APT26
Aliases: JerseyMikes, TURBINE PANDA, BRONZE EXPRESS, TECHNETIUM, Taffeta Typhoon, TG-0055, Red Kobold, APT26, BEARCLAW
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 11:46:45
Targeted industries: government-and-public-sector technology-and-telecommunications healthcare-and-pharmaceutical
Targeted regions: country_code:us country_code:ca country_code:gb
Context
APT26, also known by aliases such as JerseyMikes and TURBINE PANDA, is a nation-state cyber threat actor linked to China. The group is known for its advanced tactics, targeting government, technology, and healthcare sectors primarily for cyber-espionage purposes.
Related threat objects
- Turla (threat-actor)
Reports & references
- Mandiant — Cds19 Executive S08 Achievement Unlocked (report)
- secureworks.com — Bronze Express (report)
- uscc.gov — Adam Kozy Testimony (report)
- raw.githubusercontent.com — Microsoftmapping (report)