NEW: Group Profiler — instant APT intel lookup. Try it →

← threatfilter.dev / all groups / Axiom

Axiom

G0001 China Espionage MITRE ATT&CK →

Also known as: Group 72

Overview

Axiom is a suspected Chinese cyber espionage group that has targeted the aerospace, defense, government, manufacturing, and media sectors since at least 2008. Some reporting suggests a degree of overlap between Axiom and Winnti Group but the two groups appear to be distinct based on differences in reporting on TTPs and targeting.

Targets

Civil society · Defense · Government · Intelligence · Justice · Mining · Private sector · Technology

Regions

Belgium · China · Germany · Indonesia · Italy · Japan · Netherlands · Russia · Switzerland · United Kingdom · United States

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1190, T1203
  • Custom malware/implant development — ATT&CK: 8 attributed custom malware families

TTPs — 16 techniques across 10 tactics

Resource Development

Privilege Escalation

Stealth

Defense Impairment

Credential Access

Lateral Movement

Command and Control

Tools & malware (8)

ZxShell · gh0st RAT · Zox · PlugX · Hikit · PoisonIvy · Derusbi · Hydraq

Reporting (3)