APT16 is a China-linked espionage threat actor known for targeting organizations in East Asia, particularly in Japan and Taiwan. Reported victim sectors include high technology, government services, media, financial services, and Taiwanese information and news agencies. The group has been associated with targeted intrusion activity using spear-phishing and exploitation of Microsoft Office vulnerability CVE-2015-2545 for initial access. APT16 has been linked to the ELMER backdoor, a Delphi-based malware family used for post-compromise control and collection. ELMER supports host profiling, proxy-aware communications, command execution, file upload and download, directory and file enumeration, process listing, and exfiltration of host and file data. Observed tradecraft includes dynamic API resolution, custom string and code decryption, HTTP-based command-and-control, and collection of local system and network information. The actor has also used compromised legitimate websites and servers as operational infrastructure, including staging servers for second-stage payloads. This reflects an effort to blend malicious activity with trusted third-party infrastructure and support follow-on payload delivery and command-and-control. Overall, APT16 is best characterized as a Chinese cyber-espionage actor focused on intelligence collection against government, media, financial, and technology targets in Asia.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
7 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Uses compromised legitimate websites/servers as staging infrastructure for second-stage payloads.
Chinese threat actor using the ELMER backdoor to target organizations in Japan and Taiwan, including high-tech, government services, media, and financial services, with capabilities for host discovery, proxy detection, command execution, file upload/download, directory and process enumeration, and data exfiltration over HTTP.
Uses compromised legitimate websites as staging servers for second-stage payloads.
China-nexus espionage activity using a modified CVE-2015-2545 EPS exploit to compromise Taiwan-based media/information organizations; associated with the ELMER backdoor in referenced reporting.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.