Introduction
APT19 is a Chinese-based threat group that has targeted a variety of industries, including defense, finance, energy, pharmaceutical, telecommunications, high tech, education, manufacturing, and legal services. In 2017, a phishing campaign was used to target seven law and investment firms. FireEye APT19 Some analysts track APT19 and Deep Panda as the same group, but it is unclear from open source information if the groups are the same. ICIT Chinaβs Espionage Jul 2016 FireEye APT Groups Unit 42 C0d0so0 Jan 2016
Activities and Tactics
Targeted Sectors: Technology, Finance, Non-profit organisation, Private sector, Military
Country of Origin: π¨π³ China
Risk Level: High
Incident Type: Espionage
Suspected Victims: United States
Notable Campaigns
- Bassos Campaign
Tactics, Techniques, and Procedures (TTPs)
- T1547.001 Registry Run Keys / Startup Folder
- T1059.001 PowerShell
- T1564.003 Hidden Window
- T1016 System Network Configuration Discovery
- T1033 System Owner/User Discovery
- T1218.011 Rundll32
- T1112 Modify Registry
- T1189 Drive-by Compromise
- T1543.003 Windows Service
- T1071.001 Web Protocols
- T1059 Command and Scripting Interpreter
- T1027.013 Encrypted/Encoded File
- T1566.001 Spearphishing Attachment
- T1204.002 Malicious File
- T1082 System Information Discovery
- T1132.001 Standard Encoding
- T1588.002 Tool
- T1574.001 DLL
- T1218.010 Regsvr32
- T1140 Deobfuscate/Decode Files or Information
- T1027.010 Command Obfuscation
ATT&CK technique IDs (denormalized)
- T1016
- T1027.010
- T1027.013
- T1033
- T1059
- T1059.001
- T1071.001
- T1082
- T1112
- T1132.001
- T1140
- T1189
- T1204.002
- T1218.010
- T1218.011
- T1543.003
- T1547.001
- T1564.003
- T1566.001
- T1574.001
- T1588.002
Notable Indicators of Compromise (IOCs)
No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.
Malware and Tools
- Bergard Trojan:
- Derusbi:
- TXER:
MITRE ATT&CK Software
Attribution and Evidence
Country of Origin: China Additional attribution information pending cataloguing.
References
[1] mitre-attack [7] FireEye APT19 Ahl, I. (2017, June 06). Privileges and Credentials: Phished at the Request of Counsel. Retrieved May 17, 2018. [8] Dark Reading Codoso Feb 2015 Chickowski, E. (2015, February 10). Chinese Hacking Group Codoso Team Uses Forbes.com As Watering Hole. Retrieved September 13, 2018. [9] FireEye APT Groups FireEye. (n.d.). Advanced Persistent Threat Groups. Retrieved August 3, 2018. [10] Unit 42 C0d0so0 Jan 2016 Grunzweig, J., Lee, B. (2016, January 22). New Attacks Linked to C0d0so0 Group. Retrieved August 2, 2018. [11] ICIT Chinaβs Espionage Jul 2016 Scott, J. and Spaniel, D. (2016, July 28). ICIT Brief - Chinaβs Espionage Dynasty: Economic Death by a Thousand Cuts. Retrieved June 7, 2018.