Also known as: APT16, SVCMONDR, G0023
APT16 is a China-based threat group that has launched spearphishing campaigns targeting Japanese and Taiwanese organizations. (Citation: FireEye EPS Awakens Part 2)
Spear phishing email delivering a malicious Microsoft Word document exploiting EPS dict copy use-after-free vulnerability, and the local Windows privilege escalation vulnerability CVE-2015-1701. The successful exploitation of both vulnerabilities led to the delivery of either a downloader (IRONHALO), or a backdoor (ELMER). Also known to be using compromised VPN credentials to maintain network persistency.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
APT16, a China-based threat group, targets Japanese and Taiwanese organizations in the government, financial services, and media sectors with spearphishing campaigns to steal sensitive information. Their primary motivation is espionage, using tactics such as exploiting vulnerabilities and phishing to gain access to networks. APT16's activities have been observed delivering malicious Microsoft Word documents and utilizing compromised VPN credentials for persistence.
Goals & Targeting
APT16's strategic objectives are centered around conducting espionage operations against organizations in the government, financial services, and media sectors. The group's targeting of Japanese and Taiwanese organizations suggests a specific interest in regional geopolitical issues, with the potential goal of gathering intelligence to inform Chinese foreign policy decisions. Typical victims of APT16's operations include high-profile organizations with access to sensitive information, such as government agencies, financial institutions, and media outlets.
Enhanced Description
APT16's operations are characterized by a high degree of sophistication, with the group demonstrating a deep understanding of the vulnerabilities and weaknesses present within the networks they target. The use of spearphishing campaigns, combined with the exploitation of known vulnerabilities, highlights the group's ability to adapt and evolve their tactics in response to changing network defenses. Furthermore, the utilization of compromised VPN credentials underscores the group's focus on establishing and maintaining a persistent presence within targeted networks, facilitating the exfiltration of sensitive information over an extended period.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
APT16's campaign patterns are characterized by a focus on targeting specific organizations within the government, financial services, and media sectors. The group's operational tempo is marked by a high degree of persistence, with APT16 maintaining access to targeted networks over an extended period. Notable past operations include the use of spearphishing campaigns to deliver malicious Microsoft Word documents, as well as the exploitation of compromised VPN credentials to establish persistent network access.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available data on APT16 provides a moderate to high confidence level in the group's tactics, techniques, and procedures (TTPs). However, information gaps exist regarding the group's exact motivations, the scope of their operations, and the full range of their technical capabilities. Further research and analysis are necessary to fully understand the threat posed by APT16 and to develop effective countermeasures.
No campaigns linked yet.
No observed data linked yet.
1
Techniques
8
Tools
0
Campaigns
3
IOCs
0
Observed Data
1
Tactics