← threatfilter.dev / all groups / APT18
APT18
Also known as: TG-0416 · Dynamite Panda · Threat Group-0416
Overview
APT18 is a threat group that has operated since at least 2009 and has targeted a range of industries, including technology, manufacturing, human rights groups, government, and medical.
Targets
Aerospace · Civil society · Defense · Government · Healthcare · High-Tech · Private sector · Telecommunications
Regions
United States
Capabilities
- Custom malware/implant development — ATT&CK: 4 attributed custom malware families
TTPs — 12 techniques across 5 tactics
Execution
-
T1053.002At -
T1059.003Windows Command Shell
Persistence
-
T1133External Remote Services -
T1547.001Registry Run Keys / Startup Folder
Stealth
-
T1027.013Encrypted/Encoded File -
T1070.004File Deletion -
T1078Valid Accounts
Discovery
Command and Control
-
T1071.001Web Protocols -
T1071.004DNS -
T1105Ingress Tool Transfer
Tools & malware (5)
hcdLoader · gh0st RAT · cmd · Pisloader · HTTPBrowser