, tracked as, TA428, Advanced Persistent Threat 39, Chafer, Cadelspy, Remexi, ITG07, Unit 61398, Sandworm Team, Gamaredon APT, REvil

Description

APT18 is a long‑standing threat actor that has been active since 2009, targeting a broad spectrum of industries ranging from technology and manufacturing to human rights organizations and medical institutions. Operating under various monikers—including Dynamite Panda, Threat Group‑0416, Scandium, and Wekby—the group demonstrates typical state‑sponsored espionage motives, focusing on information gathering rather than destructive sabotage. The group’s techniques are characterized by low‑profile command execution via the Windows command shell (cmd.exe) and the native at scheduler for task creation. Persistence is achieved through registry Run keys under HKCU\Software\Microsoft\Windows\CurrentVersion\Run. APT18 frequently leverages legitimate credentials to access external remote services, such as VPNs or corporate portals, enabling lateral movement while maintaining plausible deniability. Notably, the group employs DNS queries as a covert channel for command and control, often obfuscating traffic with encoded payloads (T1027) and cleansing evidence by deleting batch files and other artifacts post‑deployment. It also conducts file upload operations (T1105), occasionally using well‑known delivery tools that are promptly cleared from victim systems.

Goals & Targeting

Targeted Sectors

Government
Financial services
Telecommunications
Non profit
Defense
Healthcare
Manufacturing
Energy
Education
Media
Pharmaceutical
Information technology
Aerospace
Transportation
Critical infrastructure
Maritime
Legal services
Utilities
Aviation
Think tank
Mining
Chemical
Construction
Retail
Hospitality
Nuclear

Targeted Countries / Regions

US
CN
RU
UA
SA
IN
KR
PK
AE
IL
KP
TW
IR
VN
MX
ES
AZ
AU
NL
BY
GB
TR
LB
JP
RO

AI Analysis

Grounded in web research
· 2 days ago

Executive Summary

APT18, also known as Wekby or TG‑0416, is a state-sponsored espionage group believed to be linked to the PLA Navy that has operated since at least 2009. It targets high-value sectors—including government, defense, healthcare, and critical infrastructure—using stealthy operations such as DNS‑based command channels and legitimate credentials. The group routinely removes its tools from victim machines after exploitation, reducing forensic footprints.

Goals & Targeting

APT18’s primary goal is strategic espionage, seeking to procure sensitive data across a wide range of sectors including defense, aerospace, telecommunications, and healthcare. By targeting both government agencies and critical infrastructure entities, the group aims to gain leverage for geopolitical advantage or intelligence-driven decision making. Typical victims are midsize to large organizations with robust IT environments that still rely on user accounts or remote service access, enabling APT18 to exploit legitimate credentials and subtle command channels. The actor’s broad sector focus suggests a value‑driven approach: capturing proprietary technology from manufacturing firms, surveillance data from defense contractors, and personal data from healthcare and legal services. Geographic targeting spans NATO allies, emerging economies, and regions of strategic interest to the sponsoring government, underscoring an intelligence-gathering mission rather than purely financial or destructive motives.

Enhanced Description

Key Capabilities

  • Command execution via cmd.exe (T1059.003)
  • Persistence through HKCU Run key (T1547.001)
  • Use of DNS for covert C2 channels (T1071.004)
  • Leverage of legitimate credentials to access external services (T1078)
  • Obfuscation and encoding of files (T1027)
  • Scheduled task creation with native at tool (T1053.002)
  • Cleanup of artifacts post‑exploitation (T1070)

MITRE ATT&CK Tactics

Persistence
Execution
Command and Control
Defense Evasion
Credential Access
Collection

