Elderwood

MITRE ATT&CK: G0066 View on attack.mitre.org

Aliases: Elderwood Gang, Beijing Group, Sneaky Panda, SNEAKY PANDA, Elderwood, SIG22

First seen
2009-01-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
Espionage
Profile updated
2026-07-07 12:32:20

Targeted industries: defense-and-aerospace manufacturing education-and-nonprofits technology-and-telecommunications

Targeted regions: country_code:us country_code:au country_code:uk country_code:sg

Context

Elderwood is a suspected Chinese cyber espionage group that was reportedly responsible for the 2009 Google intrusion known as Operation Aurora. The group has targeted defense organizations, supply chain manufacturers, human rights and nongovernmental organizations (NGOs), and IT service providers.

Detection coverage

  • 5 YARA rules
  • 146 Sigma rules

Malware & tools used

  • Encrypted/Encoded File (attack-pattern)
  • Malicious File (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Malicious Link (attack-pattern)
  • Drive-by Compromise (attack-pattern)
  • Exploitation for Client Execution (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Software Packing (attack-pattern)
  • Wiarp (malware)
  • Naid (malware)
  • Hydraq (malware)
  • Briba (malware)
  • PoisonIvy (malware)
  • Nerex (malware)
  • Pasam (malware)
  • Linfo (malware)
  • Vasport (malware)

Reports & references

  • cfr.org — Sneaky Panda (report)
  • Broadcom/Symantec — Viewdocument (report)
  • MITRE ATT&CK — G0066 (report)
  • securityaffairs.co — Elderwood Project Who Is Behind Op Aurora And Ongoing Attacks (report)
  • web.archive.org — The Elderwood Project (report)
  • csmonitor.com — Stealing Us Business Secrets Experts Id Two Huge Cyber Gangs In China (report)

External references