Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: Deputy Dog, Aurora Panda, APT17, Hidden Lynx, Tailgater Team, Group 8, "Axiom, SportsFans, Winnti Umbrella, Dogfish, BRONZE KEYSTONE, G0025, Group 72, G0001, Axiom, HELIUM, Heart Typhoon, DeputyDog, Sandworm Team, APT41, Winnti, tracked as, T-APT-17, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, APT1, Unit 61398, APT37, Ricochet Chollima, ScarCruft, Reaper Group, Spring Dragon, Billbug, manufacturing, telecom, Vietnam, Hong Kong, Rare Wolf, Belarusian, Ukrainian industrial enterprises, Gamaredon, verifying the signature, Shadows, Comet, Darkstar, to carry out attacks, APT44, BlackEnergy, PHANTOM, UAC-0133, Bitter, APT-C-08, Orange Yali, TA397, Thrip, Blue Echidna, Sandworm, UNK_CraftyCamel, ZDI-25-148

Description

APT17 (Deputy Dog/Hidden Lynx) traces back to 2013 when it leveraged the CVE‑2013‑3893 Windows Mark‑of‑the‑Web double‑archive zero‑day against Japanese organizations. Since then, the group has broadened its reach worldwide, targeting U.S., European, and Eurasian entities in critical industries such as aerospace, defense, energy, telecom, finance, healthcare, manufacturing, and non‑profits. APT17 consistently employs a blend of social engineering and software exploitation to gain initial access: spear‑phishing with spoofed documents, exploitation of public‑facing vulnerabilities (e.g., CVE‑2023‑48788, CVE‑2024‑1709), and zero‑days in proprietary applications. Once inside, the actor establishes persistence via web shells uploaded through compromised web servers, then leverages Windows Management Instrumentation (WMI) commands to move laterally. APT17 creates new local and domain accounts, changes passwords, and deploys advanced malware such as Cobalt Strike for command‑and‑control alongside ransomware binaries (Cring.exe, Ghost.exe, ElysiumO.exe, Locker.exe). The group further obfuscates traffic by embedding encoded IP addresses in scripts and hides its C2 servers behind legitimate hosted domains such as cisa.gov or custom TEMP.* subdomains. APT17’s operations demonstrate a high level of technical sophistication, rapid exploit development, and operational diversity across industries and geographies. Despite being linked to large state‑aligned campaigns, the actor remains distinct from groups like Winnti and Sandworm, focusing more on espionage and ransomware as a service rather than purely destructive objectives.

Goals & Targeting

Targeted Sectors

Government
Defense
Aerospace & defense
Ngo
Financial services
Telecommunications
Manufacturing
Energy
Education
Healthcare
Non profit
Media
Pharmaceutical
Legal services
Information technology
Transportation
Critical infrastructure
Aviation
Aerospace
Mining
Retail
Chemical
Hospitality
Think tank
Maritime
Oil gas
Nuclear
Gaming
Construction
Entertainment
Utilities
Food agriculture

Targeted Countries / Regions

CN
US
RU
JP
VN
TW
IR
UA
SA
IL
AE
KR
GB
AU
PK
IN
SG
DE
TR
BY
RO
MX
ES
PL
CA
LB
FR
NG
KP
IT
AZ
KZ
BR

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

APT17, also known as Deputy Dog and Hidden Lynx, is a China‑based threat actor that has repeatedly exploited zero‑day vulnerabilities to infiltrate U.S., Japanese, and Ukrainian high‑value targets spanning government, defense, manufacturing, and critical infrastructure sectors. The group blends spear‑phishing with sophisticated exploitation and hosts its command-and-control on legitimate web domains, making detection difficult for conventional security tools. APT17’s recent campaigns feature rapid development of custom exploits, widespread use of web shells, and an expanding ransomware portfolio.

