APT17
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
APT17, also known by the aliases Elderwood and Deputy Dog, is a threat actor group that has been publicly linked to China’s Ministry of State Security, specifically its Jinan bureau. The group’s affiliation with a state entity was highlighted when researchers from Intrusion Truth identified three individuals working as contractors for the ministry who conducted on‑demand hacking operations from Jinan. This connection places APT17 within the broader pattern of Chinese state‑sponsored cyber‑espionage activity that has been observed over several years. The actor’s location is consistently described as China, with operational ties to the Jinan region.
In terms of targeting, APT17 has demonstrated a focus on government agencies and vertical organizations, particularly those that rely on niche or region‑specific software with limited security oversight. The group’s campaigns have exploited zero‑day vulnerabilities in Japanese applications such as Sanshiro spreadsheets, Ichitaro word processors, and SkySea Client View management tools, indicating a strategic interest in compromising less‑monitored attack surfaces to gain access to sensitive networks. While the primary objective appears to be espionage, the actor’s methods are designed to establish persistent footholds for data collection and potential follow‑on operations. The group does not appear to be motivated by financial gain, as its activities align with intelligence‑gathering goals rather than monetization.
The typical initial access vector for APT17 involves spear‑phishing emails that carry malicious attachments, often in the form of RTF or XLSX documents. These files leverage known vulnerabilities such as CVE‑2017‑11882 in the Microsoft Office Equation Editor and CVE‑2018‑0798/CVE‑2018‑0802 in Excel to trigger remote code execution. Once a system is compromised, the actor deploys a suite of malware families including PlugX, Emdivi, Agtid, NodeRAT, and Wali, which provide remote access, lateral movement, and data exfiltration capabilities. The malware frequently incorporates anti‑detection techniques such as string obfuscation, process termination of security tools, and masquerading as legitimate Windows updates to evade detection. Additionally, APT17 has been observed creating scheduled tasks to maintain persistence and repeatedly attempting to reload payloads if initial execution fails.
Notable publicly reported operations include a multiyear campaign beginning around 2014 that targeted Japanese government and industry sectors through zero‑day exploits in the aforementioned software families, resulting in the installation of the PlugX‑based toolset for sustained espionage. Another significant moment came in 2010 when the group’s Jinan‑based contractors were exposed, linking the activity directly to a bureau within China’s Ministry of State Security and reinforcing the attribution of APT17 to state‑backed actors. These examples illustrate the actor’s consistent use of tailored spear‑phishing, zero‑day exploitation, and a specific malware toolkit to achieve its intelligence‑gathering objectives across multiple years.
Incidents
Attributed incidents are available to members.
2 incidents