APT17 is a Chinese cyber-espionage threat actor widely tracked under aliases including DeputyDog, Hidden Lynx, Aurora Panda, Sportsfans, and Tailgater. Public reporting has repeatedly associated the group with China and, in some reporting, specifically with the Jinan bureau of the Ministry of State Security. The actor has been linked to long-running espionage operations against government and private-sector targets, including organizations in Japan, Italy, the United States, and other Western countries. APT17 is known for targeted intrusion activity using spearphishing, watering-hole attacks, and supply-chain compromise. Reported operations include exploitation of Internet Explorer zero-days in watering-hole campaigns against Japanese targets, use of region-specific software exploits in campaigns against Japanese organizations, and social-engineering-driven malware delivery against Italian government and corporate entities. The group has also been discussed in connection with the CCleaner supply-chain compromise based on code similarities to earlier APT17-associated malware, although attribution in that case has remained inconclusive. Malware and tooling associated with APT17 include Agtid, RAT 9002, BLACKCOFFEE, and ZoxPNG, with historical reporting also linking the group to development lineage involving ZoxRPC. Reported implants and modules have supported remote shell access, screen capture, file and process management, reconnaissance, persistence, and download-and-execute functionality. Observed tradecraft includes diskless payload execution, encrypted command-and-control communications, DLL sideloading, process injection, scheduled-task persistence, and modular post-compromise tooling. APT17 has primarily been characterized as an espionage actor, but some reporting has also alleged that individuals linked to the group engaged in hackers-for-hire activity and attempted to monetize stolen data. Those claims are less uniformly corroborated than the group’s espionage activity. Overall, APT17 is best understood as a China-linked advanced persistent threat focused on covert access, intelligence collection, and sustained post-exploitation against government and enterprise targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
39 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 malware families attributed to this actor across reporting.
8 additional families tracked in Mallory.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
The watering hole attacks observed in August 2013 leveraged a zero-day vulnerability in Internet Explorer (CVE-2013-3893) and eventually infected victims with Agtid.
The attacks observed in September 2013 leveraged another zero-day vulnerability in Internet Explorer (CVE-2013-3918). In these cases, the PlugX malware, a plug-in-based bot known as McRAT and a tunnelling tool, Htran, were later found in the victim’s environment.
CVE-2014-7247 was exploited as a zero-day vulnerability. The attack was carried out through targeted emails which were distributed to government agencies and enterprises in Japan.
28 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as an example of an APT group that has used Windows Scheduled Tasks for persistence.
Conducting targeted attacks against Italian companies and government entities using RAT 9002 / RAT 3102 delivered via malicious Office documents and links to a fake Skype for Business MSI package, with diskless modular payload execution and encrypted C2 communications.
Listed as a publicly known Chinese offensive cyber operations group associated with the Jinan bureau of the Chinese Ministry of State Security.
Mentioned only as background comparison regarding prior analysis of QQ data and codenames.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.