Goals & Targeting

Strategically, APT17 appears motivated by long‑term intelligence gathering with an ancillary goal of monetization through ransomware. Its sector focus—government, defense, aerospace, telecommunications, manufacturing, energy, and non‑profits—reflects a dual agenda: obtaining strategic data while exploiting vulnerabilities for financial gain. The actor’s geographic spread, covering China, United States, Russia, Japan, Ukraine, Indonesia, and various Middle Eastern and European nations, indicates an opportunistic approach that prioritizes high‑value targets over political alignment. Tactics such as spear‑phishing, zero‑day exploitation, web shell persistence, and encoded C2 channels serve to evade detection while maintaining long‑term footholds. By creating new accounts and modifying passwords they can establish privilege escalation paths, enabling deeper infiltration and potential exfiltration of classified or sensitive data. The recent adoption of ransomware assets suggests a shift toward profit‑driven attacks when opportunities arise. In sum, APT17’s operational profile fits that of an “information stealer + opportunistic extortionist” with capabilities enabling both stealthy espionage and disruptive financial operations.

Enhanced Description

Key Capabilities

  • Exploit zero‑day vulnerabilities
  • Create and customize exploits rapidly
  • Host command‑and‑control on legitimate websites
  • Obfuscate C&C IP addresses via encoding
  • Bypass Windows Mark‑of‑the‑Web through double‑archival files
  • Spear‑phishing using spoofed documents
  • Upload and deploy web shells on compromised servers
  • Execute PowerShell and Windows command prompt scripts via WMIC
  • Establish persistence through web shells
  • Create new local and domain user accounts
  • Change account passwords
  • Download and execute Cobalt Strike Beacon malware
  • Deploy ransomware executables (Cring.exe, Ghost.exe, ElysiumO.exe, Locker.exe)

MITRE ATT&CK Tactics

Resource Development
Command and Control
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Development
Impact

ATT&CK Techniques

T1583
T1585
T1190
T1105
T1059.001
T1086
T1047
T1136.001
T1136.002
T1098
T1486

Software / Tooling

BLACKCOFFEE
Cobalt Strike
Cring.exe
Ghost.exe
ElysiumO.exe
Locker.exe
J-magic
Machete
China Chopper
PlugX
Akira
Carbanak
Hydraq
Sagerunex
gh0st RAT
Hikit
Sakula
ZxShell
AppleJeus
ShadowPad
Mythic
WEBCnC
Joy RAT
Trojan.Naid
Backdoor.Moudoor
Backdoor.Vasport
Backdoor.Boda
DestroyRAT
Winnti
Deputy Dog
PowerShell
Dark
Nexus
SideWinder
OilRig
Zero-day exploits
Aurora
BlackByte
Confucius
FatalRat
Global
Kimsuky
Lynx
Merlin
Naikon
Polyglot
Void
Remote access tools
APT38
Hafnium
MuddyWater

Campaigns & Victims

APT17’s campaigns reveal a consistent pattern of exploiting publicly disclosed vulnerabilities, often targeting high‑profile infrastructure in the wake of patch cycles. The group operates with a moderate to rapid tempo, frequently pivoting between sectors within weeks while maintaining persistence through web shells and custom implants. Victim profiles span government agencies, defense contractors, energy operators, telecom firms, manufacturing plants, and non‑profits across >30 countries—indicative of opportunistic targeting rather than a narrow geopolitical focus. A notable aspect is the actor’s use of legitimate domains and encoded C2 channels to mask activity; it frequently hijacks or leverages compromised high‑traffic sites like cisa.gov for command and control. Recent operations such as the ‘BadPilot’ campaign linked to APT44 demonstrated multi‑stage ransomware deployment (Cring, Ghost) alongside Cobalt Strike lateral movement—showcasing an expanding operational scope and a potential shift toward monetization. Overall, APT17’s pattern underscores sophisticated threat hunting demands: continuous monitoring of both known CVEs and emerging double‑archive tactics, vigilant endpoint detection for obscure RDP/WMIC commands, and robust network segmentation to contain web shell persistence.

