Also known as: Elderwood Gang, Beijing Group, Sneaky Panda, Hydraq, SIG22, Elderwood, G0066, tracked as
Emerging in the late 2000s from the Chinese intelligence community, Elderwood first made headlines through Operation Aurora in 2009 when it leveraged an unpatched Microsoft Internet Explorer zero‑day (CVE‑2010–0187) to compromise Google’s infrastructure and exfiltrate highly sensitive data. The group’s methodology has evolved but remains rooted in advanced exploitation techniques: it uses zero‑days such as CVE‑2013‑3893 during the DeputyDog campaign, injects malicious code into public web pages for watering‑hole attacks, and carries out supply‑chain compromises like the Ccleaner 5.33 incident that distributed malware through legitimate software installers. Once inside a target network, Elderwood deploys its custom backdoor Trojans – notably Ritsol and Hydraq – that incorporate encrypted payloads, registry run keys, Windows services, and VNC modules for remote control. These utilities not only achieve persistence via autostart execution but also gather system information, harvest credentials, manipulate access tokens, perform screen capture, clear event logs, and exfiltrate data over encrypted HTTPS or alternative channels. Throughout its history, Elderwood has demonstrated operational finesse: it maintains low‑profile presence for months, scales operations with shared infrastructure, continuously refactors obfuscation techniques such as bitwise NOT/XOR, and adapts to defensive countermeasures by employing newer variants and exploiting new zero‑days.
Aurora
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Elderwood is a state‑sponsored Chinese actor notorious for exploiting zero‑day vulnerabilities, watering hole injections, and spear‑phishing campaigns to infiltrate defense, energy, finance, and NGO sectors worldwide. Its operations frequently employ custom backdoors such as Ritsol and Hydraq that provide stealthy persistence and remote desktop capabilities. Elderwood’s blend of technical sophistication and broad targeting profile makes it a persistent threat to critical infrastructure and foreign analysts alike.
Goals & Targeting
Elderwood’s overarching goal is state intelligence collection focused on defense, energy, finance, and critical infrastructure across a geographic range that includes China, Iran, Japan, the United States, Russia, North Korea, and India. While financial gain appears as a secondary motivation in public reports, the primary objective aligns with national intelligence agencies to acquire strategic information and disrupt adversary capabilities. The actor targets high‑value assets—government agencies, NGOs, think tanks, and private sector entities—to gain footholds for long‑term espionage operations.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Since 2009, Elderwood has operated through a series of themed campaigns such as Operation Aurora (2009), DeputyDog (2013) and the more recent Hydraq/Operation Ephemeral Hydra variants. Its operational tempo is adaptive: periods of rapid lateral movement followed by long‑term low‑profile persistence. Victim profiles remain consistent—defense contractors, energy utilities, financial institutions, NGOs, universities, think tanks—and across multiple geographies including CN, IL, JP, US, RU, KP, and IN. Notable incidents include the exploitation of Microsoft's IE vulnerability against Google, supply-chain attacks via Ccleaner 5.33 that leveraged Avast download servers, and Game of Thrones‑style phishing lures targeting IT service providers. Elderwood’s tactics mirror broad Chinese APT operational models: use of high-privilege zero-days, watering holes, sophisticated post‑exploitation toolsets, and encrypted, low-altitude C2 channels to maintain persistence and exfiltrate sensitive data over extended periods.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available intelligence is drawn from multiple reputable sources, including vendor analyses (FireEye, Proofpoint), academic reports, and the MITRE ATT&CK framework. These indicate an established attribution to a Chinese state-sponsored entity operating through a dedicated adversary group. However, certain claims—such as precise motivations beyond espionage or specific deployment dates—are inferred rather than directly corroborated. The depth of IOC evidence is moderate; additional observable indicators (e.g., real‑time threat telemetry) would strengthen confidence in ongoing activity assessments.
Aurora
No observed data linked yet.
39
Techniques
57
Tools
1
Campaigns
38
IOCs
0
Observed Data
10
Tactics