Also known as: Deputy Dog, Aurora Panda, APT17, Hidden Lynx, Tailgater Team, Group 8, "Axiom, SportsFans, Winnti Umbrella, Dogfish, BRONZE KEYSTONE, G0025, Group 72, G0001, Axiom, HELIUM, Heart Typhoon, DeputyDog, Sandworm Team, APT41, Winnti, tracked as, T-APT-17, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, APT1, Unit 61398, APT37, Ricochet Chollima, ScarCruft, Reaper Group, Spring Dragon, Billbug, manufacturing, telecom, Vietnam, Hong Kong, Rare Wolf, Belarusian, Ukrainian industrial enterprises, Gamaredon, verifying the signature, Shadows, Comet, Darkstar, to carry out attacks, APT44, BlackEnergy, PHANTOM, UAC-0133, Bitter, APT-C-08, Orange Yali, TA397, Thrip, Blue Echidna, Sandworm, UNK_CraftyCamel, ZDI-25-148
APT17 (Deputy Dog/Hidden Lynx) traces back to 2013 when it leveraged the CVE‑2013‑3893 Windows Mark‑of‑the‑Web double‑archive zero‑day against Japanese organizations. Since then, the group has broadened its reach worldwide, targeting U.S., European, and Eurasian entities in critical industries such as aerospace, defense, energy, telecom, finance, healthcare, manufacturing, and non‑profits. APT17 consistently employs a blend of social engineering and software exploitation to gain initial access: spear‑phishing with spoofed documents, exploitation of public‑facing vulnerabilities (e.g., CVE‑2023‑48788, CVE‑2024‑1709), and zero‑days in proprietary applications. Once inside, the actor establishes persistence via web shells uploaded through compromised web servers, then leverages Windows Management Instrumentation (WMI) commands to move laterally. APT17 creates new local and domain accounts, changes passwords, and deploys advanced malware such as Cobalt Strike for command‑and‑control alongside ransomware binaries (Cring.exe, Ghost.exe, ElysiumO.exe, Locker.exe). The group further obfuscates traffic by embedding encoded IP addresses in scripts and hides its C2 servers behind legitimate hosted domains such as cisa.gov or custom TEMP.* subdomains. APT17’s operations demonstrate a high level of technical sophistication, rapid exploit development, and operational diversity across industries and geographies. Despite being linked to large state‑aligned campaigns, the actor remains distinct from groups like Winnti and Sandworm, focusing more on espionage and ransomware as a service rather than purely destructive objectives.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
APT17, also known as Deputy Dog and Hidden Lynx, is a China‑based threat actor that has repeatedly exploited zero‑day vulnerabilities to infiltrate U.S., Japanese, and Ukrainian high‑value targets spanning government, defense, manufacturing, and critical infrastructure sectors. The group blends spear‑phishing with sophisticated exploitation and hosts its command-and-control on legitimate web domains, making detection difficult for conventional security tools. APT17’s recent campaigns feature rapid development of custom exploits, widespread use of web shells, and an expanding ransomware portfolio.
Goals & Targeting
Strategically, APT17 appears motivated by long‑term intelligence gathering with an ancillary goal of monetization through ransomware. Its sector focus—government, defense, aerospace, telecommunications, manufacturing, energy, and non‑profits—reflects a dual agenda: obtaining strategic data while exploiting vulnerabilities for financial gain. The actor’s geographic spread, covering China, United States, Russia, Japan, Ukraine, Indonesia, and various Middle Eastern and European nations, indicates an opportunistic approach that prioritizes high‑value targets over political alignment. Tactics such as spear‑phishing, zero‑day exploitation, web shell persistence, and encoded C2 channels serve to evade detection while maintaining long‑term footholds. By creating new accounts and modifying passwords they can establish privilege escalation paths, enabling deeper infiltration and potential exfiltration of classified or sensitive data. The recent adoption of ransomware assets suggests a shift toward profit‑driven attacks when opportunities arise. In sum, APT17’s operational profile fits that of an “information stealer + opportunistic extortionist” with capabilities enabling both stealthy espionage and disruptive financial operations.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
APT17’s campaigns reveal a consistent pattern of exploiting publicly disclosed vulnerabilities, often targeting high‑profile infrastructure in the wake of patch cycles. The group operates with a moderate to rapid tempo, frequently pivoting between sectors within weeks while maintaining persistence through web shells and custom implants. Victim profiles span government agencies, defense contractors, energy operators, telecom firms, manufacturing plants, and non‑profits across >30 countries—indicative of opportunistic targeting rather than a narrow geopolitical focus. A notable aspect is the actor’s use of legitimate domains and encoded C2 channels to mask activity; it frequently hijacks or leverages compromised high‑traffic sites like cisa.gov for command and control. Recent operations such as the ‘BadPilot’ campaign linked to APT44 demonstrated multi‑stage ransomware deployment (Cring, Ghost) alongside Cobalt Strike lateral movement—showcasing an expanding operational scope and a potential shift toward monetization. Overall, APT17’s pattern underscores sophisticated threat hunting demands: continuous monitoring of both known CVEs and emerging double‑archive tactics, vigilant endpoint detection for obscure RDP/WMIC commands, and robust network segmentation to contain web shell persistence.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The intelligence on APT17 is high confidence regarding its use of zero‑day exploits, web shell persistence, and Cobalt Strike for command-and-control—all corroborated by multiple vendor reports. Confidence in the actor’s exact motivations (espionage versus monetization) remains moderate due to limited direct attribution of financial motives. Key gaps include precise timelines of campaigns, detailed attribution linking all aliases, and comprehensive insight into the extent of their ransomware delivery network.
Ephemeral Hydra
No observed data linked yet.
19
Techniques
63
Tools
1
Campaigns
37
IOCs
0
Observed Data
7
Tactics