Threat Actor

Operation Wocao

Also known as: Operation Wocao

[Operation Wocao](https://attack.mitre.org/groups/G0116) described activities carried out by a China-based cyber espionage adversary. [Operation Wocao](https://attack.mitre.org/groups/G0116) targeted entities within the government, managed service providers, energy, health care, and technology sectors across several countries, including China, France, Germany, the United Kingdom, and the United States. [Operation Wocao](https://attack.mitre.org/groups/G0116) used similar TTPs and tools to APT20, suggesting a possible overlap.(Citation: FoxIT Wocao December 2019)

Properties

stix_id
intrusion-set--28f04ed3-8e91-4805-b1f6-869020517871
signal_observed_at
2026-09-11T17:54:59+00:00
type
intrusion-set

Explore this actor's full graph with Ninja Signal

Operation Wocao — Threat Actor Profile — Ninja Signal | Ninja Signal