ATT&CK Techniques

T1071.004
T1071.001
T1059.003
T1547.001
T1078
T1027
T1053.002
T1105
T1082
T1083
T1070
T1070.004

Software / Tooling

ReGeorg
Netwire
Machete
Pisloader
HTTPBrowser
Cobalt Strike

Campaigns & Victims

Since its emergence in 2009, APT18 has displayed a pattern of opportunistic attacks that exploit newly disclosed vulnerabilities or zero‑day exploits shortly after release. The group often employs phishing campaigns with obfuscated attachments—such as the HTTPBrowser dropper—to deliver payloads. Its operational tempo is moderate; operations are spaced out by months but can intensify during periods of geopolitical tension. Victims typically include high‑profile organizations across a wide array of industries, especially those involved in defense and critical infrastructure. Notable incidents include the 2015‐2016 Wekby attacks that leveraged DNS C2 channels and the 2016 use of Pisloader dropper for initial access. APT18’s strategic emphasis on stealth is evident from its consistent removal of tools after deployment and its preference for command–line interfaces, which leave minimal logs. The group’s adaptability—evidenced by its use of both commercial remote tools (e.g., VPNs) and custom exploit suites—demonstrates an ongoing evolution in response to defensive postures.

IOC Patterns

  • Phishing emails carrying obfuscated HTTPBrowser variants
  • DNS queries used as covert command channels
  • Upload of malicious payloads via T1105
  • Execution via cmd.exe and at scheduled tasks

Recommended Actions

  • Deploy user and system monitoring for anomalous cmd.exe usage and registry modifications in HKCU Run keys.
  • Implement DNS traffic analysis to flag repetitive, non‑standard query patterns towards known malicious domains.
  • Enforce least privilege by disabling or strictly controlling remote service credentials where possible.
  • Deploy automated cleanup scripts to delete temporary files and batch scripts after execution,
  • Maintain an up‑to‑date inventory of legitimate remote access devices and conduct periodic key rotation.

Suggested Tags

APT
Espionage
China PLA Navy
State-sponsored
Critical Infrastructure Targeting

Confidence Assessment

The assessment is based on publicly available reports and MITRE ATT&CK references, providing moderate confidence in core TTPs. Gaps exist regarding the most recent toolset, exact exploitation methods beyond known DNS and cmd-based techniques, and the precise alignment of aliases to a single sponsoring nation.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 1 Domain 19

References

  1. Dell Lateral Movement — Carvey, H.. (2014, September 2). Where you AT?: Indicators of lateral movement using at.exe on Windows 7 systems. Retrieved January 25, 2016.
  2. Anomali Evasive Maneuvers July 2015 — Shelmire, A. (2015, July 06). Evasive Maneuvers by the Wekby group with custom ROP-packing and DNS covert channels. Retrieved November 15, 2018.
  3. ThreatStream Evasion Analysis — Shelmire, A.. (2015, July 6). Evasive Maneuvers. Retrieved January 22, 2016.
  4. attack.mitre.org — Cited by web research for: Advanced Persistent Threat 39
  5. docs.rapid7.com — Cited by web research for: Unit 61398
  6. attack.mitre.org — Cited by web research for: T1071
  7. learn.microsoft.com — Cited by web research for: Tsunami
  8. apt.etda.or.th — Cited by web research for: HTTPBrowser
  9. cloud.google.com — Cited by web research for: aqdrmf-rymPhb-ibnC6b.aqdrmf
  10. https://unit42.paloaltonetworks.com/unit42-new-wekby-attacks-use-dns-requests-as-command-and-control-mechanism/ — Cited by AI analysis.
  11. https://www.fireeye.com/blog/threat-research/2015/07/demonstrating_hustle.html — Cited by AI analysis.

Intel Summary

29

Techniques

53

Tools

0

Campaigns

38

IOCs

0

Observed Data

6

Tactics

Tags

APT
espionage
government
technology
manufacturing
Espionage
China PLA Navy
State-sponsored
Critical Infrastructure Targeting

Details

MITRE ID
G0026
Type
Unknown
Primary Motivation
Espionage
Country of Origin
C
Confidence
90%
Added
Jul 22, 2026
STIX ID
intrusion-set--38fd6a28-3353-4f2b-bb2b-459fecd5c648
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.