NEW: Group Profiler — instant APT intel lookup. Try it →

APT18

G0026 China Espionage MITRE ATT&CK →

Also known as: TG-0416 · Dynamite Panda · Threat Group-0416

Overview

APT18 is a threat group that has operated since at least 2009 and has targeted a range of industries, including technology, manufacturing, human rights groups, government, and medical.

Naming & attribution

APT18 is tracked under 4 names across the industry. It uses 12 documented ATT&CK techniques — more than 35% of the 174 groups tracked here. Activity attributed since at least 2009.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
TG-0416Shelmire, A.
Dynamite PandaShelmire, A.
Threat Group-0416Shelmire, A.
APT18Shelmire, A.

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1053.002 At — used by 3 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Metador — 5 shared techniques (31% overlap)
  • Dark Caracal — 5 shared techniques (26% overlap)
  • Play — 7 shared techniques (23% overlap)
  • Tropic Trooper China — 9 shared techniques (21% overlap)
  • FIN10 — 4 shared techniques (21% overlap)
  • Darkhotel South Korea — 6 shared techniques (20% overlap)

Targets

Aerospace · Civil society · Defense · Government · Healthcare · High-Tech · Private sector · Telecommunications

Regions

United States

Capabilities

  • Custom malware/implant development — ATT&CK: 4 attributed custom malware families

TTPs — 12 techniques across 5 tactics

Execution

Stealth

Command and Control

Tools & malware (5)

hcdLoader · gh0st RAT · cmd · Pisloader · HTTPBrowser

Reporting (3)