AdversaryGraph public intelligence page
This page is part of Threat Matrix, the public browser workspace for the main AdversaryGraph platform. Use it for ATT&CK pivots, actor and technique context, similarity leads, detection coverage review, and analyst-ready investigation paths.
Validation disclaimer: TTP overlap, actor similarity, generated summaries, and coverage findings are investigation leads, not attribution proof or operational validation without analyst review.
Main AdversaryGraph project Documentation Malware Analysis GitHub
APT18
Aliases: TG-0416, Dynamite Panda, Threat Group-0416
APT18 is a threat group that has operated since at least 2009 and has targeted a range of industries, including technology, manufacturing, human rights groups, government, and medical.
Open interactive actor investigation
ATT&CK techniques
Valid AccountsT1027.013
Encrypted/Encoded FileT1133
External Remote ServicesT1070.004
File DeletionT1053.002
AtT1105
Ingress Tool TransferT1071.004
DNST1082
System Information DiscoveryT1071.001
Web ProtocolsT1083
File and Directory DiscoveryT1059.003
Windows Command ShellT1547.001
Registry Run Keys / Startup Folder
Correlated CTI and IR reports
Continue the investigation
Cyber Knowledge routes
These contextual routes explain behaviors associated with this ATT&CK group record. They support learning and investigation planning; they do not add attribution evidence.
Red Team & Offensive Security · topic-matchPrompt injection, instruction hierarchy, and secure output handling
AI Security · topic-matchSecure AI development lifecycle and production release gate
AI Security · topic-matchEmbedded, firmware, hardware, and update-chain research
Vulnerability Research & Exploit Development · topic-matchModule 2 — The Intelligence Cycle Intelligence Types
Cyber Threat Intelligence (CTI) · topic-matchModule 8 — Operationalizing CTI (CTI → Detection)
Cyber Threat Intelligence (CTI) · topic-matchRequirements, ownership, inventory, and data flow
Secure Code & Application Security · topic-matchModule 6 — Alert triage, investigation, and escalation
Blue Team & Defensive Security · topic-matchMemory forensics and runtime reconstruction
Digital Forensics & Incident Response (DFIR) · topic-matchDynamic testing, fuzzing, abuse simulation, and security regression
Secure Code & Application Security · topic-matchAI security foundations and threat landscape
AI Security · topic-matchAI red teaming, evaluation, and reproducible security testing
AI Security · topic-match