APT17

G0025

Threat group.View on attack.mitre.org

About this group

APT17 is a China-based threat group that has conducted network intrusions against U.S. government entities, the defense industry, law firms, information technology companies, mining companies, and non-government organizations.

Techniques used2

Procedure examples2

TechniqueProcedure example
T1583.006
Web Services

APT17 has created profile pages in Microsoft TechNet that were used as C2 infrastructure.

T1585
Establish Accounts

APT17 has created and cultivated profile pages in Microsoft TechNet. To make profile pages appear more legitimate, APT17 has created biographical sections and posted in forum threads.

Software1

Campaigns0

None recorded.

References1

  1. FireEye APT17 Open source
    FireEye Labs/FireEye Threat Intelligence. (2015, May 14). Hiding in Plain Sight: FireEye and Microsoft Expose Obfuscation Tactic. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.