Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Elderwood

Also known as: Elderwood Gang, Beijing Group, Sneaky Panda, Hydraq, SIG22, Elderwood, G0066, tracked as

Description

Emerging in the late 2000s from the Chinese intelligence community, Elderwood first made headlines through Operation Aurora in 2009 when it leveraged an unpatched Microsoft Internet Explorer zero‑day (CVE‑2010–0187) to compromise Google’s infrastructure and exfiltrate highly sensitive data. The group’s methodology has evolved but remains rooted in advanced exploitation techniques: it uses zero‑days such as CVE‑2013‑3893 during the DeputyDog campaign, injects malicious code into public web pages for watering‑hole attacks, and carries out supply‑chain compromises like the Ccleaner 5.33 incident that distributed malware through legitimate software installers. Once inside a target network, Elderwood deploys its custom backdoor Trojans – notably Ritsol and Hydraq – that incorporate encrypted payloads, registry run keys, Windows services, and VNC modules for remote control. These utilities not only achieve persistence via autostart execution but also gather system information, harvest credentials, manipulate access tokens, perform screen capture, clear event logs, and exfiltrate data over encrypted HTTPS or alternative channels. Throughout its history, Elderwood has demonstrated operational finesse: it maintains low‑profile presence for months, scales operations with shared infrastructure, continuously refactors obfuscation techniques such as bitwise NOT/XOR, and adapts to defensive countermeasures by employing newer variants and exploiting new zero‑days.

TTP Summary

Aurora

Goals & Targeting

Targeted Sectors

Defense
Energy
Financial services
Critical infrastructure
Ngo
Non profit
Government
Manufacturing
Financial services
Media
Education
Mining
Chemical
Think tank

Targeted Countries / Regions

CN
IL
JP
US
RU
KP
IN

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 1 day ago

Executive Summary

Elderwood is a state‑sponsored Chinese actor notorious for exploiting zero‑day vulnerabilities, watering hole injections, and spear‑phishing campaigns to infiltrate defense, energy, finance, and NGO sectors worldwide. Its operations frequently employ custom backdoors such as Ritsol and Hydraq that provide stealthy persistence and remote desktop capabilities. Elderwood’s blend of technical sophistication and broad targeting profile makes it a persistent threat to critical infrastructure and foreign analysts alike.

Goals & Targeting

Elderwood’s overarching goal is state intelligence collection focused on defense, energy, finance, and critical infrastructure across a geographic range that includes China, Iran, Japan, the United States, Russia, North Korea, and India. While financial gain appears as a secondary motivation in public reports, the primary objective aligns with national intelligence agencies to acquire strategic information and disrupt adversary capabilities. The actor targets high‑value assets—government agencies, NGOs, think tanks, and private sector entities—to gain footholds for long‑term espionage operations.

Enhanced Description

Key Capabilities

  • Zero-day exploitation for initial access
  • Spearphishing attachments or links
  • Watering hole attacks via web page code injection
  • Drive-by site compromise
  • Supply-chain attacks using legitimate installers
  • Persistent installation through registry run keys, startup folders, and Windows services
  • Encrypted payloads and C2 traffic (bitwise NOT/XOR)
  • Remote token privilege manipulation / privilege escalation
  • File read/write/delete with event log clearing
  • System information discovery (hardware/software/network)
  • Process discovery/monitoring
  • VNC-based remote desktop streaming

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Defense Evasion
Exfiltration
Privilege Escalation
Discovery

ATT&CK Techniques

T1105
T1027
T1566
T1204
T1190
T1189
T1134
T1543
T1005
T1685
T1573
T1048
T1083
T1070
T1112
T1057
T1012
T1113
T1129
T1082
T1016
T1007
T1569

Software / Tooling

Ritsol Backdoor
Hydraq Trojan
Roarur
MdmBot
HomeUnix
Homux
McRat
9002 RAT

Campaigns & Victims

Since 2009, Elderwood has operated through a series of themed campaigns such as Operation Aurora (2009), DeputyDog (2013) and the more recent Hydraq/Operation Ephemeral Hydra variants. Its operational tempo is adaptive: periods of rapid lateral movement followed by long‑term low‑profile persistence. Victim profiles remain consistent—defense contractors, energy utilities, financial institutions, NGOs, universities, think tanks—and across multiple geographies including CN, IL, JP, US, RU, KP, and IN. Notable incidents include the exploitation of Microsoft's IE vulnerability against Google, supply-chain attacks via Ccleaner 5.33 that leveraged Avast download servers, and Game of Thrones‑style phishing lures targeting IT service providers. Elderwood’s tactics mirror broad Chinese APT operational models: use of high-privilege zero-days, watering holes, sophisticated post‑exploitation toolsets, and encrypted, low-altitude C2 channels to maintain persistence and exfiltrate sensitive data over extended periods.

IOC Patterns

  • Zero-day exploits
  • Spearphishing attachments and links
  • Watering hole web-page injections
  • Supply‑chain compromise via legitimate installers
  • Encrypted payloads and C2 traffic
  • Persistence through Windows services/run keys
  • Registry modification and event log clearing
  • Process monitoring instrumentation
  • Remote desktop via VNC
  • Credential theft and token manipulation

Recommended Actions

  • Apply security patches immediately for all exposed vulnerabilities, particularly in legacy browsers such as Internet Explorer. Implement advanced email filtering and user training to detect spearphishing attachments and malicious links. Monitor outbound web traffic for signs of code injection or watering hole behavior; block known compromised domains. Deploy endpoint detection & response (EDR) solutions capable of identifying unauthorized registry run keys, startup folder entries, and newly created Windows services. Enforce application whitelisting and continuous monitoring of registry changes related to service creation. Harden privilege escalation pathways and enforce least‑privilege principles. Analyze network traffic for encrypted or obfuscated malware communications; block HTTPS connections to domains that have been linked to Hydraq or related C2 infrastructure. Employ forensic tools to detect and remove event log clearing, file tampering, and other indicators of compromise.

