APT17
MITRE ATT&CK: G0025 View on attack.mitre.org
Aliases: Deputy Dog, Group 8, AURORA PANDA, Hidden Lynx, Tailgater Team, Dogfish, BRONZE KEYSTONE, Group 72, Axiom, HELIUM, Heart Typhoon, APT17, ATG3, Red Typhoon, KAOS, TG-8153, SportsFans, DeputyDog, Tailgater
- First seen
- 2014-01-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- Espionage
- Last IoC activity
- 2026-07-19 10:45:03
- Profile updated
- 2026-07-07 12:31:40
Targeted industries: defense-and-aerospace government-and-public-sector technology-and-telecommunications professional-services education-and-nonprofits
Targeted regions: country_code:us
Context
APT17 is a China-based threat group that has conducted network intrusions against U.S. government entities, the defense industry, law firms, information technology companies, mining companies, and non-government organizations.
Detection coverage
- 1 YARA rules
Malware & tools used
- Web Services (attack-pattern)
- Establish Accounts (attack-pattern)
- BLACKCOFFEE (malware)
Exploited vulnerabilities
- CVE-2013-3893 (vulnerability)
Related threat objects
- Winnti Group (threat-actor)
- Axiom (threat-actor)
- APT41 (threat-actor)
Reports & references
- Mandiant — Apt Groups (report)
- web.archive.org — Operation Deputydog Zero Day Cve 2013 3893 Attack Against Japanese Targets (report)
- paper.seebug.org — Hidden Lynx (report)
- cfr.org — Apt 17 (report)
- carbonblack.com — Bit9 And Our Customers Security (report)
- web.archive.org — Security Vendors Take Action Against Hidden Lynx Malware (report)
- web.archive.org — Hidden Lynx Professional Hackers Hire (report)
- recordedfuture.com — Hidden Lynx Analysis (report)
- secureworks.com — Bronze Keystone (report)
- MITRE ATT&CK — G0025 (report)
- cfr.org — Axiom (report)
- MITRE ATT&CK — G0001 (report)
- youtube.com — Watch (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- Mandiant — Apt17 Report (report)