NEW: Group Profiler — instant APT intel lookup. Try it →

APT17

G0025 China Espionage MITRE ATT&CK →

Also known as: Deputy Dog

Overview

APT17 is a China-based threat group that has conducted network intrusions against U.S. government entities, the defense industry, law firms, information technology companies, mining companies, and non-government organizations.

Naming & attribution

APT17 is tracked under 2 names across the industry. It uses 2 documented ATT&CK techniques — more than 5% of the 174 groups tracked here.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
Deputy DogFireEye Labs/FireEye Threat Intelligence
APT17FireEye Labs/FireEye Threat Intelligence

Targets

Civil society · Defense · Government · Intelligence · Justice · Mining · Private sector · Technology

Regions

Belgium · China · Germany · Indonesia · Italy · Japan · Netherlands · Russia · Switzerland · United Kingdom · United States

TTPs — 2 techniques across 1 tactics

Resource Development

Tools & malware (1)

BLACKCOFFEE

Reporting (1)