CSIDB logo
Threat actor

APT12

Attribution profile

Type
Nation State
Location
China
Known incidents
0 incidents
First seen
-
Last seen
-
Updated
2026-08-01 06:28
Aliases
4 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

APT12, also known by the aliases DeputyDog, Axiom and AXIUM, is a Chinese state‑sponsored espionage group that has been active since at least 2007 and is believed to operate under the direction of the Ministry of State Security. The group’s primary objective is the collection of political, military and economic intelligence to support Chinese strategic interests, and it has consistently pursued espionage rather than financially motivated crime. Its activities are characterized by a focus on high‑value targets that possess sensitive governmental, technological or defense‑related information.

APT12 has historically targeted sectors such as aerospace, defense, telecommunications, high‑technology manufacturing and governmental institutions, with a geographic emphasis on the United States, European nations and Japan. The group’s intrusions are aimed at gathering classified documents, technical specifications and diplomatic communications that can advance China’s intelligence and industrial goals. While the primary motive is espionage, there is no public evidence linking the group to direct financial gain or disruptive attacks as a primary objective.

The group’s typical tactics include spear‑phishing campaigns that deliver malicious attachments or links, watering‑hole compromises of websites frequented by target personnel, and occasional supply‑chain compromises where legitimate software updates are trojanized. APT12 is known for employing custom malware families such as Sakula, Derusbi and PlugX, which provide remote access, credential harvesting and lateral movement capabilities. The actors often use legitimate‑looking file names and code signing to evade detection, and they frequently employ command‑and‑control infrastructure that mimics benign services to blend with normal traffic.

Notable operations attributed to APT12 include intrusions into foreign ministries of several European countries, breaches of defense contractors involved in aircraft and missile programs, and compromises of telecommunications providers in Asia and the United States. These campaigns have been documented in multiple public reports linking the group’s tools and infrastructure to Chinese state‑sponsored activity. The sustained focus on high‑value intellectual property and governmental data underscores APT12’s role as a persistent espionage threat aligned with Chinese strategic priorities.

Incidents

Attributed incidents are available to members.

0 incidents
CSIDB