APT16

MITRE ATT&CK: G0023 View on attack.mitre.org

Aliases: SVCMONDR, APT16

Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
Espionage
Profile updated
2026-07-07 11:46:26

Targeted industries: government-and-public-sector media-and-entertainment technology-and-telecommunications

Targeted regions: country_code:jp country_code:tw

Context

APT16 is a China-based threat group that has launched spearphishing campaigns targeting Japanese and Taiwanese organizations.

Malware & tools used

  • Server (attack-pattern)
  • ELMER (malware)

Exploited vulnerabilities

  • CVE-2015-1701 (vulnerability)
  • CVE-2015-2545 (vulnerability)

Reports & references

  • Mandiant — Apt Groups (report)
  • Mandiant — The Eps Awakens (report)
  • cfr.org — Apt 16 (report)
  • MITRE ATT&CK — G0023 (report)
  • Kaspersky — Cve 2015 2545 Overview Of Current Threats (report)
  • Mandiant — The Eps Awakens Part Two (report)

External references