APT26

Aliases: JerseyMikes, TURBINE PANDA, BRONZE EXPRESS, TECHNETIUM, Taffeta Typhoon, TG-0055, Red Kobold, APT26, BEARCLAW

Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 11:46:45

Targeted industries: government-and-public-sector technology-and-telecommunications healthcare-and-pharmaceutical

Targeted regions: country_code:us country_code:ca country_code:gb

Context

APT26, also known by aliases such as JerseyMikes and TURBINE PANDA, is a nation-state cyber threat actor linked to China. The group is known for its advanced tactics, targeting government, technology, and healthcare sectors primarily for cyber-espionage purposes.

Related threat objects

Reports & references

  • Mandiant — Cds19 Executive S08 Achievement Unlocked (report)
  • secureworks.com — Bronze Express (report)
  • uscc.gov — Adam Kozy Testimony (report)
  • raw.githubusercontent.com — Microsoftmapping (report)

External references