APT17 is a China-based, state-linked cyberespionage actor associated with the Jinan bureau of China's Ministry of State Security. It is also tracked under names including DeputyDog, Hidden Lynx, Aurora Panda, Bronze Export, Heart Typhoon, Red Typhoon, Helium, Sportsfans, Tailgater, ATG3, TG-3279, and TG-8153. Its operations have targeted organizations in the United States, Japan, and Italy, including government agencies and corporate entities. APT17 uses watering-hole attacks, targeted document lures, malicious links, and software-update supply-chain compromises for initial access. Its Japanese campaigns exploited Internet Explorer zero-days CVE-2013-3893 and CVE-2013-3918, while activity involving the Agtid backdoor exploited the Japanese word processor Ichitaro through CVE-2014-7247. Operation Snowman involved compromise of the U.S. Veterans of Foreign Wars website and exploitation of Internet Explorer vulnerability CVE-2014-0322. The group has also altered legitimate update servers or redirected update requests to malicious infrastructure. Associated malware includes BLACKCOFFEE, also known as ZoxPNG, Agtid, and RAT 9002. Campaigns against Italian government and corporate organizations in 2024 used impersonated government meeting pages and trojanized Skype for Business installers to deliver a diskless RAT 9002 variant through a Java-based shellcode loader. Its modular functionality included screen capture, remote command execution, file management, process management, and host and network reconnaissance. Other documented persistence techniques include Windows Scheduled Tasks. APT17 shares malware and certificate overlaps with other Chinese threat actors, notably APT41; these overlaps do not establish that the groups are identical.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
50 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
26 malware families attributed to this actor across reporting.
21 additional families tracked in Mallory.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
The watering hole attacks observed in August 2013 leveraged a zero-day vulnerability in Internet Explorer (CVE-2013-3893) and eventually infected victims with Agtid.
The attacks observed in September 2013 leveraged another zero-day vulnerability in Internet Explorer (CVE-2013-3918). In these cases, the PlugX malware, a plug-in-based bot known as McRAT and a tunnelling tool, Htran, were later found in the victim’s environment.
CVE-2014-7247 was exploited as a zero-day vulnerability. The attack was carried out through targeted emails which were distributed to government agencies and enterprises in Japan.
103 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the broader China-nexus umbrella under which Silver Dragon likely operates.
Referenced as the broader umbrella under which Silver Dragon is believed to operate; associated here with China-linked cyberespionage activity targeting government/public sector.
Referenced as an established Chinese espionage ecosystem that Silver Dragon’s activity overlaps with; no direct APT41 operation details are provided beyond the linkage/overlap claim.
China-linked espionage and financially motivated operations: collection from telecom, healthcare, semiconductor manufacturing, and machine learning organizations, plus virtual currency theft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.