APT16
MITRE ATT&CK: G0023 View on attack.mitre.org
Aliases: SVCMONDR, APT16
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- Espionage
- Profile updated
- 2026-07-07 11:46:26
Targeted industries: government-and-public-sector media-and-entertainment technology-and-telecommunications
Targeted regions: country_code:jp country_code:tw
Context
APT16 is a China-based threat group that has launched spearphishing campaigns targeting Japanese and Taiwanese organizations.
Malware & tools used
- Server (attack-pattern)
- ELMER (malware)
Exploited vulnerabilities
- CVE-2015-1701 (vulnerability)
- CVE-2015-2545 (vulnerability)
Reports & references
- Mandiant — Apt Groups (report)
- Mandiant — The Eps Awakens (report)
- cfr.org — Apt 16 (report)
- MITRE ATT&CK — G0023 (report)
- Kaspersky — Cve 2015 2545 Overview Of Current Threats (report)
- Mandiant — The Eps Awakens Part Two (report)