Wekby was described by Palo Alto Networks in a 2015 report as: 'Wekby is a group that has been active for a number of years, targeting various industr...

Threat Actor Profile

APT18

State-sponsored threat group originating from CN. Suspected sponsor: China. Known to target Government, Private sector, Civil society. Uses 18 known MITRE ATT&CK techniques.

18 TTPs Mapped 3 Industries Tracked Real-Time Alerts

Actor Overview

Origin Country
CN
Suspected Sponsor
China
Incident Types
Espionage
Known Techniques
18 TTPs

Target Industries

GovernmentPrivate sectorCivil society

Suspected Victims

United States

MITRE ATT&CK Techniques

T1071.004T1547T1071T1071.001T1547.001T1059T1059.003T1133T1083T1070T1070.004T1105T1027T1027.013T1053 +3 more

Related Threat Reports

Premium
APT Campaign Analysis - Q4 2025Dec 2025
New Tactics Observed in WildDec 2025
Infrastructure Mapping ReportDec 2025
Stay Updated

Get alerts when new intel on APT18 is published.

Actor Details

Primary Name
APT18
Known Aliases
DYNAMITE PANDA, TG-0416, SCANDIUM, PLA Navy, Wekby, G0026
Data Source
Precursor Intelligence
Need API Access?

Integrate threat actor data into your SIEM or SOAR.

View Plans →