APT19 — APT Profile
APT19 is a Chinese-based threat group that has targeted a variety of industries, including defense, finance, energy, pharmaceutical, telecommunications, high tech, education, manufacturing, and legal services. In 2017, a phishing campaign was used to target seven law and investment firms. Some analysts track APT19 and Deep Panda as the same group, but it is unclear from open source information if the groups are the same.Also tracked as
Codoso, C0d0so0, Codoso Team, Sunshop Group
Tools & malware
- Cobalt Strike Adversary Simulation
- Empire Post-Exploitation Framework
- win.cobalt_strike Adversary Simulation
- win.firechili Backdoor
Vendor research
- Privileges and Credentials: Phished at the Request of Counsel FireEye
- Chinese Hacking Group Codoso Team Uses Forbes.com As Watering Hole Dark Reading
- FireEye. (n.d.). Advanced Persistent Threat Groups FireEye
- New Attacks Linked to C0d0so0 Group Unit 42
- ICIT Brief - China’s Espionage Dynasty: Economic Death by a Thousand Cuts ICIT