APT20 — APT Profile

APT20 — FireEye's designation for a Chinese espionage cluster that CrowdStrike calls Violin Panda and Palo Alto Networks has tracked as th3bug and Crawling Taurus — is unusual among Chinese groups for leaning on strategic web compromises rather than phishing. Unit 42 documented a 2014 wave in which the operators seeded malware on legitimate sites their intended targets were likely to visit, among them a prominent Uyghur-language portal, delivering Poison Ivy to visitors. The group resurfaced in December 2019 when Fox-IT published Operation Wocao, an account of two years of incident response that attributes the activity to APT20 with medium confidence and judges with high confidence that its operators are Chinese and working to state requirements. Fox-IT counted victims in ten countries, clustered in Western Europe — France, Germany, Italy, Portugal, Spain and the United Kingdom — plus Brazil, Mexico, China and the United States, spanning government bodies, managed service providers and industries from energy and health care to aviation and offshore engineering. The report describes intrusions that began at vulnerable JBoss servers, escalated by looting password vaults on administrators' workstations, then abandoned backdoors in favour of the victim's own corporate VPN, including one case where the actor defeated a two-factor soft-token implementation. Fox-IT rested its country assessment on a Chinese browser language header leaked through the actor's own tunnel, UTC+8 working hours, and an operator who typed the Mandarin expletive that gave the operation its name.

Also tracked as

VIOLIN PANDA, TH3Bug, Crawling Taurus, RIDGE CASTLE

Vendor research

Read the full analysis on IntelFusions