Threat Actor

APT17

Also known as: APT17, Deputy Dog

[APT17](https://attack.mitre.org/groups/G0025) is a China-based threat group that has conducted network intrusions against U.S. government entities, the defense industry, law firms, information technology companies, mining companies, and non-government organizations. (Citation: FireEye APT17)

2
Techniques
1
Software

Properties

stix_id
intrusion-set--090242d7-73fc-4738-af68-20162f7a5aae
signal_observed_at
2026-09-11T17:54:59+00:00
type
intrusion-set

MITRE ATT&CK Techniques (2)

Establish Accounts

Adversaries may create and cultivate accounts with services that can be used during targeting. Adversaries can create accounts that can be used to bui

Web Services

Adversaries may register for web services that can be used during targeting. A variety of popular websites exist for adversaries to register for a web

Software & Tools (1)

BLACKCOFFEE [malware]

[BLACKCOFFEE](https://attack.mitre.org/software/S0069) is malware that has been used by several Chinese groups since at least 2013. (Citation: FireEye

Explore this actor's full graph with Ninja Signal

APT17 — Threat Actor Profile — Ninja Signal | Ninja Signal