← Back to all threat actors

Elderwood

Also known as Elderwood Gang, Beijing Group, Sneaky Panda
Tracked as G0066

Elderwood is a suspected Chinese cyber espionage group that was reportedly responsible for the 2009 Google intrusion known as Operation Aurora. The group has targeted defense organizations, supply chain manufacturers, human rights and nongovernmental organizations (NGOs), and IT service providers.

How we source and review actor profiles
Status
Active

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
IdentityTracking identifier: G0066

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Elderwood Gang

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Beijing Group

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Sneaky Panda

Reviewed identity mapping approved on this date.

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

ElderwoodCanonical Name
Beijing GroupAlias
Elderwood GangAlias
Sneaky PandaAlias
G0066Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...