LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0026: APT18

APT18 is a threat group that has operated since at least 2009 and has targeted a range of industries, including technology, manufacturing, human rights groups, government, and medical. [1]

EnterpriseG0026GroupObject v2.2Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

APT18 is an ATT&CK group entry describing a long-running threat group reported since at least 2009 with targeting across technology, manufacturing, human rights, government, and medical sectors. The decision value is not the name alone: the associated relationships point to credential use, external remote access, Windows command execution, persistence, discovery, file transfer, deletion, and web/DNS command-and-control patterns. For leaders, this is a useful scenario for testing whether identity controls, endpoint visibility, and network egress monitoring work together during a real intrusion investigation.

Executive priority

Prioritize this as an operational resilience and readiness scenario rather than as proof of current exposure. Executives should ask whether remote access services are strongly authenticated and logged, whether SOC teams can connect suspicious logins to endpoint activity, and whether DNS/web traffic can support incident response. Because ATT&CK provides no official detection text and no group-level platforms or tactics, audit and budget decisions should focus on validating control coverage for the related techniques and software, not on the group name itself.

Technical view

The relationship set is heavily useful for SOC and IR validation. Confirm visibility for Windows command shell activity, at-based scheduling, registry run keys/startup folders, file deletion, file and directory discovery, system information discovery, ingress tool transfer, valid account abuse, and external remote services. Network detection should include web-protocol and DNS-based command-and-control patterns, especially given the related Pisloader note about DNS C2 and anti-analysis, and HTTPBrowser/gh0st RAT/hcdLoader relationships. Treat these relationships as analytic context, not attribution proof, because several related tools are public or used by multiple groups.

Likely telemetry

  • Identity provider, VPN, remote access, and externally exposed service authentication logs
  • Endpoint process creation telemetry, especially cmd.exe and child-process chains
  • Scheduled execution evidence, including at utility usage where present
  • Windows Registry Run key and Startup folder modification events
  • Endpoint file creation, deletion, rename, and transfer events

Detection direction

  • Build correlation around suspicious remote-service login followed by command shell execution, discovery, tool transfer, persistence creation, and cleanup activity.
  • Tune detections for cmd.exe, at, file deletion, and discovery commands against administrative baselines to reduce false positives from legitimate operations.
  • Validate DNS monitoring for unusual query patterns, rare domains, high-volume or structured subdomain activity, and other indicators consistent with DNS-based C2, without assuming every anomaly is malicious.
  • Validate web egress monitoring for unusual client behavior, rare destinations, and process-to-network relationships where endpoint telemetry is available.
  • Alert on new or modified Run keys and Startup folder entries, especially when preceded by remote access, tool transfer, or command shell activity.

Mitigation priorities

  • Start with identity and remote access controls: enforce strong authentication, review externally accessible services, and ensure credential abuse investigations have complete logs.
  • Harden and monitor endpoint execution paths, including command shell use, scheduled execution, and persistence locations such as Run keys and Startup folders.
  • Restrict and inspect outbound DNS and web traffic according to business need, with logging retained for incident response.
  • Improve endpoint file telemetry and response procedures for tool transfer, suspicious file creation, encoded artifacts, and deletion activity.
  • Maintain incident response playbooks that connect identity events, endpoint process activity, persistence, and DNS/web egress into one investigation timeline.
Additional notes and limits

APT18 is also listed with aliases TG-0416, Dynamite Panda, and Threat Group-0416. The supplied relationships include software and techniques that make this entry useful for detection engineering even though the group object itself has sparse platform and tactic fields. The most actionable defensive theme is integrated coverage across identity, remote access, Windows endpoint activity, persistence, and DNS/web egress.

MITRE provides no official detection text for this object, and the group-level platforms and tactics are not specified. The relationships support defensive planning but do not prove current activity, customer exposure, or attribution in a local incident. Local telemetry, asset scope, authentication architecture, and baseline administrative behavior are required to determine actual risk and coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

APT18

APT18 is a threat group that has operated since at least 2009 and has targeted a range of industries, including technology, manufacturing, human rights groups, government, and medical. [1]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

12 rows
DomainIDNameRelationship / procedure
EnterpriseT1078Valid Accounts

APT18 actors leverage legitimate credentials to log into external remote services.[2]

EnterpriseT1027.013Encrypted/Encoded FileSub-technique

APT18 obfuscates strings in the payload.[3]

