AdversaryGraph public intelligence page
This page is part of Threat Matrix, the public browser workspace for the main AdversaryGraph platform. Use it for ATT&CK pivots, actor and technique context, similarity leads, detection coverage review, and analyst-ready investigation paths.
Validation disclaimer: TTP overlap, actor similarity, generated summaries, and coverage findings are investigation leads, not attribution proof or operational validation without analyst review.
Main AdversaryGraph project Documentation Malware Analysis GitHub
Axiom
Aliases: Group 72
Axiom is a suspected Chinese cyber espionage group that has targeted the aerospace, defense, government, manufacturing, and media sectors since at least 2008. Some reporting suggests a degree of overlap between Axiom and Winnti Group but the two groups appear to be distinct based on differences in reporting on TTPs and targeting.
Open interactive actor investigation
ATT&CK techniques
SteganographyT1005
Data from Local SystemT1560
Archive Collected DataT1584.005
BotnetT1189
Drive-by CompromiseT1553
Subvert Trust ControlsT1021.001
Remote Desktop ProtocolT1583.002
DNS ServerT1203
Exploitation for Client ExecutionT1078
Valid AccountsT1583.003
Virtual Private ServerT1563.002
RDP HijackingT1546.008
Accessibility FeaturesT1566
PhishingT1190
Exploit Public-Facing ApplicationT1003
OS Credential DumpingT1001
Data Obfuscation
Correlated CTI and IR reports
Continue the investigation
Cyber Knowledge routes
These contextual routes explain behaviors associated with this ATT&CK group record. They support learning and investigation planning; they do not add attribution evidence.
Cyber Threat Intelligence (CTI) · explicit-idModule 3 — Core Frameworks Models
Cyber Threat Intelligence (CTI) · explicit-idModule 8 — Operationalizing CTI (CTI → Detection)
Cyber Threat Intelligence (CTI) · explicit-idExploitability validation and laboratory exploit engineering
Vulnerability Research & Exploit Development · explicit-idModule 9 — Tools of the Trade
Cyber Threat Intelligence (CTI) · explicit-nameModule 12 — Human-layer and physical testing
Red Team & Offensive Security · explicit-nameMalware, phishing, ransomware, and behavior extraction
Digital Forensics & Incident Response (DFIR) · explicit-nameHuman, workload, pipeline, and emergency identity
Cloud Security · explicit-nameScenario-based cyber risk assessment and treatment
Governance, Risk & Compliance (GRC) · explicit-nameEvidence integrity, order of volatility, and chain of custody
Digital Forensics & Incident Response (DFIR) · topic-matchTimeline reconstruction, ATT CK mapping, CTI, and confidence
Digital Forensics & Incident Response (DFIR) · topic-matchWeakness taxonomy and vulnerability identity
Vulnerability Research & Exploit Development · topic-match