APT19
Adversary group targeting financial, technology, non-profit organisations.
APT19 (DEEP PANDA) is a China-based cyber espionage group targeting finance and technology sectors in the US.
APT19 (DEEP PANDA) is a China-based cyber espionage group. It primarily targets private sector, finance, technology, and non-profit organizations in the United States. The group uses Drive-by Compromise and Spearphishing Attachment for initial access, leveraging PowerShell, Cobalt Strike, and Empire for execution and lateral movement. Defenders should monitor for suspicious PowerShell execution, Rundll32 abuse, and anomalous web-based C2 traffic.
Adversary group targeting financial, technology, non-profit organisations.
Monitor for downloads of tools used to evade security products.
Monitor for suspicious email attachments and access to malicious websites.
Monitor for suspicious PowerShell commands and script execution.
Monitor for Registry Run Keys and Windows Service changes.
Monitor for Rundll32 execution and creation of hidden windows.
Monitor for system network configuration and user information gathering.
Monitor for suspicious web protocol traffic and standard encoding methods.
Monitor and restrict Registry changes.
APT19 uses Drive-by Compromise and Spearphishing Attachment for initial access.
Defenders should monitor for suspicious PowerShell execution, Rundll32 abuse, and anomalous web-based C2 traffic.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.