APT21 is a suspected Chinese state-sponsored cyber espionage group also known as Zhenbao and Hammer Panda. It has been associated with the NetTraveler, also referred to as Travelnet, intrusion set and is known for intelligence collection operations focused on document theft and long-term access. Observed tradecraft includes use of droppers and backdoors that establish persistence through Windows services, masquerade as legitimate system components, and maintain execution through service DLL registration. The group’s malware has demonstrated host reconnaissance, process and system enumeration, internet and proxy discovery, collection of network configuration data, recursive file enumeration across local drives, removable media, and network shares, and exfiltration of selected documents. Targeted file types have included common office and text document formats and PDFs, consistent with espionage objectives. APT21-associated malware has also shown multiple defense-evasion and post-compromise behaviors, including mutex-based anti-reinfection, timestomping, service impersonation, token impersonation, hidden staging of collected files, cleanup and self-removal when connectivity checks fail, and retrieval and execution of additional payloads from command infrastructure. Reported command capabilities include uninstall, update, reset, and upload tasking. Additional reporting links APT21 to tooling or development artifacts associated with bypass techniques, but the strongest directly supported activity centers on backdoor-enabled collection and exfiltration. APT21 is best characterized as a cyber espionage actor of Chinese origin focused on covert access, reconnaissance, document harvesting, and data exfiltration.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Included as one of the APT malware families in the dataset; the study reports near-perfect class separability for APT21 in ROC-AUC analysis.
Conducting espionage-oriented intrusions using the Travelnet backdoor and NetTraveler trojan to establish persistence, profile infected hosts, enumerate files and processes, collect documents from local disks, USB drives, and network shares, and exfiltrate data to C2 infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.