G0066 Elderwood
Elderwood is a suspected Chinese cyber espionage group that was reportedly responsible for the 2009 Google intrusion known as Operation Aurora. 1 The group has targeted defense organizations, supply chain manufacturers, human rights and nongovernmental organizations (NGOs), and IT service providers. 2 3
Item | Value |
---|---|
ID | G0066 |
Associated Names | Elderwood Gang, Beijing Group, Sneaky Panda |
Version | 1.2 |
Created | 18 April 2018 |
Last Modified | 02 March 2021 |
Navigation Layer | View In ATT&CK® Navigator |
Associated Group Descriptions
Name | Description |
---|---|
Elderwood Gang | 2 3 |
Beijing Group | 3 |
Sneaky Panda | 3 |
Techniques Used
Domain | ID | Name | Use |
---|---|---|---|
enterprise | T1189 | Drive-by Compromise | Elderwood has delivered zero-day exploits and malware to victims by injecting malicious code into specific public Web pages visited by targets within a particular sector.231 |
enterprise | T1203 | Exploitation for Client Execution | Elderwood has used exploitation of endpoint software, including Microsoft Internet Explorer Adobe Flash vulnerabilities, to gain execution. They have also used zero-day exploits.2 |
enterprise | T1105 | Ingress Tool Transfer | The Ritsol backdoor trojan used by Elderwood can download files onto a compromised host from a remote location.4 |
enterprise | T1027 | Obfuscated Files or Information | Elderwood has encrypted documents and malicious executables.2 |
enterprise | T1027.002 | Software Packing | Elderwood has packed malware payloads before delivery to victims.2 |
enterprise | T1566 | Phishing | - |
enterprise | T1566.001 | Spearphishing Attachment | Elderwood has delivered zero-day exploits and malware to victims via targeted emails containing malicious attachments.23 |
enterprise | T1566.002 | Spearphishing Link | Elderwood has delivered zero-day exploits and malware to victims via targeted emails containing a link to malicious content hosted on an uncommon Web server.23 |
enterprise | T1204 | User Execution | - |
enterprise | T1204.001 | Malicious Link | Elderwood has leveraged multiple types of spearphishing in order to attempt to get a user to open links.23 |
enterprise | T1204.002 | Malicious File | Elderwood has leveraged multiple types of spearphishing in order to attempt to get a user to open attachments.23 |
Software
References
-
Paganini, P. (2012, September 9). Elderwood project, who is behind Op. Aurora and ongoing attacks?. Retrieved February 13, 2018. ↩↩
-
O’Gorman, G., and McDonald, G.. (2012, September 6). The Elderwood Project. Retrieved February 15, 2018. ↩↩↩↩↩↩↩↩↩↩↩↩↩↩↩↩↩↩↩
-
Clayton, M.. (2012, September 14). Stealing US business secrets: Experts ID two huge cyber ‘gangs’ in China. Retrieved February 15, 2018. ↩↩↩↩↩↩↩↩↩
-
Ladley, F. (2012, May 15). Backdoor.Ritsol. Retrieved February 23, 2018. ↩