NEW: Group Profiler — instant APT intel lookup. Try it →

APT12

G0005 China Espionage MITRE ATT&CK →

Also known as: IXESHE · DynCalc · Numbered Panda · DNSCALC

Overview

APT12 is a threat group that has been attributed to China. The group has targeted a variety of victims including but not limited to media outlets, high-tech companies, and multiple governments.

Naming & attribution

APT12 is tracked under 5 names across the industry. It uses 5 documented ATT&CK techniques — more than 13% of the 174 groups tracked here.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
IXESHEMeyers, A
DynCalcMeyers, A
Numbered PandaMeyers, A
DNSCALCMoran, N., Oppenheim, M., Engle, S., & Wartell, R.
APT12Meyers, A

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1568.003 DNS Calculation — used by 1 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • TA459 China — 3 shared techniques (43% overlap)
  • The White Company — 3 shared techniques (33% overlap)
  • Elderwood China — 3 shared techniques (27% overlap)
  • admin@338 China — 3 shared techniques (21% overlap)
  • Andariel North Korea — 3 shared techniques (21% overlap)
  • BlackTech China — 3 shared techniques (19% overlap)

Targets

Government · Private sector

Regions

Japan · Taiwan

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1203

TTPs — 5 techniques across 3 tactics

Initial Access

Command and Control

Tools & malware (3)

Ixeshe · RIPTIDE · HTRAN

Reporting (2)