« All threats

APT groupMITRE G0026

APT18

Also known as: dynamite panda, g0026, pla navy, satin typhoon, scandium, tg-0416, threat group-0416, wekby

[APT18](https://attack.mitre.org/groups/G0026) is a threat group that has operated since at least 2009 and has targeted a range of industries, including technology, manufacturing, human rights groups, government, and medical. (Citation: Dell Lateral Movement)

Victims in the last 90 days0

Most affected countries

No data yet.

Most affected sectors

No data yet.

Priority mitigations

MITRE ATT&CK mitigations that cover the most techniques used by this group.

  1. Network Intrusion Prevention (3 techniques covered)
  2. Filter Network Traffic (3 techniques covered)
  3. User Account Management (2 techniques covered)
  4. Privileged Account Management (2 techniques covered)
  5. Multi-factor Authentication (2 techniques covered)
  6. Application Developer Guidance (1 techniques covered)
  7. Active Directory Configuration (1 techniques covered)
  8. User Training (1 techniques covered)

MITRE ATT&CK techniques

Recent victims

No data yet.

Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.

Sources: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, Google News.