CNChinaconfidence: 50G0009G0073
APT19APT19
Also known as: DEEP PANDA · Codoso · WebMasters · KungFu Kittens · Black Vine · TEMP.Avengers · Group 13 · PinkPanther · Shell Crew · BRONZE FIRESTONE · G0009 · G0073 · Pupa · Sunshop Group · Checkered Typhoon · APT19
Origin
CN
Known aliases
16
Target sectors
2
Attribution
State-sponsored
Profile
APT19 is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as DEEP PANDA, Codoso, WebMasters (and 12 more). Operational targeting focuses on the Private sector and Military sectors. Documented victim organisations include United States. Original record: Adversary group targeting financial, technology, non-profit organisations.
Aliases· 16
DEEP PANDACodosoWebMastersKungFu KittensBlack VineTEMP.AvengersGroup 13PinkPantherShell CrewBRONZE FIRESTONEPupaSunshop GroupCheckered TyphoonAPT19
Target sectors· 2
Private sectorMilitary
Known victims· 1
- United States
MITRE ATT&CK Group crosswalk
References
- http://cybercampaigns.net/wp-content/uploads/2013/06/Deep-Panda.pdf
- https://docs.huihoo.com/rsaconference/usa-2014/anf-t07b-the-art-of-attribution-identifying-and-pursuing-your-cyber-adversaries-final.pdf
- https://www.cfr.org/interactive/cyber-operations/deep-panda
- https://eromang.zataz.com/2012/12/29/attack-and-ie-0day-informations-used-against-council-on-foreign-relations/
- https://eromang.zataz.com/2013/01/02/capstone-turbine-corporation-also-targeted-in-the-cfr-watering-hole-attack-and-more/
- https://www.crowdstrike.com/blog/department-labor-strategic-web-compromise/
- https://www.crowdstrike.com/blog/deep-thought-chinese-targeting-national-security-think-tanks/
- https://krebsonsecurity.com/2015/06/catching-up-on-the-opm-breach/
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.