APT9 is a threat actor targeting critical US industries with cyber espionage and confidential data theft.
Analyst brief
APT9, also tracked as NIGHTSHADE PANDA, is a threat actor of undetermined origin focused on cyber espionage and theft of confidential data to undermine competitive advantage. The group primarily targets the US pharmaceuticals, healthcare, construction, aerospace, and defense industrial base sectors. Observed TTPs for initial access include spearphishing, use of valid accounts, exploitation of remote services, and leveraging trusted partner relationships; after gaining a foothold, they deploy a mix of publicly available and custom backdoors. Defenders should prioritize email gateway security, enforce strict MFA on all accounts, regularly assess risks from trusted third-party connections, and monitor for anomalous remote access activity or unauthorized backdoor communications.
APT9
NIGHTSHADE PANDARed PegasusGroup 27
unknown
APT9 engages in cyber operations where the goal is data theft, usually focusing on the data and projects that make a particular organization competitive within its field. APT9 was historically very active in the pharmaceuticals and biotechnology industry. We have observed this actor use spearphishing, valid accounts, as well as remote services for Initial Access. On at least one occasion, Mandiant observed APT9 at two companies in the biotechnology industry and suspect that APT9 actors may have gained initial access to one of the companies by using a trusted relationship between the two companies. APT9 use a wide range of backdoors, including publicly available backdoors, as well as backdoors that are believed to be custom, but are used by multiple APT groups.
APT9 primarily targets sectors that provide competitive advantage, including the US pharmaceuticals, healthcare, construction, aerospace, and defense industrial base.
What methods does APT9 use to gain initial access?+
APT9 gains initial access through methods such as spearphishing, use of valid accounts, exploitation of remote services, and leveraging trusted partner relationships.