APT18
MITRE ATT&CK: G0026 View on attack.mitre.org
Aliases: TG-0416, Dynamite Panda, Threat Group-0416, DYNAMITE PANDA, SCANDIUM, PLA Navy, Wekby, Satin Typhoon, APT18, COMBINE, SILVERVIPER, Red Wraith, Elderwood Group
- First seen
- 2009-01-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- Espionage
- Profile updated
- 2026-07-07 12:31:41
Targeted industries: technology-and-telecommunications manufacturing government-and-public-sector healthcare-and-pharmaceutical
Targeted regions: country_code:us country_code:cn country_code:jp
Context
APT18 is a threat group that has operated since at least 2009 and has targeted a range of industries, including technology, manufacturing, human rights groups, government, and medical.
Detection coverage
- 3 YARA rules
- 317 Sigma rules
Malware & tools used
- Valid Accounts (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- External Remote Services (attack-pattern)
- File Deletion (attack-pattern)
- At (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- DNS (attack-pattern)
- System Information Discovery (attack-pattern)
- Web Protocols (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Windows Command Shell (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- gh0st RAT (malware)
- hcdLoader (malware)
- Pisloader (malware)
- cmd (malware)
- HTTPBrowser (malware)
Related threat objects
- APT4 (threat-actor)
- SAMURAI PANDA (threat-actor)
Reports & references
- Mandiant — Apt Groups (report)
- threatpost.com — 107828 (report)
- cfr.org — Apt 18 (report)
- MITRE ATT&CK — G0026 (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- secureworks.com — Where You At Indicators Of Lateral Movement Using At Exe On Windows 7 Systems (report)
- anomali.com — Evasive Maneuvers The Wekby Group Attempts To Evade Analysis Via Custom Rop (report)
- threatstream.com — Evasive Maneuvers The Wekby Group Attempts To Evade Analysis Via Custom Rop (report)
Attributed from
- ArcaneDoor (Deprecated) (campaign)
External references
- mitre-attack — G0026
- Threat Group-0416
- APT18
- TG-0416
- Dynamite Panda
- Dell Lateral Movement
- Anomali Evasive Maneuvers July 2015
- ThreatStream Evasion Analysis
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy