APT 19, Deep Panda, C0d0so0

Description

APT 19 is a Chinese-based threat group that has targeted a variety of industries, including defense, finance, energy, pharmaceutical, telecommunications, high tech, education, manufacturing, and legal services. In 2017, a phishing campaign was used to target seven law and investment firms.

Some analysts track APT19, DarkHydrus, LazyMeerkat, Turbine Panda, APT 26, Shell Crew, WebMasters, KungFu Kittens as the same group, but it is unclear from open source information if the groups are the same.

Names

NameName-Giver
APT 19Mandiant
Deep PandaCrowdStrike
CodosoCrowdStrike
Sunshop GroupFireEye
TG-3551SecureWorks
Bronze FirestoneSecureWorks
PupaSymantec
Red PegasusPWC
Checkered TyphoonMicrosoft

Country

A group likely composed of freelancers, with some degree of sponsorship by the Chinese government. (FireEye)

Motivation

  • Information theft and espionage

First Seen

2013

Observed Sectors

Observed Countries

Tools

Operations

Counter Operations

Mitre Attack

Other Information

Uuid

58c7e347-341c-4446-bf03-81fc1f7d9254

Last Card Change

2025-06-28