Threat group.View on attack.mitre.org
APT19 is a Chinese-based threat group that has targeted a variety of industries, including defense, finance, energy, pharmaceutical, telecommunications, high tech, education, manufacturing, and legal services. In 2017, a phishing campaign was used to target seven law and investment firms. Some analysts track APT19 and Deep Panda as the same group, but it is unclear from open source information if the groups are the same.
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
APT19 used an HTTP malware variant and a Port 22 malware variant to collect the MAC address and IP address from the victim’s machine. |
| T1027.010 Command Obfuscation |
APT19 used Base64 to obfuscate executed commands. |
| T1027.013 Encrypted/Encoded File |
APT19 used Base64 to obfuscate payloads. |
| T1033 System Owner/User Discovery |
APT19 used an HTTP malware variant and a Port 22 malware variant to collect the victim’s username. |
| T1059 Command and Scripting Interpreter |
APT19 downloaded and launched code within a SCT file. |
| T1059.001 PowerShell |
APT19 used PowerShell commands to execute payloads. |
| T1071.001 Web Protocols |
APT19 used HTTP for C2 communications. APT19 also used an HTTP malware variant to communicate over HTTP for C2. |
| T1082 System Information Discovery |
APT19 collected system architecture information. APT19 used an HTTP malware variant and a Port 22 malware variant to gather the hostname and CPU information from the victim’s machine. |
| T1112 Modify Registry |
APT19 uses a Port 22 malware variant to modify several Registry keys. |
| T1132.001 Standard Encoding |
An APT19 HTTP malware variant used Base64 to encode communications to the C2 server. |
| T1140 Deobfuscate/Decode Files or Information |
An APT19 HTTP malware variant decrypts strings using single-byte XOR keys. |
| T1189 Drive-by Compromise |
APT19 performed a watering hole attack on forbes.com in 2014 to compromise targets. |
| T1204.002 Malicious File |
APT19 attempted to get users to launch malicious attachments delivered via spearphishing emails. |
| T1218.010 Regsvr32 |
APT19 used Regsvr32 to bypass application control techniques. |
| T1218.011 Rundll32 |
APT19 configured its payload to inject into the rundll32.exe. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.