Axiom
Also known as: Group 72
Overview
Axiom is a suspected Chinese cyber espionage group that has targeted the aerospace, defense, government, manufacturing, and media sectors since at least 2008. Some reporting suggests a degree of overlap between Axiom and Winnti Group but the two groups appear to be distinct based on differences in reporting on TTPs and targeting.
Naming & attribution
Axiom is tracked under 2 names across the industry. It uses 16 documented ATT&CK techniques — more than 45% of the 174 groups tracked here. Activity attributed since at least 2008.
| Name | First reported by |
|---|---|
| Group 72 | Esler, J., Lee, M., and Williams, C |
| Axiom | Novetta |
Distinctive techniques
Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.
-
T1001.002Steganography — used by 1 of 174 groups -
T1553Subvert Trust Controls — used by 1 of 174 groups -
T1563.002RDP Hijacking — used by 1 of 174 groups -
T1583.002DNS Server — used by 3 of 174 groups
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- Sea Turtle — 6 shared techniques (16% overlap)
- Dragonfly Russia — 8 shared techniques (13% overlap)
- Leviathan China — 7 shared techniques (12% overlap)
- Andariel North Korea — 3 shared techniques (12% overlap)
- Ember Bear Russia — 6 shared techniques (11% overlap)
- INC Ransom — 4 shared techniques (11% overlap)
Targets
Civil society · Defense · Government · Intelligence · Justice · Mining · Private sector · Technology
Regions
Belgium · China · Germany · Indonesia · Italy · Japan · Netherlands · Russia · Switzerland · United Kingdom · United States
Capabilities
- Exploitation of public-facing / client applications — ATT&CK T1190, T1203
- Custom malware/implant development — ATT&CK: 8 attributed custom malware families
TTPs — 16 techniques across 10 tactics
Resource Development
-
T1583.002DNS Server -
T1583.003Virtual Private Server -
T1584.005Botnet
Initial Access
-
T1189Drive-by Compromise -
T1190Exploit Public-Facing Application -
T1566Phishing
Execution
Privilege Escalation
-
T1546.008Accessibility Features
Stealth
-
T1078Valid Accounts
Defense Impairment
-
T1553Subvert Trust Controls
Credential Access
-
T1003OS Credential Dumping
Lateral Movement
-
T1021.001Remote Desktop Protocol -
T1563.002RDP Hijacking
Collection
-
T1005Data from Local System -
T1560Archive Collected Data
Command and Control
-
T1001.002Steganography
Tools & malware (8)
ZxShell · gh0st RAT · Zox · PlugX · Hikit · PoisonIvy · Derusbi · Hydraq
Reporting (3)
- Games are over: Winnti is now targeting pharmaceutical companies — Tarakanov, D
- Winnti Analysis — Novetta Threat Research Group
- Threat Spotlight: Group 72 — Esler, J., Lee, M., and Williams, C