Axiom

MITRE ATT&CK: G0001 View on attack.mitre.org

Aliases: Group 72, Axiom

First seen
2008-01-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Related IoCs
84 (42 malicious)
Last IoC activity
2026-09-02 00:39:19
Profile updated
2026-07-07 11:47:27

Targeted industries: defense-and-aerospace government-and-public-sector manufacturing media-and-entertainment

Context

Axiom is a suspected Chinese cyber espionage group that has targeted the aerospace, defense, government, manufacturing, and media sectors since at least 2008. Some reporting suggests a degree of overlap between Axiom and Winnti Group but the two groups appear to be distinct based on differences in reporting on TTPs and targeting.

Recent IoC activity

42 malicious indicators in Maltiverse are attributed to Axiom (G0001). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname mirros.microsoftcontents.com 2026-09-02 1
hostname exchange.openmd5.com 2026-09-02 2
hostname microsoftcontents.com 2026-09-02 1
hostname exchange.portomnail.com 2026-09-02 1
hostname static.tcplog.com 2026-09-02 1
file sample SiteAdv.exe 2026-08-20 2
hostname officecdn-microsoft-com.akamaixed.net 2026-08-05 1
hostname dash.tcplog.com 2026-07-22 1
hostname help.tcplog.com 2026-07-22 1
hostname www.microsoftcontents.com 2026-07-22 1
hostname linuxupdate.info 2026-06-16 3
hostname yxwasec.com 2026-05-21 1
hostname dns.win10micros0ft.com 2026-04-30 2
hostname fonts.google-au.ga 2026-04-27 1
hostname cdn.google-au.ga 2026-04-27 1
hostname static.adobe-cdn.org 2026-04-27 1
hostname ns1.xxe.pw 2026-04-27 1
hostname x.xxe.pw 2026-04-27 1
hostname q4.xxe.pw 2026-04-27 1
hostname qq.xxe.pw 2026-04-27 1

Detection coverage

  • 17 YARA rules
  • 206 Sigma rules

Malware & tools used

  • Steganography (attack-pattern)
  • Data from Local System (attack-pattern)
  • Archive Collected Data (attack-pattern)
  • Botnet (attack-pattern)
  • Drive-by Compromise (attack-pattern)
  • Subvert Trust Controls (attack-pattern)
  • Remote Desktop Protocol (attack-pattern)
  • DNS Server (attack-pattern)
  • Exploitation for Client Execution (attack-pattern)
  • Valid Accounts (attack-pattern)
  • Virtual Private Server (attack-pattern)
  • RDP Hijacking (attack-pattern)
  • Accessibility Features (attack-pattern)
  • Phishing (attack-pattern)
  • Exploit Public-Facing Application (attack-pattern)
  • OS Credential Dumping (attack-pattern)
  • PlugX (malware)
  • Hydraq (malware)
  • gh0st RAT (malware)
  • Derusbi (malware)
  • Hikit (malware)
  • PoisonIvy (malware)
  • ZxShell (malware)
  • Zox (malware)

Related threat objects

Reports & references

  • MITRE ATT&CK — G0001 (report)
  • Kaspersky — 37029 (report)
  • Kaspersky — 70991 (report)
  • web.archive.org — Novetta Winntianalysis (report)
  • blogs.cisco.com — Threat Spotlight Group 72 (report)
  • web.archive.org — Executive Summary Final 1 (report)

External references