Threat Actor
Operation Wocao
Also known as: Operation Wocao
[Operation Wocao](https://attack.mitre.org/groups/G0116) described activities carried out by a China-based cyber espionage adversary. [Operation Wocao](https://attack.mitre.org/groups/G0116) targeted entities within the government, managed service providers, energy, health care, and technology sectors across several countries, including China, France, Germany, the United Kingdom, and the United States. [Operation Wocao](https://attack.mitre.org/groups/G0116) used similar TTPs and tools to APT20, suggesting a possible overlap.(Citation: FoxIT Wocao December 2019)
Properties
- stix_id
- intrusion-set--28f04ed3-8e91-4805-b1f6-869020517871
- signal_observed_at
- 2026-09-11T17:54:59+00:00
- type
- intrusion-set
Explore this actor's full graph with Ninja Signal