Suggested Tags

Elderwood
APT17
Chinese State‑Sponsored
Zero‑Day Exploit
Watering Hole Attack
Spearphishing
Supply‑Chain Attack
Web Intrusion
Targeting NGOs
Defense Organizations
HydraQ
Operation Aurora
Trojan-Hydraq
Privilege Escalation
Persistence via Service
Data Exfiltration
C2 Over HTTPS
VNC Remote Desktop
Registry Manipulation
Command and Control

Confidence Assessment

The available intelligence is drawn from multiple reputable sources, including vendor analyses (FireEye, Proofpoint), academic reports, and the MITRE ATT&CK framework. These indicate an established attribution to a Chinese state-sponsored entity operating through a dedicated adversary group. However, certain claims—such as precise motivations beyond espionage or specific deployment dates—are inferred rather than directly corroborated. The depth of IOC evidence is moderate; additional observable indicators (e.g., real‑time threat telemetry) would strengthen confidence in ongoing activity assessments.

ATT&CK Techniques

Initial Access
5 techniques

Software / Tooling

Campaigns / Victims

Active

Aurora

TLP:CLEAR

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 10 Domain 10

References

  1. CSM Elderwood Sept 2012 — Clayton, M.. (2012, September 14). Stealing US business secrets: Experts ID two huge cyber 'gangs' in China. Retrieved February 15, 2018.
  2. Symantec Elderwood Sept 2012 — O'Gorman, G., and McDonald, G.. (2012, September 6). The Elderwood Project. Retrieved November 17, 2024.
  3. Security Affairs Elderwood Sept 2012 — Paganini, P. (2012, September 9). Elderwood project, who is behind Op. Aurora and ongoing attacks?. Retrieved February 13, 2018.
  4. attack.mitre.org — Cited by web research for: T1105
  5. docs.rapid7.com — Cited by web research for: T1583
  6. attack.mitre.org — Cited by web research for: T1134
  7. learn.microsoft.com — Cited by web research for: Tsunami
  8. apt.etda.or.th — Cited by web research for: DeputyDog
  9. https://apt.etda.or.th/cgi-bin/showcard.cgi?g=APT%2017,%20Deputy%20Dog,%20Elderwood,%20Sneaky%20Panda — Cited by AI analysis.
  10. https://en.wikipedia.org/wiki/Operation_Aurora — Cited by AI analysis.
  11. https://googleblog.blogspot.com/2010/01/new-approach-to-china.html — Cited by AI analysis.
  12. https://www.theregister.co.uk/2010/11/11/amnesty_international_hosts_ie_exploit/ — Cited by AI analysis.
  13. https://www.theregister.co.uk/2012/05/11/amnesty_malware_rat/ — Cited by AI analysis.
  14. https://www.fireeye.com/blog/threat-research/2013/09/operation-deputydog-zero-day-cve-2013-3893-attack-against-japanese-targets.html — Cited by AI analysis.
  15. https://www.fireeye.com/blog/threat-research/2013/11/operation-ephemeral-hydra-ie-zero-day-linked-to-deputydog-uses-diskless-method.html — Cited by AI analysis.
  16. https://www.proofpoint.com/us/threat-insight/post/operation-rat-cook-chinese-apt-actors-use-fake-game-thrones-leaks-lures — Cited by AI analysis.
  17. https://blog.talosintelligence.com/2017/09/avast-distributes-malware.html — Cited by AI analysis.
  18. https://www.tgsoft.it/news/news_archivio.asp?id=1557&lang=eng — Cited by AI analysis.
  19. http://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/the-elderwood-project.pdf — Cited by AI analysis.
  20. https://intrusiontruth.wordpress.com/2019/07/24/apt17-is-run-by-the-jinan-bureau-of-the-chinese-ministry-of-state-security/ — Cited by AI analysis.
  21. https://intezer.com/evidence-aurora-operation-still-active-supply-chain-attack-through-ccleaner/ — Cited by AI analysis.
  22. https://intezer.com/evidence-aurora-operation-still-active-part-2-more-ties-uncovered-between-ccleaner-hack-chinese-hackers-2/ — Cited by AI analysis.
  23. https://attack.mitre.org/groups/G0025/ — Cited by AI analysis.

Intel Summary

39

Techniques

57

Tools

1

Campaigns

38

IOCs

0

Observed Data

10

Tactics

Tags

APT
Supply Chain Attack
Government Targeting
APT-17
Elderwood Group
Operation Aurora
Zero-Day Exploit
Watering Hole Attack
Spearphishing
Backdoor Trojan
Deputy_Dog
Ephemeral_Hydra
RAT_Cook
Ccleaner Supply Chain Attack
Chinese State-sponsored
Hydraq
Data-Theft Trojan
Service Persistence
XOR Encryption
Event Log Clearing
File Deletion
Token Privilege Modification
VNC Remote Desktop
China‑Based Actor
Elderwood
APT17
Chinese State‑Sponsored
Zero‑Day Exploit
Supply‑Chain Attack
Web Intrusion
Targeting NGOs
Defense Organizations
HydraQ
Trojan-Hydraq
Privilege Escalation
Persistence via Service
Data Exfiltration
C2 Over HTTPS
Registry Manipulation
Command and Control

Details

MITRE ID
G0066
Type
Unknown
Resource Level
Government
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--03506554-5f37-4f8f-9ce4-0e9f01a1b484
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.