APT 4, Maverick Panda, Wisp Team

Description

(Trend Micro) Sykipot has a history of primarily targeting US Defense Initial Base (DIB) and key industries such as telecommunications, computer hardware, government contractors, and aerospace. Open source review of 15 major Sykipot attacks over the last 6 years confirm this.

Recently, we encountered a case where Sykipot variants were gathering information related to the civil aviation sector. The exploitation occurred at a target consistent with their history, the information sought raises new interest. The intentions of this latest round of targeting are unclear, but it represents a change in shift in objectives or mission.

Names

NameName-Giver
APT 4Mandiant
APT 4FireEye
Maverick PandaCrowdStrike
Wisp TeamSymantec
SykipotAlienVault
TG-0623SecureWorks
Bronze EdisonSecureWorks
SodiumMicrosoft
Salmon TyphooMicrosoft

Country

State-sponsored, PLA Navy

Motivation

  • Information theft and espionage

First Seen

2007

Observed Sectors

Observed Countries

Tools

Operations

Information

Other Information

Uuid

37543431-9ac9-488b-ad5a-eded5a6ff964

Last Card Change

2024-03-06