Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
Also known as: Codoso, C0d0so0, Codoso Team, Sunshop Group
21
techniques
2
software
11,593
corpus matches
profile
APT19 is a Chinese-based threat group that has targeted a variety of industries, including defense, finance, energy, pharmaceutical, telecommunications, high tech, education, manufacturing, and legal services. In 2017, a phishing campaign was used to target seven law and investment firms. Some analysts track APT19 and Deep Panda as the same group, but it is unclear from open source information if the groups are the same.
techniques
21 attributed · most-instrumented first
software
2 malware & tools attributed
Cobalt Strike
S0154
Empire
S0363
read this carefully
11,593 corpus matches is not attribution
That count is indicators which exhibit techniques APT19 is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
+9 more techniques
showing 30 of 11,593
known aliases
Vendors name the same group differently. Searching any alias reaches this profile.