NEW: Group Profiler — instant APT intel lookup. Try it →

Axiom

G0001 China Espionage MITRE ATT&CK →

Also known as: Group 72

Overview

Axiom is a suspected Chinese cyber espionage group that has targeted the aerospace, defense, government, manufacturing, and media sectors since at least 2008. Some reporting suggests a degree of overlap between Axiom and Winnti Group but the two groups appear to be distinct based on differences in reporting on TTPs and targeting.

Naming & attribution

Axiom is tracked under 2 names across the industry. It uses 16 documented ATT&CK techniques — more than 45% of the 174 groups tracked here. Activity attributed since at least 2008.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
Group 72Esler, J., Lee, M., and Williams, C
AxiomNovetta

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1001.002 Steganography — used by 1 of 174 groups
  • T1553 Subvert Trust Controls — used by 1 of 174 groups
  • T1563.002 RDP Hijacking — used by 1 of 174 groups
  • T1583.002 DNS Server — used by 3 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Sea Turtle — 6 shared techniques (16% overlap)
  • Dragonfly Russia — 8 shared techniques (13% overlap)
  • Leviathan China — 7 shared techniques (12% overlap)
  • Andariel North Korea — 3 shared techniques (12% overlap)
  • Ember Bear Russia — 6 shared techniques (11% overlap)
  • INC Ransom — 4 shared techniques (11% overlap)

Targets

Civil society · Defense · Government · Intelligence · Justice · Mining · Private sector · Technology

Regions

Belgium · China · Germany · Indonesia · Italy · Japan · Netherlands · Russia · Switzerland · United Kingdom · United States

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1190, T1203
  • Custom malware/implant development — ATT&CK: 8 attributed custom malware families

TTPs — 16 techniques across 10 tactics

Resource Development

Privilege Escalation

Stealth

Defense Impairment

Credential Access

Lateral Movement

Command and Control

Tools & malware (8)

ZxShell · gh0st RAT · Zox · PlugX · Hikit · PoisonIvy · Derusbi · Hydraq

Reporting (3)