EnterpriseT1133External Remote Services

APT18 actors leverage legitimate credentials to log into external remote services.[2]

EnterpriseT1070.004File DeletionSub-technique

APT18 actors deleted tools and batch files from victim systems.[1]

EnterpriseT1053.002AtSub-technique

APT18 actors used the native at Windows task scheduler tool to use scheduled tasks for execution on a victim network.[1]

EnterpriseT1105Ingress Tool Transfer

APT18 can upload a file to the victim’s machine.[3]

EnterpriseT1071.004DNSSub-technique

APT18 uses DNS for C2 communications.[3]

EnterpriseT1082System Information Discovery

APT18 can collect system information from the victim’s machine.[3]

EnterpriseT1071.001Web ProtocolsSub-technique

APT18 uses HTTP for C2 communications.[3]

EnterpriseT1083File and Directory Discovery

APT18 can list files information for specific directories.[3]

EnterpriseT1059.003Windows Command ShellSub-technique

APT18 uses cmd.exe to execute commands on the victim’s machine.[3][6]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

APT18 establishes persistence via the HKCU\Software\Microsoft\Windows\CurrentVersion\Run key.[6][3]

Associated objects

Groups, software, and campaigns

ToolEnterprise

S0106: cmd

cmd is the Windows command-line interpreter that can be used to interact with systems and execute other processes and utilities. [1]

Cmd.exe contains native functionality to perform many operations to interact with the system, including listing files in a directory (e.g., dir [2]), deleting files (e.g., del [3]), and copying files (e.g., copy [4]).

Windows
MalwareEnterprise

S0124: Pisloader

Pisloader is a malware family that is notable due to its use of DNS as a C2 protocol as well as its use of anti-analysis tactics. It has been used by APT18 and is similar to another malware family, HTTPBrowser, that has been used by the group. [1]

Windows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.2
Created
Modified
Raw hash
48fa13a349da9461...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.12.2Current bundle48fa13a349da…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Dell Lateral Movement

    Carvey, H.. (2014, September 2). Where you AT?: Indicators of lateral movement using at.exe on Windows 7 systems. Retrieved January 25, 2016.

  2. [2]
    RSA2017 Detect and Respond Adair

    Adair, S. (2017, February 17). Detecting and Responding to Advanced Threats within Exchange Environments. Retrieved November 17, 2024.

    Open source URL
  3. [3]
    PaloAlto DNS Requests May 2016

    Grunzweig, J., et al. (2016, May 24). New Wekby Attacks Use DNS Requests As Command and Control Mechanism. Retrieved November 15, 2018.

    Open source URL
  4. [4]
    ThreatStream Evasion Analysis

    Shelmire, A.. (2015, July 6). Evasive Maneuvers. Retrieved January 22, 2016.

    Open source URL
  5. [5]
    Palo Alto DNS Requests

    Grunzweig, J., et al. (2016, May 24). New Wekby Attacks Use DNS Requests As Command and Control Mechanism. Retrieved August 17, 2016.

  6. [6]
    Anomali Evasive Maneuvers July 2015

    Shelmire, A. (2015, July 06). Evasive Maneuvers by the Wekby group with custom ROP-packing and DNS covert channels. Retrieved November 15, 2018.

    Open source URL
  7. [7]
    APT18

    (Citation: ThreatStream Evasion Analysis)(Citation: Anomali Evasive Maneuvers July 2015)

  8. [8]
    APT18

    (Citation: ThreatStream Evasion Analysis)(Citation: Anomali Evasive Maneuvers July 2015)

  9. [9]
    APT18

    (Citation: ThreatStream Evasion Analysis)(Citation: Anomali Evasive Maneuvers July 2015)

  10. [10]
    Anomali Evasive Maneuvers July 2015

    Shelmire, A. (2015, July 06). Evasive Maneuvers by the Wekby group with custom ROP-packing and DNS covert channels. Retrieved November 15, 2018.

    Open source URL
  11. [11]
    Anomali Evasive Maneuvers July 2015

    Shelmire, A. (2015, July 06). Evasive Maneuvers by the Wekby group with custom ROP-packing and DNS covert channels. Retrieved November 15, 2018.

    Open source URL
  12. [12]
    Dell Lateral Movement

    Carvey, H.. (2014, September 2). Where you AT?: Indicators of lateral movement using at.exe on Windows 7 systems. Retrieved January 25, 2016.

