Affiliations
- Believed to be associated with the Axiom, APT 17, and Mirage threat actors. Believed to share the same tools and infrastructure as the threat actors that carried out Operation Aurora, the 2015 targeting of video game companies, the 2015 targeting of the Thai government, and the 2017 targeting of Chinese-language news websites
This threat actor targets software companies and political organizations in the United States, China, Japan, and South Korea. It primarily acts to support cyber operations conducted by other threat actors affiliated with Chinese intelligence services.
Suspected victims
- United States
- South Korea
- Universities in Hong Kong
- United Kingdom
- China
- Japan
- Hong Kong
Suspected state sponsor
- China
Type of incident
- Espionage
Target category
- Private sector