IOC Patterns

  • Encoded IP addresses embedded in scripts for command‑and‑control
  • Legitimate websites used as C&C infrastructure hosts
  • Double‑archived files bypassing Windows Mark‑of‑the‑Web protection
  • Spear‑phishing emails with spoofed document extensions
  • Exploitation of publicly disclosed CVEs such as CVE‑2024‑1709 and CVE‑2023‑48788
  • Web shell uploads to compromised web servers
  • WMIC command execution for lateral movement
  • Download and execution of Cobalt Strike Beacon
  • Ransomware binaries Cring.exe, Ghost.exe, ElysiumO.exe, Locker.exe

Recommended Actions

  • Patch all known vulnerabilities (e.g., CVE‑2013‑3893) promptly; Monitor traffic to/from encoded IP addresses used by malicious C2 servers; Block or quarantine access to legitimate sites hijacked for malicious C&C; Deploy email filtering and attachment sandboxing against spearfishing with spoofed documents; Detect and block double‑archived file execution attempts that bypass Mark‑of‑the‑Web checks; Implement detection rules for anomalous PowerShell, CMD, and WMIC usage on non‑normal hosts; Use endpoint protection to detect and quarantine ransomware binaries (Cring, Ghost, ElysiumO, Locker); Enforce least privilege principles, monitor new user account creation and password changes; Employ network segmentation and continuous behavioral analytics for lateral movement detection;

Suggested Tags

APT17
DeputyDog
HiddenLynx
AuroraPanda
BlackCoffee
ZeroDayExploit
CommandAndControl
DoubleArchive
SpearPhishing
APT44
BadPilot campaign
WebShell
VulnerabilityExploitation
CobaltStrike
Ransomware
WMI
WindowsCommandPrompt

Confidence Assessment

The intelligence on APT17 is high confidence regarding its use of zero‑day exploits, web shell persistence, and Cobalt Strike for command-and-control—all corroborated by multiple vendor reports. Confidence in the actor’s exact motivations (espionage versus monetization) remains moderate due to limited direct attribution of financial motives. Key gaps include precise timelines of campaigns, detailed attribution linking all aliases, and comprehensive insight into the extent of their ransomware delivery network.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 5 Domain 15

References

  1. FireEye APT17 — FireEye Labs/FireEye Threat Intelligence. (2015, May 14). Hiding in Plain Sight: FireEye and Microsoft Expose Obfuscation Tactic. Retrieved November 17, 2024.
  2. attack.mitre.org — Cited by web research for: Sandworm Team
  3. apt.etda.or.th — Cited by web research for: APT1
  4. docs.rapid7.com — Cited by web research for: Unit 61398
  5. ics-cert.kaspersky.com — Cited by web research for: APT37
  6. attack.mitre.org — Cited by web research for: T1583
  7. apt.etda.or.th — Cited by web research for: CVE-2013-3893
  8. https://www.cfr.org/cyber-operations/apt-17 — Cited by AI analysis.
  9. https://cloud.google.com/blog/topics/threat-intelligence/hiding_in_plain_sight — Cited by AI analysis.
  10. https://www.fireeye.com/blog/threat-research/2013/09/operation-deputydog-zero-day-cve-2013-3893-attack-against-japanese-targets.html — Cited by AI analysis.
  11. https://www.symantec.com/connect/blogs/security-vendors-take-action-against-hidden-lynx-malware — Cited by AI analysis.
  12. https://cloud.google.com/security/resources/insights/apt-groups — Cited by AI analysis.

Intel Summary

19

Techniques

63

Tools

1

Campaigns

37

IOCs

0

Observed Data

7

Tactics

Tags

APT
espionage
government
defense
APT17
DeputyDog
HiddenLynx
AuroraPanda
BlackCoffee
ZeroDayExploit
CommandAndControl
DoubleArchive
SpearPhishing
APT44
BadPilot campaign
WebShell
VulnerabilityExploitation
CobaltStrike
Ransomware
WMI
WindowsCommandPrompt

Details

MITRE ID
G0025
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
90%
Added
Jul 22, 2026
STIX ID
intrusion-set--090242d7-73fc-4738-af68-20162f7a5aae
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.