APT9

Aliases: NIGHTSHADE PANDA, Red Pegasus, Group 27

Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 11:46:23

Targeted industries: healthcare-and-pharmaceutical technology-and-telecommunications

Context

APT9 engages in cyber operations where the goal is data theft, usually focusing on the data and projects that make a particular organization competitive within its field. APT9 was historically very active in the pharmaceuticals and biotechnology industry. We have observed this actor use spearphishing, valid accounts, as well as remote services for Initial Access. On at least one occasion, Mandiant observed APT9 at two companies in the biotechnology industry and suspect that APT9 actors may have gained initial access to one of the companies by using a trusted relationship between the two companies. APT9 use a wide range of backdoors, including publicly available backdoors, as well as backdoors that are believed to be custom, but are used by multiple APT groups.

Reports & references

  • Mandiant — Apt Groups (report)
  • pwc.com — Yir Cyber Threats Report Download (report)
  • otx.alienvault.com — 55Bbc68E67Db8C2D547Ae393 (report)
  • app.box.com — Z1Uanuv1Vn3Vw5Iket1R6Bqrmlra0Gpn (report)
  • news.softpedia.com — Trochilus Rat Evades Antivirus Detection Used For Cyber Espionage In South East Asia 498776.Shtml (report)
  • Palo Alto Unit 42 — Unit42 Trochilus Rat New Moonwind Rat Used Attack Thai Utility Organizations (report)

External references