APT17 is a China-based state-sponsored cyber espionage group targeting government, defense, and technology sectors.
Analyst brief
APT17 is a China-based nation-state cyber espionage group also known as AURORA PANDA, targeting government, defense, intelligence, technology, and mining sectors primarily in the US, Europe, and Asia. Their key TTPs include phishing and drive-by compromise for initial access, RDP exploitation for lateral movement, and OS Credential Dumping for data collection, using malware such as PlugX, gh0st RAT, and PoisonIvy. Defenders should focus on detecting C2 traffic hidden via steganography, privilege escalation through accessibility features, and abuse of valid accounts.
APT17
Group 8AURORA PANDAHidden Lynx
nation-state
FireEye described APT17 in a 2015 report as: 'APT17, also known as DeputyDog, is a China based threat group that FireEye Intelligence has observed conducting network intrusions against U.S. government entities, the defense industry, law firms, information technology companies, mining companies, and non-government organizations.'
origin (suspected)
🇨🇳China· state-sponsoredattribution confidence: medium (50)