APT46
Attribution profile
- Type
- Nation State
- Location
- China
- Known incidents
- 0 incidents
- Sources
- 39 sources
- First seen
- -
- Last seen
- -
- Updated
- 2026-08-01 08:22
- Aliases
- 1 alias
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known as APT46, also tracked as Bronze President, Mustang Panda and HoneyMyte, is based in China and is considered a state‑backed hacking group. Its activities are described as intelligence‑collection campaigns, indicating an espionage‑oriented objective rather than purely financial gain. The actor has been observed targeting government officials, religious organizations and entities in Europe and Hong Kong.
Its typical tradecraft includes spear‑phishing emails that carry malicious attachments packaged as ZIP or RAR archives containing Windows executables disguised as PDF files, often named after a Russian city such as Blagoveshchensk and purportedly containing European Union sanction documents. Once opened, the executable employs a legitimate signed binary—identified as a file from UK‑based Global Graphics Software Ltd—to perform DLL search‑order hijacking, which loads a malicious DLL loader (DocConvDll.dll) that side‑loads an encrypted PlugX variant. The PlugX payload is then executed from a newly created directory under C:\ProgramData\Fuji Xerox\Fonts\ and provides the attackers with remote‑access capabilities. The group also uses digitally signed .EXE files and has been observed leveraging the same staging server that hosted the zyber‑i[.]com domain in earlier EU‑focused campaigns.
Public reporting links this actor to a phishing campaign that aimed at Russian state officers in the Blagoveshchensk region, using EU sanction‑themed lures, and to a separate spear‑phishing operation that targeted members of the Hong Kong Catholic Church with malicious Word or Adobe Reader lures that dropped PlugX via DLL‑sideloading. Earlier activity attributed to the same infrastructure includes intelligence‑gathering efforts against European targets, and the group is noted for its broad use of DLL‑side‑loading techniques against religious groups, including Catholic organizations. These campaigns illustrate the actor’s focus on gathering sensitive information from governmental and religious targets across multiple regions.
Incidents
Attributed incidents are available to members.
0 incidentsSources
Sources available to members: 39 sources.