APT18
Also known as: TG-0416 · Dynamite Panda · Threat Group-0416
Overview
APT18 is a threat group that has operated since at least 2009 and has targeted a range of industries, including technology, manufacturing, human rights groups, government, and medical.
Naming & attribution
APT18 is tracked under 4 names across the industry. It uses 12 documented ATT&CK techniques — more than 35% of the 174 groups tracked here. Activity attributed since at least 2009.
| Name | First reported by |
|---|---|
| TG-0416 | Shelmire, A. |
| Dynamite Panda | Shelmire, A. |
| Threat Group-0416 | Shelmire, A. |
| APT18 | Shelmire, A. |
Distinctive techniques
Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.
-
T1053.002At — used by 3 of 174 groups
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- Metador — 5 shared techniques (31% overlap)
- Dark Caracal — 5 shared techniques (26% overlap)
- Play — 7 shared techniques (23% overlap)
- Tropic Trooper China — 9 shared techniques (21% overlap)
- FIN10 — 4 shared techniques (21% overlap)
- Darkhotel South Korea — 6 shared techniques (20% overlap)
Targets
Aerospace · Civil society · Defense · Government · Healthcare · High-Tech · Private sector · Telecommunications
Regions
United States
Capabilities
- Custom malware/implant development — ATT&CK: 4 attributed custom malware families
TTPs — 12 techniques across 5 tactics
Execution
-
T1053.002At -
T1059.003Windows Command Shell
Persistence
-
T1133External Remote Services -
T1547.001Registry Run Keys / Startup Folder
Stealth
-
T1027.013Encrypted/Encoded File -
T1070.004File Deletion -
T1078Valid Accounts
Discovery
Command and Control
-
T1071.001Web Protocols -
T1071.004DNS -
T1105Ingress Tool Transfer
Tools & malware (5)
hcdLoader · gh0st RAT · cmd · Pisloader · HTTPBrowser