Wekby was described by Palo Alto Networks in a 2015 report as: 'Wekby is a group that has been active for a number of years, targeting various industries such as healthcare, telecommunications, aerospace, defense, and high tech. The group is known to leverage recently released exploits very shortly after those exploits are available, such as in the case of HackingTeams Flash zero - day exploit.'
origin (suspected)
🇨🇳China· state-sponsoredattribution confidence: medium (50)
APT18 targets the US defense, aerospace, healthcare, and telecom sectors.
What should defenders focus on regarding APT18?+
Defenders should focus on zero-day exploitation typical of this actor and monitor for DNS-based C2 traffic associated with malware such as hcdLoader and gh0st RAT.