Threat Actor

APT16

Also known as: APT16

[APT16](https://attack.mitre.org/groups/G0023) is a China-based threat group that has launched spearphishing campaigns targeting Japanese and Taiwanese organizations. (Citation: FireEye EPS Awakens Part 2)

1
Techniques
1
Software

Properties

stix_id
intrusion-set--d6e88e18-81e8-4709-82d8-973095da1e70
signal_observed_at
2026-09-11T17:55:00+00:00
type
intrusion-set

MITRE ATT&CK Techniques (1)

Server

Adversaries may compromise third-party servers that can be used during targeting. Use of servers allows an adversary to stage, launch, and execute an

Software & Tools (1)

ELMER [malware]

[ELMER](https://attack.mitre.org/software/S0064) is a non-persistent, proxy-aware HTTP backdoor written in Delphi that has been used by [APT16](https:

Explore this actor's full graph with Ninja Signal

APT16 — Threat Actor Profile — Ninja Signal | Ninja Signal