Axiom
MITRE ATT&CK: G0001 View on attack.mitre.org
Aliases: Group 72, Axiom
- First seen
- 2008-01-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Related IoCs
- 84 (42 malicious)
- Last IoC activity
- 2026-09-02 00:39:19
- Profile updated
- 2026-07-07 11:47:27
Targeted industries: defense-and-aerospace government-and-public-sector manufacturing media-and-entertainment
Context
Axiom is a suspected Chinese cyber espionage group that has targeted the aerospace, defense, government, manufacturing, and media sectors since at least 2008. Some reporting suggests a degree of overlap between Axiom and Winnti Group but the two groups appear to be distinct based on differences in reporting on TTPs and targeting.
Recent IoC activity
42 malicious indicators in Maltiverse are attributed to Axiom (G0001). The 20 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | mirros.microsoftcontents.com | 2026-09-02 | 1 |
| hostname | exchange.openmd5.com | 2026-09-02 | 2 |
| hostname | microsoftcontents.com | 2026-09-02 | 1 |
| hostname | exchange.portomnail.com | 2026-09-02 | 1 |
| hostname | static.tcplog.com | 2026-09-02 | 1 |
| file sample | SiteAdv.exe | 2026-08-20 | 2 |
| hostname | officecdn-microsoft-com.akamaixed.net | 2026-08-05 | 1 |
| hostname | dash.tcplog.com | 2026-07-22 | 1 |
| hostname | help.tcplog.com | 2026-07-22 | 1 |
| hostname | www.microsoftcontents.com | 2026-07-22 | 1 |
| hostname | linuxupdate.info | 2026-06-16 | 3 |
| hostname | yxwasec.com | 2026-05-21 | 1 |
| hostname | dns.win10micros0ft.com | 2026-04-30 | 2 |
| hostname | fonts.google-au.ga | 2026-04-27 | 1 |
| hostname | cdn.google-au.ga | 2026-04-27 | 1 |
| hostname | static.adobe-cdn.org | 2026-04-27 | 1 |
| hostname | ns1.xxe.pw | 2026-04-27 | 1 |
| hostname | x.xxe.pw | 2026-04-27 | 1 |
| hostname | q4.xxe.pw | 2026-04-27 | 1 |
| hostname | qq.xxe.pw | 2026-04-27 | 1 |
Detection coverage
- 17 YARA rules
- 206 Sigma rules
Malware & tools used
- Steganography (attack-pattern)
- Data from Local System (attack-pattern)
- Archive Collected Data (attack-pattern)
- Botnet (attack-pattern)
- Drive-by Compromise (attack-pattern)
- Subvert Trust Controls (attack-pattern)
- Remote Desktop Protocol (attack-pattern)
- DNS Server (attack-pattern)
- Exploitation for Client Execution (attack-pattern)
- Valid Accounts (attack-pattern)
- Virtual Private Server (attack-pattern)
- RDP Hijacking (attack-pattern)
- Accessibility Features (attack-pattern)
- Phishing (attack-pattern)
- Exploit Public-Facing Application (attack-pattern)
- OS Credential Dumping (attack-pattern)
- PlugX (malware)
- Hydraq (malware)
- gh0st RAT (malware)
- Derusbi (malware)
- Hikit (malware)
- PoisonIvy (malware)
- ZxShell (malware)
- Zox (malware)
Related threat objects
- APT17 (threat-actor)
Reports & references
- MITRE ATT&CK — G0001 (report)
- Kaspersky — 37029 (report)
- Kaspersky — 70991 (report)
- web.archive.org — Novetta Winntianalysis (report)
- blogs.cisco.com — Threat Spotlight Group 72 (report)
- web.archive.org — Executive Summary Final 1 (report)