← Back to all threat actors

APT19

Also known as Codoso, C0d0so0, Codoso Team, Sunshop Group
Tracked as G0073

APT19 is a Chinese-based threat group that has targeted a variety of industries, including defense, finance, energy, pharmaceutical, telecommunications, high tech, education, manufacturing, and legal services. In 2017, a phishing campaign was used to target seven law and investment firms. Some analysts track APT19 and Deep Panda as the same group, but it is unclear from open source information if the groups are the same.

How we source and review actor profiles
Motivation
nation-state
Status
Active

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
IdentityAlias: Codoso

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: C0d0so0

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Codoso Team

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Sunshop Group

Reviewed identity mapping approved on this date.

Cataloged
IdentityTracking identifier: G0073

Reviewed identity mapping approved on this date.

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

APT19Canonical Name
C0d0so0Alias
CodosoAlias
Codoso TeamAlias
Sunshop GroupAlias
G0073Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...