Intrusion setG0025
APT17
Also tracked as Deputy Dog
APT17 is a China-based threat group that has conducted network intrusions against U.S. government entities, the defense industry, law firms, information technology companies, mining companies, and non-government organizations.
- Documented techniques
- 2
- Assessed origin
- China
- Basis
- MITRE ATT&CK
How they break in
Techniques MITRE has documented this group using, grouped by the stage of an attack they belong to. This is the actionable half: each one is a behaviour you can look for in your own logs, and a control you can test.
resource development2
Malware
Families MITRE records this group deploying. Detection names for these are a reasonable place to start.
BLACKCOFFEE