APT19
[APT19](https://attack.mitre.org/groups/G0073) is a Chinese-based threat group that has targeted a variety of industries, including defense, finance, energy, pharmaceutical, telecommunications, high tech, education, manufacturing, and legal services. In 2017, a phishing campaign was used to target seven law and investment firms. (Citation: FireEye APT19) Some analysts track [APT19](https://attack.mitre.org/groups/G0073) and [Deep Panda](https://attack.mitre.org/groups/G0009) as the same group, but it is unclear from open source information if the groups are the same. (Citation: ICIT China's Espionage Jul 2016) (Citation: FireEye APT Groups) (Citation: Unit 42 C0d0so0 Jan 2016)
Properties
- stix_id
- intrusion-set--fe8796a4-2a02-41a0-9d27-7aa1e995feb6
- signal_observed_at
- 2026-09-11T17:55:00+00:00
- type
- intrusion-set
MITRE ATT&CK Techniques (21)
Adversaries may obfuscate content during command execution to impede detection. Command-line obfuscation is a method of making strings and patterns wi
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of intera
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries t
Adversaries may use [Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027) to hide artifacts of an intrusion from analysis. They
Adversaries may gain access to a system through a user visiting a website over the normal course of browsing. Multiple ways of delivering exploit code
Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection. Encrypting and/or encoding file
Adversaries may use hidden windows to conceal malicious activity from the plain sight of users. In some cases, windows that would typically be display
An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to ope
Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution. Ac
Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environ
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run key
Adversaries may abuse Regsvr32.exe to proxy execution of malicious code. Regsvr32.exe is a command-line program used to register and unregister object
Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. [Shared Modules](https://at
Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems. Spearphishing attachment is a sp
Adversaries may encode data with a standard data encoding system to make the content of command and control traffic more difficult to detect. Command
An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and
Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through info
Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is activel
Adversaries may buy, steal, or download software tools that can be used during targeting. Tools can be open or closed source, free or commercial. A to
Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with exi
Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts pr
Software & Tools (2)
[Cobalt Strike](https://attack.mitre.org/software/S0154) is a commercial, full-featured, remote access tool that bills itself as “adversary simulation
[Empire](https://attack.mitre.org/software/S0363) is an open-source, cross-platform remote administration and post-exploitation framework that is publ
Explore this actor's full graph with Ninja Signal