APT22, also known as Suckfly, is a China-linked advanced persistent threat group associated with cyber espionage activity. Public reporting commonly places it among Chinese intrusion sets focused on long-term unauthorized access, stealth, and data collection rather than disruptive or financially motivated operations. The group is referenced under the APT22 designation and has been discussed alongside other established Chinese state-aligned clusters. APT22 is associated with the broader tradecraft typical of Chinese espionage actors: targeted initial access, persistence, privilege escalation, internal reconnaissance, lateral movement, post-compromise collection, and data exfiltration. Its operational profile aligns with sustained intrusions intended to maintain access over time and support intelligence-gathering objectives. High-confidence details on specific victim countries, sectors, or distinctive sub-groups are not available from the supplied facts beyond the alias relationship identifying APT22 with Suckfly.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
74 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a threat actor associated in the report’s aggregated section with exploitation activity around React2Shell (CVE-2025-55182) and related RSC/Next.js vulnerabilities.
Named in an aggregated list of actors associated with React2Shell (CVE-2025-55182) exploitation activity.
Listed as a China-linked APT group; no additional operational detail provided in the content beyond inclusion in an APT group list.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.