APT19

G0073

Threat group.View on attack.mitre.org

About this group

APT19 is a Chinese-based threat group that has targeted a variety of industries, including defense, finance, energy, pharmaceutical, telecommunications, high tech, education, manufacturing, and legal services. In 2017, a phishing campaign was used to target seven law and investment firms. Some analysts track APT19 and Deep Panda as the same group, but it is unclear from open source information if the groups are the same.

Techniques used21

Procedure examples21

TechniqueProcedure example
T1016
System Network Configuration Discovery

APT19 used an HTTP malware variant and a Port 22 malware variant to collect the MAC address and IP address from the victim’s machine.

T1027.010
Command Obfuscation

APT19 used Base64 to obfuscate executed commands.

T1027.013
Encrypted/Encoded File

APT19 used Base64 to obfuscate payloads.

T1033
System Owner/User Discovery

APT19 used an HTTP malware variant and a Port 22 malware variant to collect the victim’s username.

T1059
Command and Scripting Interpreter

APT19 downloaded and launched code within a SCT file.

T1059.001
PowerShell

APT19 used PowerShell commands to execute payloads.

T1071.001
Web Protocols

APT19 used HTTP for C2 communications. APT19 also used an HTTP malware variant to communicate over HTTP for C2.

T1082
System Information Discovery

APT19 collected system architecture information. APT19 used an HTTP malware variant and a Port 22 malware variant to gather the hostname and CPU information from the victim’s machine.

T1112
Modify Registry

APT19 uses a Port 22 malware variant to modify several Registry keys.

T1132.001
Standard Encoding

An APT19 HTTP malware variant used Base64 to encode communications to the C2 server.

T1140
Deobfuscate/Decode Files or Information

An APT19 HTTP malware variant decrypts strings using single-byte XOR keys.

T1189
Drive-by Compromise

APT19 performed a watering hole attack on forbes.com in 2014 to compromise targets.

T1204.002
Malicious File

APT19 attempted to get users to launch malicious attachments delivered via spearphishing emails.

T1218.010
Regsvr32

APT19 used Regsvr32 to bypass application control techniques.

T1218.011
Rundll32

APT19 configured its payload to inject into the rundll32.exe.

View all 21 procedure examples

Software2

Campaigns0

None recorded.

References4

  1. FireEye APT Groups Open source
    FireEye. (n.d.). Advanced Persistent Threat Groups. Retrieved August 3, 2018.
  2. FireEye APT19 Open source
    Ahl, I. (2017, June 06). Privileges and Credentials: Phished at the Request of Counsel. Retrieved May 17, 2018.
  3. ICIT China's Espionage Jul 2016 Open source
    Scott, J. and Spaniel, D. (2016, July 28). ICIT Brief - China’s Espionage Dynasty: Economic Death by a Thousand Cuts. Retrieved June 7, 2018.
  4. Unit 42 C0d0so0 Jan 2016 Open source
    Grunzweig, J., Lee, B. (2016, January 22). New Attacks Linked to C0d0so0 Group. Retrieved August 2, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.