Also known as: Codoso, C0d0so0, Codoso Team, Sunshop Group, APT19, DEEP PANDA, WebMasters, KungFu Kittens, Black Vine, TEMP.Avengers, Group 13, PinkPanther, Shell Crew, BRONZE FIRESTONE, G0009, G0073, Pupa, Checkered Typhoon, Hurricane Panda, APT31, Zirconium, JUDGMENT PANDA, BRONZE VINEWOOD, Red keres, Violet Typhoon, TA412
APT19 is a Chinese-based threat group that has targeted a variety of industries, including defense, finance, energy, pharmaceutical, telecommunications, high tech, education, manufacturing, and legal services. In 2017, a phishing campaign was used to target seven law and investment firms. (Citation: FireEye APT19) Some analysts track APT19 and Deep Panda as the same group, but it is unclear from open source information if the groups are the same. (Citation: ICIT China's Espionage Jul 2016) (Citation: FireEye APT Groups) (Citation: Unit 42 C0d0so0 Jan 2016)
Bassos Campaign; Watering Hole DLL Side-Loading: fakerx86.exe → dbgeng.dll (Microsoft)
Targeted Sectors
Targeted Countries / Regions
Executive Summary
APT19 is a Chinese-based threat group that has targeted various industries, including defense, finance, and energy, primarily for espionage purposes. The group has been active in phishing campaigns and has utilized techniques such as DLL side-loading and spear-phishing with malicious attachments. APT19's activities pose a significant threat to organizations in targeted sectors.
Goals & Targeting
APT19's strategic objectives are primarily focused on espionage, with the group targeting various industries and sectors to gather sensitive information. The group's targeting profile suggests that it is interested in acquiring information related to national security, finance, technology, and other sensitive areas. APT19's typical victims include government agencies, defense contractors, financial institutions, and other organizations with access to sensitive information.
Enhanced Description
The group's targeting of various industries and sectors suggests that APT19 is a versatile and adaptable threat actor, capable of adjusting its TTPs to suit specific goals and objectives. The use of phishing and watering hole attacks indicates that the group is skilled in social engineering and exploit development. APT19's activities pose a significant threat to organizations in targeted sectors, particularly those with sensitive information or intellectual property.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
APT19's campaign patterns suggest that the group is a persistent and adaptable threat actor, capable of adjusting its TTPs to suit specific goals and objectives. The group's use of phishing and watering hole attacks indicates that it is skilled in social engineering and exploit development. APT19's campaigns have been observed to involve the use of legitimate software, such as Cobalt Strike and Empire, to establish C2 channels and execute malicious payloads. The group's targeting of various industries and sectors suggests that it is a versatile threat actor, capable of adjusting its TTPs to suit specific goals and objectives.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in the available data is moderate, as some information is based on open-source reports and may not be comprehensive or up-to-date. There are gaps in information regarding APT19's exact motivations, goals, and targeting profile, as well as the group's current TTPs and capabilities. Further research and analysis are necessary to fill these gaps and provide a more accurate understanding of the threat posed by APT19.
No observed data linked yet.
No IOCs linked yet.
22
Techniques
7
Tools
3
Campaigns
0
IOCs
0
Observed Data
9
Tactics