  13. [13]
    Dell Lateral Movement

    Carvey, H.. (2014, September 2). Where you AT?: Indicators of lateral movement using at.exe on Windows 7 systems. Retrieved January 25, 2016.

  14. [14]
    Dynamite Panda

    (Citation: ThreatStream Evasion Analysis)(Citation: Anomali Evasive Maneuvers July 2015)

  15. [15]
    Dynamite Panda

    (Citation: ThreatStream Evasion Analysis)(Citation: Anomali Evasive Maneuvers July 2015)

  16. [16]
    Dynamite Panda

    (Citation: ThreatStream Evasion Analysis)(Citation: Anomali Evasive Maneuvers July 2015)

  17. [17]
    TG-0416

    (Citation: ThreatStream Evasion Analysis)(Citation: Anomali Evasive Maneuvers July 2015)

  18. [18]
    TG-0416

    (Citation: ThreatStream Evasion Analysis)(Citation: Anomali Evasive Maneuvers July 2015)

  19. [19]
    TG-0416

    (Citation: ThreatStream Evasion Analysis)(Citation: Anomali Evasive Maneuvers July 2015)

  20. [20]
    Threat Group-0416

    (Citation: ThreatStream Evasion Analysis)

  21. [21]
    Threat Group-0416

    (Citation: ThreatStream Evasion Analysis)

  22. [22]
    Threat Group-0416

    (Citation: ThreatStream Evasion Analysis)

  23. [23]
    ThreatStream Evasion Analysis

    Shelmire, A.. (2015, July 6). Evasive Maneuvers. Retrieved January 22, 2016.

    Open source URL
  24. [24]
    ThreatStream Evasion Analysis

    Shelmire, A.. (2015, July 6). Evasive Maneuvers. Retrieved January 22, 2016.

    Open source URL
  25. [25]
    mitre-attackG0026
    Open source URL
  26. [26]
    mitre-attackG0026
    Open source URL
  27. [27]
    mitre-attackG0026
    Open source URL
  28. [28]
    RSA2017 Detect and Respond Adair

    Adair, S. (2017, February 17). Detecting and Responding to Advanced Threats within Exchange Environments. Retrieved November 17, 2024.

    Open source URL
  29. [29]
    PaloAlto DNS Requests May 2016

    Grunzweig, J., et al. (2016, May 24). New Wekby Attacks Use DNS Requests As Command and Control Mechanism. Retrieved November 15, 2018.

    Open source URL
  30. [30]
    RSA2017 Detect and Respond Adair

    Adair, S. (2017, February 17). Detecting and Responding to Advanced Threats within Exchange Environments. Retrieved November 17, 2024.

    Open source URL
  31. [31]
    RSA2017 Detect and Respond Adair

    Adair, S. (2017, February 17). Detecting and Responding to Advanced Threats within Exchange Environments. Retrieved November 17, 2024.

    Open source URL
  32. [32]
    Dell Lateral Movement

    Carvey, H.. (2014, September 2). Where you AT?: Indicators of lateral movement using at.exe on Windows 7 systems. Retrieved January 25, 2016.

  33. [33]
    Dell Lateral Movement

    Carvey, H.. (2014, September 2). Where you AT?: Indicators of lateral movement using at.exe on Windows 7 systems. Retrieved January 25, 2016.

  34. [34]
    Dell Lateral Movement

    Carvey, H.. (2014, September 2). Where you AT?: Indicators of lateral movement using at.exe on Windows 7 systems. Retrieved January 25, 2016.

  35. [35]
    Dell Lateral Movement

    Carvey, H.. (2014, September 2). Where you AT?: Indicators of lateral movement using at.exe on Windows 7 systems. Retrieved January 25, 2016.

  36. [36]
    Dell Lateral Movement

    Carvey, H.. (2014, September 2). Where you AT?: Indicators of lateral movement using at.exe on Windows 7 systems. Retrieved January 25, 2016.

  37. [37]
    Dell Lateral Movement

    Carvey, H.. (2014, September 2). Where you AT?: Indicators of lateral movement using at.exe on Windows 7 systems. Retrieved January 25, 2016.

  38. [38]
    ThreatStream Evasion Analysis

    Shelmire, A.. (2015, July 6). Evasive Maneuvers. Retrieved January 22, 2016.

    Open source URL
  39. [39]
    ThreatStream Evasion Analysis

    Shelmire, A.. (2015, July 6). Evasive Maneuvers. Retrieved January 22, 2016.

