APT
ATLAS
Atlas
Actors
147
Names
471
Sectors
40
Requirements
480
⌘K
▸
sign in
Atlas
Actors
147
Names
471
Sectors
40
Requirements
480
LOADING
APT19 (aka Codoso, Sunshop Group) · APT Atlas
Actors
/
Nation-state / APT
/
Asia
APT19
G0073
APT
CN · China
AKA
Codoso · Sunshop Group · C0d0so
CrowdStrike
:
DEEP PANDA
MITRE
:
G0073
Secureworks
:
IRON LYRIC
Targets
19
Sectors
18
Threat types
1
GIRs covered
0/480
Active since
2013
Pin to atlas
Watch
Share
Export
Also tracked as
4 vendor names · 3 other aliases
Open Rosetta Stone
CrowdStrike
DEEP PANDA
Mandiant
APT19
MITRE
G0073
Secureworks
IRON LYRIC
UNATTRIBUTED ALIASES
Codoso
Sunshop Group
C0d0so
Victimology
Geographic footprint · 19 countries
Region filter
Export
origin · China
targeted countries · 19
OCEANIA ·
1
Australia
AMERICAS ·
5
Brazil
·
Canada
·
Colombia
·
United States
·
Uruguay
ASIA ·
8
China
·
Hong Kong
·
India
·
Japan
·
South Korea
·
Mongolia
·
Philippines
·
Saudi Arabia
EUROPE ·
5
Germany
·
United Kingdom
·
Italy
·
Netherlands
·
Sweden
Sectors targeted
18 of 40
Government
100 actors
Defense
72 actors
Aerospace
59 actors
Financial Services
74 actors
Healthcare
47 actors
Pharmaceutical
27 actors
Technology
60 actors
Telecom
72 actors
Retail & Hospitality
33 actors
NGOs & Dissidents
56 actors
Education & Research
62 actors
Media & Journalism
49 actors
Transportation
31 actors
Food and Beverage
10 actors
Legal & Professional
18 actors
Chemicals
20 actors
Private Sector (generic)
29 actors
Dissidents (as targets)
16 actors
Tactics, techniques, procedures
Threat types + MITRE ATT&CK mapping
THREAT TYPES
ESP · Espionage
MITRE ATT&CK · 15 techniques
Initial Access
· 2
T1189
Drive-by Compromise
T1566.001
Spearphishing Attachment
Execution
· 2
T1059
Command and Scripting Interpreter
Persistence
· 2
T1543.003
Windows Service
Discovery
· 2
T1016
System Network Configuration Discovery
Command And Control
· 1
T1071.001
Web Protocols
Defense Impairment
· 1
T1112
Modify Registry
Stealth
· 5
T1027.010
Command Obfuscation
GIR coverage
0 / 480 requirements satisfied
Open matrix
No GIRs mapped yet for this actor.
Open data
Machine-readable exports of this profile
JSON · REST
Actor record
Full profile via the public v1 API
STIX 2.1
Intrusion-set bundle
Deterministic ids · techniques + targeted countries
ATT&CK NAVIGATOR
Technique layer
15 techniques · layer format 4.5
Related actors
By origin and actor type
APT31
nation-state
China · 6 targets · since 2013
APT8
nation-state
China · 5 targets · since —
APT24
nation-state
China · 3 targets · since 2008
APT27
nation-state
China · 23 targets · since 2010
APT44
nation-state
Russia · 25 targets · since 2009
APT21
nation-state
China · 5 targets · since 2010
T1059.001
PowerShell
T1547.001
Registry Run Keys / Startup Folder
T1033
System Owner/User Discovery
T1140
Deobfuscate/Decode Files or Information
T1218.010
Regsvr32
T1218.011
Rundll32
T1564.003
Hidden Window