APT19

MITRE ATT&CK: G0073 View on attack.mitre.org

Aliases: Codoso, C0d0so0, Codoso Team, Sunshop Group, DEEP PANDA, WebMasters, KungFu Kittens, Black Vine, TEMP.Avengers, Group 13, PinkPanther, Shell Crew, BRONZE FIRESTONE, Pupa, Checkered Typhoon, APT19, CHLORINE, ATG50, TG-3551, Red Gargoyle

Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
Espionage
Last IoC activity
2026-07-21 00:38:46
Profile updated
2026-07-07 12:30:59

Targeted industries: defense-and-aerospace financial-services energy-and-utilities healthcare-and-pharmaceutical technology-and-telecommunications education-and-nonprofits manufacturing professional-services

Context

APT19 is a Chinese-based threat group that has targeted a variety of industries, including defense, finance, energy, pharmaceutical, telecommunications, high tech, education, manufacturing, and legal services. In 2017, a phishing campaign was used to target seven law and investment firms. Some analysts track APT19 and Deep Panda as the same group, but it is unclear from open source information if the groups are the same.

Detection coverage

  • 149 YARA rules
  • 716 Sigma rules

Malware & tools used

  • Registry Run Keys / Startup Folder (attack-pattern)
  • PowerShell (attack-pattern)
  • Hidden Window (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Rundll32 (attack-pattern)
  • Modify Registry (attack-pattern)
  • Drive-by Compromise (attack-pattern)
  • Windows Service (attack-pattern)
  • Web Protocols (attack-pattern)
  • Command and Scripting Interpreter (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Malicious File (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Standard Encoding (attack-pattern)
  • Tool (attack-pattern)
  • DLL (attack-pattern)
  • Regsvr32 (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Command Obfuscation (attack-pattern)
  • Empire (malware)
  • Cobalt Strike (malware)

Related threat objects

Reports & references

  • Mandiant — Apt Groups (report)
  • cybercampaigns.net — Deep Panda (report)
  • docs.huihoo.com — Anf T07B The Art Of Attribution Identifying And Pursuing Your Cyber Adversaries Final (report)
  • cfr.org — Deep Panda (report)
  • eromang.zataz.com — Attack And Ie 0Day Informations Used Against Council On Foreign Relations (report)
  • eromang.zataz.com — Capstone Turbine Corporation Also Targeted In The Cfr Watering Hole Attack And More (report)
  • CrowdStrike — Department Labor Strategic Web Compromise (report)
  • CrowdStrike — Deep Thought Chinese Targeting National Security Think Tanks (report)
  • krebsonsecurity.com — Catching Up On The Opm Breach (report)
  • krebsonsecurity.com — Anthem Breach May Have Started In April 2014 (report)
  • nextgov.com — 112354 (report)
  • CrowdStrike — Ironman Deep Panda Uses Sakula Malware Target Organizations Multiple Sectors (report)
  • abc.net.au — 5889442 (report)
  • washingtonpost.com — E6C7146C 86E1 11E4 A702 Fa31Ff4Ae98E Story (report)
  • seattletimes.com — Feds Warned Premera About Security Flaws Before Breach (report)
  • krebsonsecurity.com — Carefirst Blue Cross Breach Hits 1 1M (report)
  • threatvector.cylance.com — Shell Crew Variants Continue To Fly Under Big Avs Radar (report)
  • bleepingcomputer.com — Us Arrests Chinese Man Involved With Sakula Malware Used In Opm And Anthem Hacks (report)
  • gizmodo.com — U S Indicts Chinese Hacker Spies In Conspiracy To Stea 1830111695 (report)
  • cyberscoop.com — Anthem Breach Indictment Chinese National (report)
  • Broadcom/Symantec — The Black Vine Cyberespionage Group (report)
  • MITRE ATT&CK — G0009 (report)
  • secureworks.com — Bronze Firestone (report)
  • proofpoint.com — Exploring Bergard Old Malware New Tricks (report)
  • researchcenter.paloaltonetworks.com — New Attacks Linked To C0D0S0 Group (report)

External references