    Open source URL
  40. [40]
    RSA2017 Detect and Respond Adair

    Adair, S. (2017, February 17). Detecting and Responding to Advanced Threats within Exchange Environments. Retrieved November 17, 2024.

    Open source URL
  41. [41]
    RSA2017 Detect and Respond Adair

    Adair, S. (2017, February 17). Detecting and Responding to Advanced Threats within Exchange Environments. Retrieved November 17, 2024.

    Open source URL
  42. [42]
    PaloAlto DNS Requests May 2016

    Grunzweig, J., et al. (2016, May 24). New Wekby Attacks Use DNS Requests As Command and Control Mechanism. Retrieved November 15, 2018.

    Open source URL
  43. [43]
    PaloAlto DNS Requests May 2016

    Grunzweig, J., et al. (2016, May 24). New Wekby Attacks Use DNS Requests As Command and Control Mechanism. Retrieved November 15, 2018.

    Open source URL
  44. [44]
    Dell Lateral Movement

    Carvey, H.. (2014, September 2). Where you AT?: Indicators of lateral movement using at.exe on Windows 7 systems. Retrieved January 25, 2016.

  45. [45]
    Dell Lateral Movement

    Carvey, H.. (2014, September 2). Where you AT?: Indicators of lateral movement using at.exe on Windows 7 systems. Retrieved January 25, 2016.

  46. [46]
    Palo Alto DNS Requests

    Grunzweig, J., et al. (2016, May 24). New Wekby Attacks Use DNS Requests As Command and Control Mechanism. Retrieved August 17, 2016.

  47. [47]
    PaloAlto DNS Requests May 2016

    Grunzweig, J., et al. (2016, May 24). New Wekby Attacks Use DNS Requests As Command and Control Mechanism. Retrieved November 15, 2018.

    Open source URL
  48. [48]
    PaloAlto DNS Requests May 2016

    Grunzweig, J., et al. (2016, May 24). New Wekby Attacks Use DNS Requests As Command and Control Mechanism. Retrieved November 15, 2018.

    Open source URL
  49. [49]
    PaloAlto DNS Requests May 2016

    Grunzweig, J., et al. (2016, May 24). New Wekby Attacks Use DNS Requests As Command and Control Mechanism. Retrieved November 15, 2018.

    Open source URL
  50. [50]
    PaloAlto DNS Requests May 2016

    Grunzweig, J., et al. (2016, May 24). New Wekby Attacks Use DNS Requests As Command and Control Mechanism. Retrieved November 15, 2018.

    Open source URL
  51. [51]
    PaloAlto DNS Requests May 2016

    Grunzweig, J., et al. (2016, May 24). New Wekby Attacks Use DNS Requests As Command and Control Mechanism. Retrieved November 15, 2018.

    Open source URL
  52. [52]
    PaloAlto DNS Requests May 2016

    Grunzweig, J., et al. (2016, May 24). New Wekby Attacks Use DNS Requests As Command and Control Mechanism. Retrieved November 15, 2018.

    Open source URL
  53. [53]
    PaloAlto DNS Requests May 2016

    Grunzweig, J., et al. (2016, May 24). New Wekby Attacks Use DNS Requests As Command and Control Mechanism. Retrieved November 15, 2018.

    Open source URL
  54. [54]
    Anomali Evasive Maneuvers July 2015

    Shelmire, A. (2015, July 06). Evasive Maneuvers by the Wekby group with custom ROP-packing and DNS covert channels. Retrieved November 15, 2018.

    Open source URL
  55. [55]
    PaloAlto DNS Requests May 2016

    Grunzweig, J., et al. (2016, May 24). New Wekby Attacks Use DNS Requests As Command and Control Mechanism. Retrieved November 15, 2018.

    Open source URL
  56. [56]
    Anomali Evasive Maneuvers July 2015

    Shelmire, A. (2015, July 06). Evasive Maneuvers by the Wekby group with custom ROP-packing and DNS covert channels. Retrieved November 15, 2018.

    Open source URL
  57. [57]
    PaloAlto DNS Requests May 2016

    Grunzweig, J., et al. (2016, May 24). New Wekby Attacks Use DNS Requests As Command and Control Mechanism. Retrieved November 15, 2018.

    Open source URL
  58. [58]
    RSA2017 Detect and Respond Adair

    Adair, S. (2017, February 17). Detecting and Responding to Advanced Threats within Exchange Environments. Retrieved November 17, 2024.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.