CSIDB logo
Threat actor

APT46

Attribution profile

Type
Nation State
Location
China
Known incidents
0 incidents
Sources
39 sources
First seen
-
Last seen
-
Updated
2026-08-01 08:22
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known as APT46, also tracked as Bronze President, Mustang Panda and HoneyMyte, is based in China and is considered a state‑backed hacking group. Its activities are described as intelligence‑collection campaigns, indicating an espionage‑oriented objective rather than purely financial gain. The actor has been observed targeting government officials, religious organizations and entities in Europe and Hong Kong.

Its typical tradecraft includes spear‑phishing emails that carry malicious attachments packaged as ZIP or RAR archives containing Windows executables disguised as PDF files, often named after a Russian city such as Blagoveshchensk and purportedly containing European Union sanction documents. Once opened, the executable employs a legitimate signed binary—identified as a file from UK‑based Global Graphics Software Ltd—to perform DLL search‑order hijacking, which loads a malicious DLL loader (DocConvDll.dll) that side‑loads an encrypted PlugX variant. The PlugX payload is then executed from a newly created directory under C:\ProgramData\Fuji Xerox\Fonts\ and provides the attackers with remote‑access capabilities. The group also uses digitally signed .EXE files and has been observed leveraging the same staging server that hosted the zyber‑i[.]com domain in earlier EU‑focused campaigns.

Public reporting links this actor to a phishing campaign that aimed at Russian state officers in the Blagoveshchensk region, using EU sanction‑themed lures, and to a separate spear‑phishing operation that targeted members of the Hong Kong Catholic Church with malicious Word or Adobe Reader lures that dropped PlugX via DLL‑sideloading. Earlier activity attributed to the same infrastructure includes intelligence‑gathering efforts against European targets, and the group is noted for its broad use of DLL‑side‑loading techniques against religious groups, including Catholic organizations. These campaigns illustrate the actor’s focus on gathering sensitive information from governmental and religious targets across multiple regions.

Incidents

Attributed incidents are available to members.

0 incidents

Sources

Sources available to members: 39 sources.

CSIDB