APT17

MITRE ATT&CK: G0025 View on attack.mitre.org

Aliases: Deputy Dog, Group 8, AURORA PANDA, Hidden Lynx, Tailgater Team, Dogfish, BRONZE KEYSTONE, Group 72, Axiom, HELIUM, Heart Typhoon, APT17, ATG3, Red Typhoon, KAOS, TG-8153, SportsFans, DeputyDog, Tailgater

First seen
2014-01-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
Espionage
Last IoC activity
2026-07-19 10:45:03
Profile updated
2026-07-07 12:31:40

Targeted industries: defense-and-aerospace government-and-public-sector technology-and-telecommunications professional-services education-and-nonprofits

Targeted regions: country_code:us

Context

APT17 is a China-based threat group that has conducted network intrusions against U.S. government entities, the defense industry, law firms, information technology companies, mining companies, and non-government organizations.

Detection coverage

  • 1 YARA rules

Malware & tools used

  • Web Services (attack-pattern)
  • Establish Accounts (attack-pattern)
  • BLACKCOFFEE (malware)

Exploited vulnerabilities

  • CVE-2013-3893 (vulnerability)

Related threat objects

Reports & references

  • Mandiant — Apt Groups (report)
  • web.archive.org — Operation Deputydog Zero Day Cve 2013 3893 Attack Against Japanese Targets (report)
  • paper.seebug.org — Hidden Lynx (report)
  • cfr.org — Apt 17 (report)
  • carbonblack.com — Bit9 And Our Customers Security (report)
  • web.archive.org — Security Vendors Take Action Against Hidden Lynx Malware (report)
  • web.archive.org — Hidden Lynx Professional Hackers Hire (report)
  • recordedfuture.com — Hidden Lynx Analysis (report)
  • secureworks.com — Bronze Keystone (report)
  • MITRE ATT&CK — G0025 (report)
  • cfr.org — Axiom (report)
  • MITRE ATT&CK — G0001 (report)
  • youtube.com — Watch (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Mandiant — Apt17 Report (report)

External references