Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: APT16, SVCMONDR, G0023

Description

APT16 is a China-based threat group that has launched spearphishing campaigns targeting Japanese and Taiwanese organizations. (Citation: FireEye EPS Awakens Part 2)

TTP Summary

Spear phishing email delivering a malicious Microsoft Word document exploiting EPS dict copy use-after-free vulnerability, and the local Windows privilege escalation vulnerability CVE-2015-1701. The successful exploitation of both vulnerabilities led to the delivery of either a downloader (IRONHALO), or a backdoor (ELMER). Also known to be using compromised VPN credentials to maintain network persistency.

Goals & Targeting

Targeted Sectors

Government
Financial services
Media

Targeted Countries / Regions

TW
JP

AI Analysis

· 2 months ago

Executive Summary

APT16, a China-based threat group, targets Japanese and Taiwanese organizations in the government, financial services, and media sectors with spearphishing campaigns to steal sensitive information. Their primary motivation is espionage, using tactics such as exploiting vulnerabilities and phishing to gain access to networks. APT16's activities have been observed delivering malicious Microsoft Word documents and utilizing compromised VPN credentials for persistence.

Goals & Targeting

APT16's strategic objectives are centered around conducting espionage operations against organizations in the government, financial services, and media sectors. The group's targeting of Japanese and Taiwanese organizations suggests a specific interest in regional geopolitical issues, with the potential goal of gathering intelligence to inform Chinese foreign policy decisions. Typical victims of APT16's operations include high-profile organizations with access to sensitive information, such as government agencies, financial institutions, and media outlets.

Enhanced Description

APT16's operations are characterized by a high degree of sophistication, with the group demonstrating a deep understanding of the vulnerabilities and weaknesses present within the networks they target. The use of spearphishing campaigns, combined with the exploitation of known vulnerabilities, highlights the group's ability to adapt and evolve their tactics in response to changing network defenses. Furthermore, the utilization of compromised VPN credentials underscores the group's focus on establishing and maintaining a persistent presence within targeted networks, facilitating the exfiltration of sensitive information over an extended period.

Key Capabilities

  • Spearphishing
  • Exploitation of known vulnerabilities
  • Utilization of compromised VPN credentials
  • Delivery of malicious Microsoft Word documents
  • Establishment of persistent network access

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion

ATT&CK Techniques

T1059.003
T1055
T1566.001
T1588.006
T1566
T1589.001
T1584.004

Software / Tooling

ELMER
IRONHALO
Phishing tools

Campaigns & Victims

APT16's campaign patterns are characterized by a focus on targeting specific organizations within the government, financial services, and media sectors. The group's operational tempo is marked by a high degree of persistence, with APT16 maintaining access to targeted networks over an extended period. Notable past operations include the use of spearphishing campaigns to deliver malicious Microsoft Word documents, as well as the exploitation of compromised VPN credentials to establish persistent network access.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 over DNS using fast-flux
  • Staging infrastructure on bulletproof hosting

Recommended Actions

  • Implement robust email filtering and scanning to detect and block spearphishing attempts
  • Regularly update and patch vulnerable software to prevent exploitation
  • Utilize multi-factor authentication to secure VPN access
  • Conduct regular network monitoring to detect and respond to potential APT16 activity

Suggested Tags

APT
Espionage
China
Spearphishing

Confidence Assessment

The available data on APT16 provides a moderate to high confidence level in the group's tactics, techniques, and procedures (TTPs). However, information gaps exist regarding the group's exact motivations, the scope of their operations, and the full range of their technical capabilities. Further research and analysis are necessary to fully understand the threat posed by APT16 and to develop effective countermeasures.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. FireEye EPS Awakens Part 2 — Winters, R. (2015, December 20). The EPS Awakens - Part 2. Retrieved January 22, 2016.

Intel Summary

1

Techniques

8

Tools

0

Campaigns

3

IOCs

0

Observed Data

1

Tactics

Tags

APT
Phishing
Backdoor / C2
Espionage
China
Spearphishing

Details

MITRE ID
G0023
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--d6e88e18-81e8-4709-82d8-973095da1e70
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.