Also known as: TG-0416, Dynamite Panda, Threat Group-0416, SCANDIUM, PLA Navy, Wekby, G0026, Satin Typhoon, tracked as, TA428, Advanced Persistent Threat 39, Chafer, Cadelspy, Remexi, ITG07, Unit 61398, Sandworm Team, Gamaredon APT, REvil
APT18 is a long‑standing threat actor that has been active since 2009, targeting a broad spectrum of industries ranging from technology and manufacturing to human rights organizations and medical institutions. Operating under various monikers—including Dynamite Panda, Threat Group‑0416, Scandium, and Wekby—the group demonstrates typical state‑sponsored espionage motives, focusing on information gathering rather than destructive sabotage. The group’s techniques are characterized by low‑profile command execution via the Windows command shell (cmd.exe) and the native at scheduler for task creation. Persistence is achieved through registry Run keys under HKCU\Software\Microsoft\Windows\CurrentVersion\Run. APT18 frequently leverages legitimate credentials to access external remote services, such as VPNs or corporate portals, enabling lateral movement while maintaining plausible deniability. Notably, the group employs DNS queries as a covert channel for command and control, often obfuscating traffic with encoded payloads (T1027) and cleansing evidence by deleting batch files and other artifacts post‑deployment. It also conducts file upload operations (T1105), occasionally using well‑known delivery tools that are promptly cleared from victim systems.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
APT18, also known as Wekby or TG‑0416, is a state-sponsored espionage group believed to be linked to the PLA Navy that has operated since at least 2009. It targets high-value sectors—including government, defense, healthcare, and critical infrastructure—using stealthy operations such as DNS‑based command channels and legitimate credentials. The group routinely removes its tools from victim machines after exploitation, reducing forensic footprints.
Goals & Targeting
APT18’s primary goal is strategic espionage, seeking to procure sensitive data across a wide range of sectors including defense, aerospace, telecommunications, and healthcare. By targeting both government agencies and critical infrastructure entities, the group aims to gain leverage for geopolitical advantage or intelligence-driven decision making. Typical victims are midsize to large organizations with robust IT environments that still rely on user accounts or remote service access, enabling APT18 to exploit legitimate credentials and subtle command channels. The actor’s broad sector focus suggests a value‑driven approach: capturing proprietary technology from manufacturing firms, surveillance data from defense contractors, and personal data from healthcare and legal services. Geographic targeting spans NATO allies, emerging economies, and regions of strategic interest to the sponsoring government, underscoring an intelligence-gathering mission rather than purely financial or destructive motives.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Since its emergence in 2009, APT18 has displayed a pattern of opportunistic attacks that exploit newly disclosed vulnerabilities or zero‑day exploits shortly after release. The group often employs phishing campaigns with obfuscated attachments—such as the HTTPBrowser dropper—to deliver payloads. Its operational tempo is moderate; operations are spaced out by months but can intensify during periods of geopolitical tension. Victims typically include high‑profile organizations across a wide array of industries, especially those involved in defense and critical infrastructure. Notable incidents include the 2015‐2016 Wekby attacks that leveraged DNS C2 channels and the 2016 use of Pisloader dropper for initial access. APT18’s strategic emphasis on stealth is evident from its consistent removal of tools after deployment and its preference for command–line interfaces, which leave minimal logs. The group’s adaptability—evidenced by its use of both commercial remote tools (e.g., VPNs) and custom exploit suites—demonstrates an ongoing evolution in response to defensive postures.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The assessment is based on publicly available reports and MITRE ATT&CK references, providing moderate confidence in core TTPs. Gaps exist regarding the most recent toolset, exact exploitation methods beyond known DNS and cmd-based techniques, and the precise alignment of aliases to a single sponsoring nation.
No campaigns linked yet.
No observed data linked yet.
29
Techniques
53
Tools
0
Campaigns
38
IOCs
0
Observed Data
6
Tactics