Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: Codoso, C0d0so0, Codoso Team, Sunshop Group, APT19, DEEP PANDA, WebMasters, KungFu Kittens, Black Vine, TEMP.Avengers, Group 13, PinkPanther, Shell Crew, BRONZE FIRESTONE, G0009, G0073, Pupa, Checkered Typhoon, Hurricane Panda, APT31, Zirconium, JUDGMENT PANDA, BRONZE VINEWOOD, Red keres, Violet Typhoon, TA412

Description

APT19 is a Chinese-based threat group that has targeted a variety of industries, including defense, finance, energy, pharmaceutical, telecommunications, high tech, education, manufacturing, and legal services. In 2017, a phishing campaign was used to target seven law and investment firms. (Citation: FireEye APT19) Some analysts track APT19 and Deep Panda as the same group, but it is unclear from open source information if the groups are the same. (Citation: ICIT China's Espionage Jul 2016) (Citation: FireEye APT Groups) (Citation: Unit 42 C0d0so0 Jan 2016)

TTP Summary

Bassos Campaign; Watering Hole DLL Side-Loading: fakerx86.exe → dbgeng.dll (Microsoft)

Goals & Targeting

Targeted Sectors

Government
Defense
Energy
Financial services
Think tank
Healthcare
Technology
Aerospace & defense
Manufacturing

Targeted Countries / Regions

US
FR
GB
KR
JP
IN

AI Analysis

· 2 months ago

Executive Summary

APT19 is a Chinese-based threat group that has targeted various industries, including defense, finance, and energy, primarily for espionage purposes. The group has been active in phishing campaigns and has utilized techniques such as DLL side-loading and spear-phishing with malicious attachments. APT19's activities pose a significant threat to organizations in targeted sectors.

Goals & Targeting

APT19's strategic objectives are primarily focused on espionage, with the group targeting various industries and sectors to gather sensitive information. The group's targeting profile suggests that it is interested in acquiring information related to national security, finance, technology, and other sensitive areas. APT19's typical victims include government agencies, defense contractors, financial institutions, and other organizations with access to sensitive information.

Enhanced Description

The group's targeting of various industries and sectors suggests that APT19 is a versatile and adaptable threat actor, capable of adjusting its TTPs to suit specific goals and objectives. The use of phishing and watering hole attacks indicates that the group is skilled in social engineering and exploit development. APT19's activities pose a significant threat to organizations in targeted sectors, particularly those with sensitive information or intellectual property.

Key Capabilities

  • Phishing and social engineering
  • DLL side-loading and other evasion techniques
  • Command and control (C2) channel establishment
  • Malware development and deployment
  • Network exploitation and reconnaissance

MITRE ATT&CK Tactics

Reconnaissance
Resource Development
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Exfiltration

ATT&CK Techniques

T1132.001: Standard Encoding
T1204.002: Malicious File
T1574.001: DLL
T1112: Modify Registry
T1059.001: PowerShell
T1588.002: Tool
T1027.010: Command Obfuscation
T1071.001: Web Protocols
T1033: System Owner/User Discovery
T1218.011: Rundll32
T1027.013: Encrypted/Encoded File
T1543.003: Windows Service
T1566.001: Spearphishing Attachment
T1082: System Information Discovery
T1140: Deobfuscate/Decode Files or Information

Software / Tooling

Cobalt Strike
Empire
UNICAT
Phishing kits

Campaigns & Victims

APT19's campaign patterns suggest that the group is a persistent and adaptable threat actor, capable of adjusting its TTPs to suit specific goals and objectives. The group's use of phishing and watering hole attacks indicates that it is skilled in social engineering and exploit development. APT19's campaigns have been observed to involve the use of legitimate software, such as Cobalt Strike and Empire, to establish C2 channels and execute malicious payloads. The group's targeting of various industries and sectors suggests that it is a versatile threat actor, capable of adjusting its TTPs to suit specific goals and objectives.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 over DNS using fast-flux
  • Staging infrastructure on bulletproof hosting
  • DLL side-loading with malicious executables

Recommended Actions

  • Implement robust email security controls, including spam filtering and anti-phishing measures
  • Conduct regular security awareness training for employees
  • Use strong passwords and enable multi-factor authentication
  • Implement a robust incident response plan
  • Regularly update and patch software and operating systems

Suggested Tags

APT
Chinese threat actors
Espionage
Phishing
DLL side-loading

Confidence Assessment

The confidence level in the available data is moderate, as some information is based on open-source reports and may not be comprehensive or up-to-date. There are gaps in information regarding APT19's exact motivations, goals, and targeting profile, as well as the group's current TTPs and capabilities. Further research and analysis are necessary to fill these gaps and provide a more accurate understanding of the threat posed by APT19.

ATT&CK Techniques

Stealth
7 techniques

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. FireEye APT19 — Ahl, I. (2017, June 06). Privileges and Credentials: Phished at the Request of Counsel. Retrieved May 17, 2018.
  2. Dark Reading Codoso Feb 2015 — Chickowski, E. (2015, February 10). Chinese Hacking Group Codoso Team Uses Forbes.com As Watering Hole. Retrieved September 13, 2018.
  3. FireEye APT Groups — FireEye. (n.d.). Advanced Persistent Threat Groups. Retrieved August 3, 2018.
  4. Unit 42 C0d0so0 Jan 2016 — Grunzweig, J., Lee, B. (2016, January 22). New Attacks Linked to C0d0so0 Group. Retrieved August 2, 2018.
  5. ICIT China's Espionage Jul 2016 — Scott, J. and Spaniel, D. (2016, July 28). ICIT Brief - China’s Espionage Dynasty: Economic Death by a Thousand Cuts. Retrieved June 7, 2018.

Intel Summary

22

Techniques

7

Tools

3

Campaigns

0

IOCs

0

Observed Data

9

Tactics

Tags

APT
Healthcare Targeting
Phishing
Chinese threat actors
Espionage
DLL side-loading

Details

MITRE ID
G0073
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--fe8796a4-2a02-41a0-9d27-7aa1e995feb6
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.