APT17 is a China-aligned cyber-espionage threat actor widely tracked under aliases including DeputyDog, Hidden Lynx, Aurora Panda, Tailgater, TG-8153, TG-3279, Bronze Export, Bronze University, Sportsfans, Red Typhoon, and in some reporting TA415. Public reporting has repeatedly associated the group with Chinese state interests, and some reporting specifically alleges links to the Jinan bureau of the Ministry of State Security. High-confidence reporting consistently places APT17 in the broader category of Chinese state-sponsored intrusion activity. APT17 has conducted long-running espionage operations against government, academic, and private-sector targets, including organizations in Japan, Italy, the United States, and other Western countries. Japanese organizations were targeted through spearphishing, watering-hole activity, and exploitation of region-specific software and browser vulnerabilities. More recent reporting tied RAT 9002 activity to campaigns against Italian government and corporate entities using spoofed government-themed infrastructure and trojanized software installers. The group is associated with modular remote access tooling and malware families including Agtid, BLACKCOFFEE, ZoxPNG, ZoxRPC, and RAT 9002. Reported tradecraft includes initial access via spearphishing and watering-hole attacks, exploitation of client-side vulnerabilities, supply-chain compromise techniques, use of trojanized installers, reconnaissance through host and network enumeration, persistence via Scheduled Tasks, and exfiltration of victim information. Observed post-compromise capabilities include remote shell access, file management, process management, screen capture, plugin-based expansion, and download-and-execute functionality. Reporting has also noted malware development overlap and code similarities between APT17-linked tooling and malware seen in other China-linked operations, including the CCleaner supply-chain compromise, though attribution in that case remained inconclusive. APT17 is primarily characterized as an espionage actor. Some reporting has additionally alleged hackers-for-hire behavior and attempted monetization of stolen data, but those claims are less broadly corroborated than the actor’s established espionage activity and should be treated with caution.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
52 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
26 malware families attributed to this actor across reporting.
21 additional families tracked in Mallory.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
The watering hole attacks observed in August 2013 leveraged a zero-day vulnerability in Internet Explorer (CVE-2013-3893) and eventually infected victims with Agtid.
The attacks observed in September 2013 leveraged another zero-day vulnerability in Internet Explorer (CVE-2013-3918). In these cases, the PlugX malware, a plug-in-based bot known as McRAT and a tunnelling tool, Htran, were later found in the victim’s environment.
CVE-2014-7247 was exploited as a zero-day vulnerability. The attack was carried out through targeted emails which were distributed to government agencies and enterprises in Japan.
103 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the broader China-nexus umbrella under which Silver Dragon likely operates.
Referenced as the broader umbrella under which Silver Dragon is believed to operate; associated here with China-linked cyberespionage activity targeting government/public sector.
Referenced as an established Chinese espionage ecosystem that Silver Dragon’s activity overlaps with; no direct APT41 operation details are provided beyond the linkage/overlap claim.
China-linked espionage and financially motivated operations: collection from telecom, healthcare, semiconductor manufacturing, and machine learning organizations, plus virtual currency theft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.