NEW: Group Profiler — instant APT intel lookup. Try it →

← threatfilter.dev / all groups / APT19

APT19

G0073 China Espionage MITRE ATT&CK →

Also known as: Codoso · C0d0so0 · Codoso Team · Sunshop Group

Overview

APT19 is a Chinese-based threat group that has targeted a variety of industries, including defense, finance, energy, pharmaceutical, telecommunications, high tech, education, manufacturing, and legal services. In 2017, a phishing campaign was used to target seven law and investment firms. Some analysts track APT19 and Deep Panda as the same group, but it is unclear from open source information if the groups are the same.

Targets

Finance · Military · Non-profit Organisation · Private sector · Technology

Regions

United States

TTPs — 21 techniques across 8 tactics

Resource Development

Initial Access

Execution

Persistence

Stealth

Defense Impairment

Command and Control

Tools & malware (2)

Cobalt Strike · Empire

Reporting (3)