Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors againstthewest

Also known as: APT49, AgainstTheWest, Samurai Panda, PLA Navy, APT4, Wisp Team

Description

AgainstTheWest (ATW) is a hacktivist group active since October 2021 that targets governments and corporations perceived as authoritarian, breaching organizations like Alibaba, Sberbank, and Gazprom using custom ransomware and wiper malware for ideological disruption rather than financial profit.

Goals & Targeting

Objectives

Ransomware
Financial Gain

Targeted Sectors

Government
Defense

Targeted Countries / Regions

CN

AI Analysis

· 1 week ago

Executive Summary

AgainstTheWest (ATW), also known as APT49, Samurai Panda, PLA Navy, APT4, and Wisp Team, is a hacktivist group targeting governments and corporations perceived as authoritarian. Active since October 2021, the group primarily uses ransomware and wiper malware for ideological disruption rather than financial gain. The group has targeted sectors such as government, defense, and corporate entities like Alibaba, Sberbank, and Gazprom.

Goals & Targeting

AgainstTheWest seeks to achieve organizational disruption through the deployment of ransomware and wiper malware, targeting primarily government and defense sectors in China (CN) for ideological reasons. The group's focus on high-profile targets suggests an aim to maximize impact and attention. Typical victims include large corporations and critical infrastructure organizations perceived as authoritarian or politically significant.

Enhanced Description

AgainstTheWest (ATW) is a cyber threat actor known for its hacktivist activities, operational since October 2021. The group primarily targets governments, defense organizations, and corporations perceived as authoritarian or politically significant. ATW has gained notoriety for its use of custom ransomware and wiper malware to disrupt operations and spread ideological messages. Unlike traditional criminal actors, ATW's primary motivation appears to be organizational disruption rather than financial gain. The group's victims have included high-profile entities such as Alibaba, Sberbank, and Gazprom, indicating a focus on large-scale disruption. ATW's activities are often linked to state-sponsored or politically motivated hacktivism, with ties to Chinese-speaking actors.

Key Capabilities

  • Custom ransomware
  • Wiper malware
  • Spear-phishing campaigns
  • Social engineering

Software / Tooling

Custom ransomware
Wiper malware

Campaigns & Victims

AgainstTheWest's campaign patterns involve targeting large corporations and government entities with a focus on China. The group's operational tempo is consistent, often launching campaigns against high-profile targets to achieve maximum disruption. Notable operations include attacks on Alibaba, Sberbank, and Gazprom. Campaigns are typically characterized by the deployment of custom ransomware and wiper malware, designed to cause significant downtime and disruption.

IOC Patterns

  • Spear-phishing with malicious links or attachments
  • Ransomware deployment with specific filename patterns
  • Wiper malware activity leading to data deletion

Recommended Actions

  • Enhance email filtering and phishing detection capabilities
  • Implement endpoint detection and response (EDR) solutions
  • Monitor for unusual file activities and process behavior
  • Conduct regular cybersecurity awareness training

Suggested Tags

Hacktivism
Ransomware
Wiper malware
Critical infrastructure

Confidence Assessment

Confidence in the data is moderate due to limited availability of detailed TTPs and IOCs. The primary source of information is the group's own behavior and publicly reported incidents, which may not fully capture the breadth of their capabilities.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Government Targeting
Hacktivism
Wiper / Destructive
Wiper malware
Critical infrastructure

Details

MITRE ID
APT4
Type
Criminal
Sophistication
Medium
Resource Level
Government
Primary Motivation
Organizational gain
Country of Origin
China (CN)
Confidence
80%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.